|
-
May 3rd, 2003, 11:54 PM
#14
Member
"My question is, how do you troubleshoot your box to make SURE you are
not brodcasting anything out of it you don't want to"
Hi
Besides using antivirus and spybot
You should always verify your ethernet card is not in
promiscuous mode with a detection program here is one for Windows there
may be others you can find using the google search engine I'm only
famillar with anti-sniff from Lopht..........
http://ntsecurity.nu/toolbox/promiscdetect/
If the answer is yes
then you have to check for any sniffers on your computer
if you discover the hackers sniffer it may be able possible to search
the sniffers log to piece together what he did on your system
Beware
To disguise a backdoor from your attention our friend likes to use tools
from the Windows resource kit such as Srvany.exe and netcat.exe to create
a service on your pc that he/she can connect via a remote shell
once he/she checks out what services are running before installing
the backdoor picks one that's turned off removes it with 'Srvinstw.exe'
tool then install a new service with the same name. This disguises his
backdoor and reduce the chance you'll detect it so you'll be running
around looking for new services or anything weird and won't know....
check everything on your computer not just the odd or
weird stuff that would tip you off to the Intruder when it could
be right under your nose..........
Doc
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|