Point is, when on my server, I was trying to detect any intruders. Of course, I can't see anyone else on it. No strange files and no strange processes. But I've heard of rootkits.
Running netstat -a reveals some strange information. Process running that open a port very high up 56000 range. Could be anything. Telnetting to it reveals a strange message, "-1 Hostname/IP address not recognized"
On a hunch I change my root password and run another netstat -a. This time I see a connection to some other machine coming from sendmail of all processes! Eeeeck. Intruder! He's sending my root password to himself. Hope I can make that the biggest mistake he ever made.
I suspect he/they have been around for a long time. I'll have to start watching them now. This could be fun. But have to make sure I back up all my data first! They already disconnect me when I start to delete certain files.
Who knows what else they could do ...
Sometimes I feel like a weenie who doesn't know jack. Other times I feel good, like when I caught this intruder. Like I'm smart. Knock on wood. Hope I can get certified one day as a master. It's a long journey of many small steps but the peer review process makes you work harder.
It's also my first post and first time on Advogato ... My journey begins here.
FOAF updates: Trust rankings are now exported, making the data available to other users and websites. An external FOAF URI has been added, allowing users to link to an additional FOAF file.
Keep up with the latest Advogato features by reading the Advogato status blog.
If you're a C programmer with some spare time, take a look at the mod_virgule project page and help us with one of the tasks on the ToDo list!