Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Potential Hack

Status
Not open for further replies.

mezanine

IS-IT--Management
Jul 27, 2001
61
US
I suspect some malicious behavior on my system. What leads me to believe this is when a do a netstat -r I notice all kinds of entries for addresses on the internet like ns4.ctccom.net and ns1.net.umd.edu to name just a few. In addition my server can do DNS now, when in the past it was unable to. This might be nothing however I was wondering if someone could give me some guidence to look further.
 
check out /etc/resolv.conf
this contains any dns server definitions for address resolution.
check for named running if you want to see if you are running a dns server.

as far as the routing information this can be "learned" if you have routed running.
 
This is what I see in the resolv.conf file.

nameserver 0.0.0.0
hostresorder local bind

I am still lokiing at you other suggestions.

Thanks
 
are you running the unix machine as a dhcp client or does it have a fixed ip?
 
You are probably running routed and those hosts may be broadcasting routing information using RIP (Routing Information Protocol). It is quite safe to disable routed by commenting out the relevant lines in /etc/tcp, which I do as part of a standard install. Annihilannic.
 
Thanks, I will try commenting out those lines.
 
You will obviously also have to kill the currently running instance of routed. Annihilannic.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top