From owner-freebsd-security Fri Apr 20 4:43:54 2001 Delivered-To: freebsd-security@freebsd.org Received: from point.osg.gov.bc.ca (point.osg.gov.bc.ca [142.32.102.44]) by hub.freebsd.org (Postfix) with ESMTP id 457EF37B424 for ; Fri, 20 Apr 2001 04:43:51 -0700 (PDT) (envelope-from Cy.Schubert@uumail.gov.bc.ca) Received: (from daemon@localhost) by point.osg.gov.bc.ca (8.8.7/8.8.8) id EAA15830; Fri, 20 Apr 2001 04:43:33 -0700 Received: from passer.osg.gov.bc.ca(142.32.110.29) via SMTP by point.osg.gov.bc.ca, id smtpda15828; Fri Apr 20 04:43:31 2001 Received: (from uucp@localhost) by passer.osg.gov.bc.ca (8.11.2/8.9.1) id f3KBhPU03019; Fri, 20 Apr 2001 04:43:25 -0700 (PDT) Received: from cwsys9.cwsent.com(10.2.2.1), claiming to be "cwsys.cwsent.com" via SMTP by passer9.cwsent.com, id smtpdRJ3016; Fri Apr 20 04:42:59 2001 Received: (from uucp@localhost) by cwsys.cwsent.com (8.11.3/8.9.1) id f3KBgxM10140; Fri, 20 Apr 2001 04:42:59 -0700 (PDT) Message-Id: <200104201142.f3KBgxM10140@cwsys.cwsent.com> Received: from localhost.cwsent.com(127.0.0.1), claiming to be "cwsys" via SMTP by localhost.cwsent.com, id smtpdT10136; Fri Apr 20 04:42:41 2001 X-Mailer: exmh version 2.3.1 01/18/2001 with nmh-1.0.4 Reply-To: Cy Schubert - ITSD Open Systems Group From: Cy Schubert - ITSD Open Systems Group X-Sender: schubert To: Raoul Schroeder Cc: Kris Kennaway , fukuda shinichi , freebsd-security@FreeBSD.ORG Subject: Re: unknown process In-reply-to: Your message of "Thu, 19 Apr 2001 11:02:24 EDT." <3ADEFE00.812EA0A3@gmx.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Date: Fri, 20 Apr 2001 04:42:41 -0700 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org In message <3ADEFE00.812EA0A3@gmx.net>, Raoul Schroeder writes: > > > > Take your system off the net and check it for signs of intrusion. > > > > Kris > > Just a quick question: How does one check for signs of intrusion. The FreeBSD > handbook does not really talk a lot about this. > Is there a good documentation about this? Install an IDS immediately after installation, then use it. This is not a 100% solution but IMO one of the better solutions in your toolkit. Regards, Phone: (250)387-8437 Cy Schubert Fax: (250)387-5766 Team Leader, Sun/Alpha Team Internet: Cy.Schubert@osg.gov.bc.ca Open Systems Group, ITSD, ISTA Province of BC To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message