being hacked?

_at_(none)
Date: 02/02/04

  • Next message: Florian Ernst: "Re: problem with security.debian.org"
    Date: Mon, 02 Feb 2004 01:34:29 +0100
    To: debian-user@lists.debian.org
    
    

    Hi,

    in my sid installation the synaptics logon screen asking for root
    password started warning about "could not grab keyboard, malicious
    agent". Chkrootkit gave a "bindshell on port 1630" warning.
    The warning was only generated when the adsl connection is on.
    Can this be somebody('s bot) trying over adsl?
    I have a hardware router/switch (sweex) with rather primitive firewall.
    Not very clear what it does.
    Connection is ptpp/vpn with fixed ip#.
    Made a new partition, installed new sid with serious password, installed
    bastille, planning to mount the existing partition for /home (reusing
    existing /home and perhaps some /etc files). Is this safe?
    This is my experimental machine, no real harm.

    A different sarge machine chrootkits as "4 hidden processes, possible
    LKM trojan", I bastilled this machine too. Google seemed to indicate
    this may not be serious, it is a P4 with multiple threading (not enabled
    I think). Now I feel less secure.

    My woody server (66 MHz) and a sarge (355 MHz) laptop have no chkrootkit
    warnings (too slow for a hacker?).

    Any other packages recommended for battening down the hatches?

    mvg Boudewijn

    -- 
    To UNSUBSCRIBE, email to debian-user-request@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Florian Ernst: "Re: problem with security.debian.org"

    Relevant Pages

    • Re: Uninstall Office 2003 Trial? Add/Remove returns Error Message!
      ... The most common "Warning and Information" source is listed as ... it simply doesn't proceed with the installation. ... Microsoft Office MVP ... MVP FAQ site: http://mvps.org/ ...
      (microsoft.public.office.misc)
    • Re: Installing gnuplot 4.2.2 on Mac G4 under Mac OS X 10.4.11
      ... I got several error messages before the installation failed. ... The error messages asked that I report these messages to the gnuplot ... configure: WARNING: dirent.h: check for missing prerequisite headers? ...
      (comp.graphics.apps.gnuplot)
    • RE: problem of setting up WMS
      ... checked the event logs. ... After installation of QoS Packet Scheduler, the only warning is that HP ... NC7781 Gigabit Server Adapter: ...
      (microsoft.public.windowsmedia.server)
    • Re: XP SP3 Update, Outlook 2002
      ... software that triggers the warning) and the testers were not told of the ... security changes, so it caught everyone, including MVPs, by surprise. ... Diane Poremsky [MVP - Outlook] ... Would it not have been possible during> *installation*, however, to inspect registered> plugins/dlls to at least warn the user that this problem> might occur if installation continues. ...
      (microsoft.public.outlook.installation)
    • Re: what happened to make world?
      ... WARNING: make world will overwrite your existing FreeBSD ... installation without also building and installing a new ... The correct sequence to upgrade is described in /usr/src/UPDATING and does ...
      (freebsd-hackers)