LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-22-2004, 11:22 PM   #1
statmobile
Member
 
Registered: Aug 2003
Location: Chapel Hill, NC
Distribution: Gentoo, Windows 95 2000 & XP
Posts: 160

Rep: Reputation: 30
PARANOID, Have I been hacked?


Hey,
I've been running an algorithm for over a week and a half on my machine, and it seems to keep getting slower. When I check top, I keep seeing weird things popping up here in there, such as xfce-panel, even though this should not be running, these also keep changing the PID number each time they show up. When using top the CPU status indicates that it is running at 100%, but when looking at the processes running the only significant process is my algorithm which is only using 64% of the processor. What gives? Is someone using my machine, and hiding the processes from me? I highly doublt this, but you just never know.

Last edited by statmobile; 04-22-2004 at 11:23 PM.
 
Old 04-23-2004, 12:36 AM   #2
Electro
LQ Guru
 
Registered: Jan 2002
Posts: 6,042

Rep: Reputation: Disabled
Dissconnect the computer from the network. Then see if this helps. If it does, you have to do some digging. You may want to scan for torjans and rootkits.
 
Old 04-23-2004, 12:54 AM   #3
statmobile
Member
 
Registered: Aug 2003
Location: Chapel Hill, NC
Distribution: Gentoo, Windows 95 2000 & XP
Posts: 160

Original Poster
Rep: Reputation: 30
thanks, I'll do that when I get to the office. Is there something I'm missing when looking at top though?
 
Old 04-23-2004, 01:10 AM   #4
Jerre Cope
Member
 
Registered: Oct 2003
Location: Texas (central)
Distribution: ubuntu,Slackware,knoppix
Posts: 323

Rep: Reputation: 37
Use netstat to see if you have connections to computers you can't identify.
 
Old 04-23-2004, 01:49 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
The "best" way to check would be to shut down the system, reboot with a bootable cdr like Knoppix, FIRE, PSK, Plan9 and run your filesystem integrity checker (that is, if you installed, configured and ran it and saved at least the databases to read-only media). This way there is nearly no way to circumvent detection. Else please read this first: Intruder Detection Checklist (CERT): http://www.cert.org/tech_tips/intrud...checklist.html to make sure you know what to do. Also search the Linux - Security forum for words like "compromise". We've written a lot of advice on checking integrity. Run "rpm -Va", check your passwd, group and shadow files for any users added you can't recognise, then check "last" and "lastlog" to see if any logged in, then check your system logs (the further back the better) for any "weird" lines. Make sure you know what services are running (also see Xinetd) and run "netstat -panel -A inet" to see listening services and the location/PID of the binary and investigate any unusual ones. Run Chkrootkit and Rootkit Hunter. If you're gonna post, please post output if you found anything weird or are unsure if it means something.
 
Old 04-23-2004, 03:18 AM   #6
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 475Reputation: 475Reputation: 475Reputation: 475Reputation: 475
Moved: This thread is more suitable in Linux-Security and has been moved accordingly to help your thread/question get the exposure it deserves.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Have I been hacked or am I just being paranoid? Kyral Retsam Linux - Security 8 07-15-2004 08:02 PM
Am I being hacked? or just paranoid piratebiter Linux - Security 4 10-17-2003 07:59 PM
Paranoid security raybcher Linux - Security 3 08-29-2003 07:54 AM
Paranoid about SSH Crashed_Again Linux - Security 7 02-02-2003 03:37 AM
Confused and Paranoid XP - RH 8 Install griff Linux - General 3 10-28-2002 02:51 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:03 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration