hi,everyone!
I'm using rh7.2,but my machine is hackered recently,I open wu-ftpd and www
server only,I really don't know how the hacker cracked in,I guess maybe is from
wu-ftpd,the ftp server,now I found there is a tcp link:
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 My IP:41430 205.252.46.98:6667 ESTABLISHED
What this mean?
the ps and netstat command is unusable,I download the psproc and net-tools rpms
and upgrade the two package,so I found the strange 41430 port,but when I use ps
aux|less found the running process looks like quite well,what should I do next step?
����������������[EMAIL PROTECTED]
��������������������2002-06-02
_______________________________________________
Redhat-list mailing list
[EMAIL PROTECTED]
https://listman.redhat.com/mailman/listinfo/redhat-list