[TriLUG] werid network connection

Errol Casey errol at nouce.net
Fri Sep 26 14:56:44 EDT 2003


This is on a box that has been root kited (sucKIT) and will be
reinstalled, but was wondering what this raw
connection is?

raw        0      0 0.0.0.0:6               0.0.0.0:*               7
-
raw        0      0 0.0.0.0:1               0.0.0.0:*               7
-
raw        0      0 0.0.0.0:6               0.0.0.0:*               7
-


Anybody know how the backdoor works on this root kit?

-- 
Errol Casey
errol at nouce.net



More information about the TriLUG mailing list