View Single Post
  #3   (View Single Post)  
Old 1st July 2009
s2scott's Avatar
s2scott s2scott is offline
Package Pilot
 
Join Date: May 2008
Location: Toronto, Ontario Canada
Posts: 198
Default

Quote:
Originally Posted by knasbas View Post
How do i trace what a user been doing?
On the simple side, using ...

tcpdump and/or pftop (if installed)

you can "watch" your box's actual network traffic to see who's NOW talking to you and with whom your talking to. If you cannot account for the sessions you see, then you are OPERATING as compromised host.

The very nature of an IM/IRC "bot" would suggest that you're going to see lots and lots of sessions.

In the bash history, where you see
Code:
./a 21.21
are obfuscated and powerful system calls, where the hacker knows what 21.21 is.

/S
__________________
Never argue with an idiot. They will bring you down to their level and beat you with experience.
Reply With Quote