|
![]() ![]() |
CERT® Incident Note IN-99-06The CERT Coordination Center publishes incident notes to provide information about incidents to the Internet community.Distributed Network SnifferMonday, October 25, 1999
OverviewWe have received reports of intruders using distributed network sniffers to capture usernames and passwords. The distributed sniffer consists of a client and a server portion. The sniffer clients have been found exclusively on compromised Linux hosts.
DescriptionThe following characteristics may be present on compromised hosts running the sniffer client:
The characteristics of the sniffer server include these:
SolutionsIf you believe a host has been compromised, we encourage you to disconnect the host from the network and review our steps for recovering from a root compromise:
We encourage you to ensure that your hosts are current with security patches or work-arounds for well-known vulnerabilities. This document is available from: http://www.cert.org/incident_notes/IN-99-06.html CERT/CC Contact Information
Phone: +1 412-268-7090 (24-hour hotline) Fax: +1 412-268-6989 Postal address: CERT/CC personnel answer the hotline 08:00-17:00 EST(GMT-5) / EDT(GMT-4) Monday through Friday; they are on call for emergencies during other hours, on U.S. holidays, and on weekends. Using encryptionWe strongly urge you to encrypt sensitive information sent by email. Our public PGP key is available from If you prefer to use DES, please call the CERT hotline for more information. Getting security informationCERT publications and other security information are available from our web site
* "CERT" and "CERT Coordination Center" are registered in the U.S. Patent and Trademark Office.
NO WARRANTY Conditions for use, disclaimers, and sponsorship information
Copyright 1999 Carnegie Mellon University. |








