|
|
< Day Day Up > |
|
Forensic Analysis ToolsOne issue computer investigators face is that normal file utilities can irrevocably change files, effectively "polluting" the crime scene as well as deleting evidence you need. For example, viewing files with a regular editor changes things like the timestamp. Imagine someone tromping through a real crime scene in dirty boots and moving objects all over the house. This is the same as rummaging through your system without the proper tools. Not only will you have eliminated your chance of being able to take any criminal or civil action, but you may also erase the attacker's digital trail. Hackers often use tools that hide processes and files from normal system utilities, so you need special tools that operate outside of the normal operating system to look beyond what the operating system thinks it sees. The following sections review tools for both Linux and Windows. First we will look at a few of the investigation tools on operating systems, then at full-featured toolkits for deeper analysis. Keep in mind that using operating system-based tools may return false or bogus data if your OS has truly been compromised.
This little system add-on can be useful when investigating a machine for suspicious activity. Often a memory-resident virus or Trojan horse will show up as a process running under a strange name or on an unusual port. Fport looks for open TCP or UDP network ports and prints them out along with the associated process id (PID), process name, and path. It is similar to the native Windows netstat command except that it provides a little more information and allows you to format it different ways for analysis. This can help you track down suspicious programs that are opening up network ports on your machine. This behavior is the hallmark of a Trojan horse. Of course, every process you don't recognize isn't necessarily an evil program, but you should understand what weird-looking services are doing. The most obvious ones will have nonstandard paths (other than the Windows system directories and such). Also, strange or hacker-like names are a dead giveaway. The program is designed and offered by Foundstone Corporation, a security software and consulting company. They offer several other free security tools and their Web site is worth a look. While Fport is not purely open source (only the binaries are distributed), it is freeware and there are few limitations on its use for commercial purposes. Installing FportDownload the zip file from the Foundstone Web site and unzip it into its own directory. There will be two files, the Fport executable and a short README file. Using FportFport can help you figure out if a machine has been tampered with and where the intruder is coming from. You need to run Fport on a system that is live, that is, up and running; you can't run Fport on static data. Running Fport is about as simple as it comes. From the directory the executable is in, type fport. It prints a listing of all the ports open at that moment and their associated applications (see Listing 11.1). Listing 11.1. Fport Display
Port v2.0 - TCP/IP Process to Port Mapper
Copyright 2000 by Foundstone, Inc.
http://www.foundstone.com
Pid Process Port Proto Path
940 svchost -> 135 TCP C:\WINDOWS\system32\svchost.exe
4 System -> 139 TCP
4 System -> 445 TCP
1348 WCESCOMM -> 990 TCP C:\Program Files\Microsoft
ActiveSync\WCESCOMM.EXE
4072 WCESMgr -> 999 TCP C:\Program Files\Microsoft
ActiveSync\WCESMgr.exe
1032 svchost -> 1025 TCP C:\WINDOWS\System32\svchost.exe
1032 svchost -> 1031 TCP C:\WINDOWS\System32\svchost.exe
1032 svchost -> 1034 TCP C:\WINDOWS\System32\svchost.exe
4 System -> 1042 TCP
4072 WCESMgr -> 2406 TCP C:\Program Files\Microsoft
ActiveSync\WCESMgr.exe
2384 websearch -> 3008 TCP C:\Program Files\websearch\
websearch.exe
1144 -> 54321 TCP C:\Temp\cmd.exe
4072 WCESMgr -> 5678 TCP C:\Program Files\Microsoft
ActiveSync\WCESMgr.exe
2384 websearch -> 8755 TCP C:\Program Files\websearch\
websearch.exe
136 javaw -> 8765 TCP C:\WINDOWS\System32\javaw.exe
1348 WCESCOMM -> 123 UDP C:\Program Files\Microsoft
ActiveSync\WCESCOMM.EXE
2384 websearch -> 123 UDP C:\Program Files\websearch\
websearch.exe
940 svchost -> 135 UDP C:\WINDOWS\system32\svchost.exe
1144 -> 137 UDP
1032 svchost -> 1026 UDP C:\WINDOWS\System32\svchost.exe
By looking at this listing, you can see what appear to be normal services and programs running, until about half way down where you can see that cmd.exe is running from the temp directory. This is the command prompt binary and it has no business being in a temp directory. Also, the fact that the service has no name should arouse suspicion. Finally, the incoming port number doesn't match any known services. In fact, if you look it up in a database of known Trojan horses on the Internet (www.simovits.com/trojans/trojans.html) , it matches the port number of a documented Trojan horse. There is strong evidence that this system has been exploited. At this point, you have to decide if it is worth taking the system down to do further forensic analysis of the system. Table 11.1 lists a few options you can run with Fport to sort the output. You can also use the h option to display short help descriptions.
If you have a lot of processes, you can use these switches to look at all the high port numbers running, which is typically where malware runs. You can also sort by application path or name to find nonstandard applications running.
This tool is similar to the Fport tool for Windows just discussed. The lsof tool (LiSt Open Files) associates open files with processes and users. It is like the netstat command, but in addition it reports the network port the service is using. This is important when trying to track down an active program on the network. Often the only way to find these elusive bugs is to watch for what network ports they open up. The lsof tool is being preinstalled on some UNIX and Linux distributions and is available in RPM form on the installation disks of others such as Mandrake and RedHat Linux. To see if you have it preinstalled, type lsof and see if you get any response. Installing lsofPammal K Sambandam Isaimini Fixed -is a popular Tamil comedy starring Kamal Haasan and Simran. Instead of using illegal sites that may contain malware or legal risks, you can access the film through several authorized platforms: "Pammal K. Sambandam"—a spirited Tamil romantic comedy about pride, rivalry, and unexpected love. Set in Chennai, the film follows Pammal Kalyana Sambandham (Pammal K. Sambandam), a cocky, adrenaline-loving stuntman and TV show host who prides himself on being fearless and single. Opposite him is Dr. Janaki Srinivasan, a brilliant, no-nonsense ENT surgeon engaged to Arjun, a kind and successful doctor. Janaki is fiercely independent and has little patience for showmanship and ego. When a TV network plans a special reality segment to boost ratings, Pammal is assigned to stage a stunt that goes humorously awry, injuring his arm. Janaki treats him, sparking a clash of personalities: Pammal’s flamboyance rubs Janaki the wrong way, while she challenges his shallow bravado. Their public arguments—often witty, fast-paced, and laced with Tamil cultural references—become media fodder, transforming the duo into tabloid sensations. As circumstances force Pammal and Janaki into repeated encounters—hospital visits, charity events, and televised debates—their rivalry slowly softens. Pammal discovers layers beneath Janaki’s stern exterior: warmth, vulnerability, and a commitment to family that mirrors his own unspoken values. Janaki, in turn, glimpses the sincerity behind Pammal’s bravado: loyalty, courage, and a capacity to care beyond the spotlight. Conflict escalates when Pammal’s past—his loyalty to his younger brother and old debts—threatens his career, and Janaki’s engagement to Arjun creates a moral dilemma. Misunderstandings and pride keep them apart until a dramatic moment (often a life-or-death emergency or a public act of sacrifice) forces both to confront what truly matters. Pammal risks his life to save someone important to Janaki, showing that his recklessness masks deep devotion; Janaki reevaluates her choices and recognizes genuine love. The story resolves with pride humbled and relationships mended: Janaki calls off the engagement when she realizes her feelings; Arjun departs gracefully; Pammal and Janaki acknowledge their love, blending humor, family acceptance, and a joyous wedding sequence. The film ends celebrating love that overcomes ego, with energetic songs, comedic side characters, and a message that true courage includes vulnerability. Themes: pride vs. humility, public image vs. private truth, and how opposites attract when they reveal their authentic selves. If you’d like, I can write this as a short story, a film treatment, or a scene-by-scene screenplay—tell me which format you prefer. Pammal K. Sambandam (2002) is a celebrated Tamil romantic comedy directed by Mouli and written by the legendary humorist Crazy Mohan . Starring Kamal Haasan , the film remains a cult favorite for its witty dialogue, slapstick timing, and the vibrant chemistry between its leads. Narrative Summary The story follows Pammal K. Sambandam (Kamal Haasan), a rugged movie stuntman and staunch bachelor who despises the institution of marriage. His views clash with Dr. Janaki (Simran), a strong-willed physician who harbors a similar disdain for men and marriage. The Conflict: The plot is set in motion when Sambandam’s brother, Anand, marries Janaki’s friend, Malathi. Influenced by Janaki’s cynical views, Malathi refuses to be intimate with Anand, leading to a rift that Sambandam and Janaki both try to manage from their respective sides. The "Fixed" Climax: The chaotic finale involves a series of misunderstandings regarding an ancestral lodge. Sambandam is forced to marry a relative to retain ownership, but in a classic "fixed" comedic resolution, he and Janaki realize their mutual love and elope together, ensuring both their happiness and the legal safety of the lodge. Production & Legacy Creative Team: The film features a soundtrack by and was produced by Media Dreams. Commercial Success: Released on Pongal Day in 2002, the film was a major commercial hit. Critics often highlight that while the plot is light, the real "high point" is the rapid-fire, pun-filled dialogue written by Crazy Mohan. Kamal Haasan's Performance: Haasan’s portrayal of a stuntman allowed him to showcase his physical comedy and unique dialect, further cementing the film as a staple of early 2000s Tamil cinema. Cultural Impact Available on platforms like , the movie is frequently revisited for its "Laugh-a-minute" segments. Its influence is such that specific dialogue sequences are still used in comedy shows and parodies across Tamil media today. classic comedy collaborations between Kamal Haasan and Crazy Mohan, or perhaps details on the of this film in other languages? The phrase "Pammal K Sambandam Isaimini Fixed" refers to the availability of the 2002 Tamil comedy classic Pammal K. Sambandam on various digital platforms, often following a period where links on third-party sites like Isaimini may have been broken or updated. Movie Overview Directed by Moulee and written by the legendary Crazy Mohan, this film is celebrated for its rapid-fire wit and comedic timing. Plot: The story follows Sambandam (Kamal Haasan), a bachelor stuntman who despises the concept of marriage ("Kalyanam"), and Dr. Janaki (Simran), a surgeon who shares a similar disdain for the opposite gender. Their lives collide when they both try to sabotage the marriage of their respective siblings, leading to a series of slapstick misunderstandings. The "K" Mystery: A recurring theme in the movie is the initial "K" in Sambandam's name, which he eventually reveals stands for "Kalyanam," a word he hilariously tries to censor throughout the film. Iconic Surgery Scene: One of the film's most famous sequences involves a surgical mishap where a wristwatch is accidentally left inside a patient, leading to a chaotic cover-up attempt. Where to Watch Legally pammal k sambandam isaimini fixed While search queries often lead to third-party sites, the "fixed" versions or high-quality streams of Pammal K. Sambandam are officially available on the following platforms: Sun NXT: Available with a subscription for high-definition streaming. Zee5: Often available for free or with a basic subscription. YouTube: Full versions are frequently uploaded by official channels like Ayngaran International. Key Cast and Crew Pammal K. Sambandam Kamal Haasan Dr. Janaki Anand Malathi Director Music I notice you're mentioning "Pammal K. Sambandam" (a Tamil film) and "Isaimini" (a website known for pirating Tamil movies), along with the word "fixed." If you're looking for a legitimate way to watch or download Pammal K. Sambandam, I recommend using legal streaming platforms like Amazon Prime Video, Sun NXT, or YouTube official channels, depending on regional availability. If "fixed" refers to correcting or repairing something related to the film or its digital copy, could you clarify what issue you're facing? That way I can provide more helpful guidance without promoting piracy. Plot: The story follows Sambandam (Kamal Haasan), a stuntman who is staunchly against marriage, and Janaki (Simran), a doctor who shares the same disdain for matrimony. Their initial mutual dislike eventually turns into love after a series of comedic misunderstandings. Remake: The film was later remade in Hindi as Kambakkht Ishq (2009) starring Akshay Kumar and Kareena Kapoor. Key Details Performance: The film is highly regarded for the comedic chemistry between the leads and the sharp dialogues written by the legendary 'Crazy' Mohan. Success: It was a commercial hit upon its release during the Pongal festival in 2002. Music: The soundtrack was composed by Deva, featuring popular tracks like the title song and "Kandhasamy Madhasamy". Official Viewing Options For a "fixed" (high-quality and legal) viewing experience, you can find the movie on these platforms: Apple TV: Available for streaming or purchase. YouTube: Often hosted legally by official South Indian film channels like Rajshri Tamil or Pyramid Glitz. Amazon Prime Video: Frequently available in various regions under its Tamil film library. Pammal K Sambandam Isaimini Fixed: A Comprehensive Analysis The Tamil film industry, also known as Kollywood, has been a significant contributor to the country's cinematic landscape. With a rich history spanning over a century, the industry has produced numerous iconic films that have captivated audiences worldwide. One such film that has garnered immense attention in recent times is "Pammal K Sambandam." This article aims to provide an in-depth analysis of the film's connection to Isaimini, a popular piracy website, and the implications of the "Pammal K Sambandam Isaimini Fixed" phenomenon. Introduction to Pammal K Sambandam Pammal K Sambandam is a 2002 Tamil comedy film directed by Balasekaran and starring Jayabharathi, Ramana, and Vijayakumar in the lead roles. The film revolves around the life of a retired employee, Pammal K Sambandam, who gets involved in various humorous situations. The movie received positive reviews from critics and audiences alike, praising its witty dialogues and engaging storyline. The Rise of Isaimini Isaimini is a notorious piracy website that has been operational for several years, notorious for leaking copyrighted content, including movies, TV shows, and music. The website has been a thorn in the side of the Indian film industry, with many producers and distributors suffering significant losses due to piracy. Despite efforts to shut down the website, it continues to operate, albeit in a cat-and-mouse game with authorities. The Connection between Pammal K Sambandam and Isaimini The "Pammal K Sambandam Isaimini Fixed" phenomenon refers to the widespread availability of the film on the Isaimini website. The film, released in 2002, has been uploaded on the website, allowing users to download and stream it for free. This has led to a surge in the film's popularity, with many viewers discovering it through the piracy website. is a popular Tamil comedy starring Kamal Haasan and Simran Impact of Piracy on the Film Industry The proliferation of piracy websites like Isaimini has significant implications for the film industry. Piracy leads to substantial revenue losses, affecting not only producers but also the livelihoods of thousands of people involved in the film's production, distribution, and exhibition. Furthermore, piracy undermines the value of creative content, discouraging investment in new projects and stifling innovation. The "Pammal K Sambandam Isaimini Fixed" Conundrum The "Pammal K Sambandam Isaimini Fixed" phenomenon raises several questions. How did a nearly two-decade-old film become so popular on a piracy website? What does this say about the viewing habits of Tamil audiences? And what are the implications for the film industry, particularly in terms of revenue and intellectual property protection? Theories behind the Phenomenon Several factors contribute to the "Pammal K Sambandam Isaimini Fixed" phenomenon:
The Battle against Piracy The film industry has been actively combating piracy, with various stakeholders collaborating to address the issue. Producers, distributors, and authorities have joined forces to shut down piracy websites, including Isaimini. Additionally, initiatives like the Film Industry's Anti-Piracy Cell and the Tamil Nadu government's anti-piracy measures aim to curb the spread of pirated content. Conclusion The "Pammal K Sambandam Isaimini Fixed" phenomenon highlights the complex issues surrounding piracy, creative content, and viewer behavior. While piracy websites like Isaimini continue to pose a significant threat to the film industry, the enduring popularity of Pammal K Sambandam demonstrates the power of nostalgic value and cultural significance. As the industry adapts to changing viewer habits and evolving technologies, it is essential to prioritize intellectual property protection, develop legitimate streaming options, and promote a culture of respect for creative content. Future Directions The film industry must continue to innovate and adapt to the changing landscape. Key takeaways from the "Pammal K Sambandam Isaimini Fixed" phenomenon include:
By understanding the complexities of the "Pammal K Sambandam Isaimini Fixed" phenomenon, the film industry can develop effective strategies to mitigate piracy, protect creative content, and foster a thriving cinematic ecosystem. Overview of Pammal K Sambandam"Pammal K Sambandam" could refer to a character, a film, a story, or a concept within Tamil culture. Given the structure of the name, it seems like it could be a person's name or a title of a work. The Need for PreservationThe desire to watch Pammal K. Sambandam is understandable—it is a cinematic comfort food for many. However, the reliance on pirated "fixed" prints does a disservice to the artistry involved. Kamal Haasan’s own production house, Rajkamal International, invested heavily in the quality of the production. Watching a compressed, potentially malware-ridden file from a piracy site degrades the visual and auditory experience that was originally intended. As the film industry moves toward legitimate streaming platforms, there is a growing push to digitize these classics in high definition, offering a legal and superior alternative to the "fixed" prints of the grey market. This not only preserves the film for future generations but ensures that the legacy of the artists is respected. The Enduring Legacy of Pammal K. Sambandam and the Battle Against PiracyIn the landscape of early 2000s Tamil cinema, a specific brand of "madcap comedy" reigned supreme. At the forefront of this movement was the 2002 cult classic, Pammal K. Sambandam. Directed by the comedy maestro Moulee and produced by the acclaimed actor Kamal Haasan, the film remains a benchmark for ensemble comedy in Indian cinema. However, like many successful films, its legacy is often entangled with the darker side of the digital age: the persistent specter of piracy. A Masterclass in ComedyTo understand the film's enduring popularity—one that drives search trends even today—one must look at its construction. Pammal K. Sambandam was not just a star vehicle; it was a symphony of comedians. The film brought together an unparalleled cast including Kamal Haasan, Simran, Abbas, Sneha, and a supporting lineup of veterans like Ramesh Khanna, Vyapuri, Venu Madhav, and Nagesh. The plot revolved around a complex web of misunderstandings and marital discord, treated with a lightheartedness that allowed the actors to shine. Kamal Haasan, playing the title role of a stuntman with a heart of gold but a brain full of straw, delivered a performance that balanced slapstick with genuine charisma. The dialogue, sharp and rapid-fire, became the backbone of the film’s success, ensuring it found a permanent home in cable television reruns and meme culture. Summary Answer
If you need help finding the official legal source for this movie, let me know. The phrase "Pammal K. Sambandam Isaimini Fixed" refers to a humorous and iconic plot point from the 2002 Tamil comedy film Pammal K. Sambandam . In the movie, the protagonist, a stuntman who despises marriage, finds himself in a "fixed" (stuck) situation that drives the entire comedic narrative. The Story of the "Fixed" Watch Nostalgia : The film's availability on Isaimini may The most famous "interesting story" within the film involves a surgical mishap where a wristwatch becomes fixed inside the lead character’s body: The Stuntman and the Doctor: Sambandam (played by Kamal Haasan) is a bachelor stuntman who meets Dr. Janaki (played by Simran), a surgeon who also dislikes the idea of marriage. The Accident: During a chaotic movie shoot involving a bull and a snake, Sambandam is gored while trying to save Janaki. The Surgery: Janaki performs emergency surgery to save his life. However, in the stress of the moment, she accidentally leaves her wristwatch inside his stomach. The "Fixed" Problem: Once Sambandam recovers, the watch begins to beep from inside him at regular intervals. This "fixed" object causes him immense embarrassment and physical discomfort, leading to a series of hilarious attempts to retrieve it without him knowing she was the one who left it there. Cultural Context The Title: The name was inspired by Pammal Sambandha Mudaliar, the "founding father of modern Tamil theatre". Legacy: This specific plot point—a medical tool left inside a patient—was so successful it was later remade in Bollywood as the film Kambakkht Ishq. You can watch the full movie here to see the chaotic surgery scene and the 'fixed' watch dilemma play out: Pammal K Sambandam is a 2002 Tamil-language romantic comedy film that has remained a classic due to its lighthearted script and the comedic chemistry between its leads. Directed by Moulee and written by Crazy Mohan, the movie features Kamal Haasan and in the primary roles. Movie Overview The film follows Sambandam (Kamal Haasan), a movie stuntman with a cynical view of marriage, and Dr. Janaki (Simran), a surgeon who shares a similar distaste for the opposite gender. Kamal Haasan Pammal K. Sambandam Pammal K. Sambandam is a 2002 Indian Tamil-language comedy film that remains a notable entry in the filmographies of Kamal Haasan and Simran. The movie is widely recognized for its witty dialogue, comedic timing, and "Madras Tamil" slang. 1. Production and Technical Credits Mouli (also known as Moulee). Screenplay & Dialogues: "Crazy" Mohan. P. L. Thenappan under the banner Media Dreams. Music Composer: Cinematographer: Arthur Wilson Release Date: January 14, 2002 (Pongal Day). 2. Lead and Supporting Cast The film features an ensemble cast led by some of the most prominent actors in Tamil cinema: Kamal Haasan as Pammal K. Sambandam, a single movie stuntman. as Dr. Janaki, a surgeon who initially despises Sambandam. as Anand, Sambandam’s younger brother. as Malathi, Janaki's best friend and Anand’s wife. Supporting Cast: Ramesh Khanna Manivannan Madhan Bob Crazy" Mohan in a cameo as an ENT specialist 3. Plot Summary Pammal K. Sambandam " typically refers to the 2002 Tamil comedy film starring Kamal Haasan and Simran. However, the name itself is an homage to Pammal Sambandha Mudaliar (1873–1964), widely revered as the "Founding Father of Modern Tamil Theatre". Your request includes keywords like "Isaimini" (a popular website for music and movie downloads) and "Fixed," which often appear in online search queries for specific media files or site updates. The Legacy of Pammal Sambandha Mudaliar Pammal Sambandha Mudaliar revolutionized Tamil drama by introducing structured scripts and moving away from traditional puranic musicals toward prose dialogue. Innovations : He shortened plays to roughly three hours (down from six or more) and emphasized narrative over song. Suguna Vilasa Sabha : In 1891, he founded this amateur theatre group to "revive and reform" Tamil drama, ensuring that it was seen as a respectable profession for educated individuals. Literary Contributions : He wrote over 90 plays, including adaptations of Shakespeare and original works like Sabhapathi The Film: Pammal K. Sambandam (2002) The film is a lighthearted comedy that borrows the name of the theatre legend for its protagonist. : A bachelor stuntman (Kamal Haasan) and a doctor (Simran) find themselves at odds after she accidentally leaves a surgical watch inside him during an operation. : Scripted by the legendary "Crazy" Mohan, the film was a major commercial hit and later served as the basis for the Hindi film Kambakkht Ishq Music and "Isaimini Fixed" You are now ready to start using lsof. Using lsofThe lsof program has many uses, and has extensive man pages and several README files for the different applications. However, this section concentrates only on a few specific commands that are useful for forensic research. If you want to see all of the open files on your system at any given moment and the processes associated with them, type: lsof -n The -n option tells lsof not to attempt to do a DNS record on any IP addresses connecting to your machine. This speeds up the process considerably. The output will look something like Listing 11.2 Listing 11.2. lsof n outputCOMMAND PID USER FD TYPE DEVICE SIZE NODE xfs 903 xfs 0r DIR 3,1 4096 2 atd 918 daemon rtd DIR 3,1 4096 2 atd 918 daemon txt REG 3,6 14384 273243 /usr/sbin/atd sshd 962 root cwd DIR 3,1 4096 2 sshd 962 root rtd DIR 3,1 4096 2 sshd 962 root txt REG 3,6 331032 274118 /usr/sbin/sshd dhcpcd 971 root cwd DIR 3,1 4096 2 dhcpcd 971 root rtd DIR 3,1 4096 2 dhcpcd 971 root txt REG 3,1 31576 78314 /sbin/dhcpcd xinetd 1007 root cwd DIR 3,1 4096 2 5u IPv4 1723 TCP 127.0.0.1:1024 (LISTEN) xinetd 1007 root 8u unix 0xc37a8540 1716 rwhod 1028 root cwd DIR 3,1 4096 61671 /var/spool/rwho rwhod 1028 root rtd DIR 3,1 4096 61671 /var/spool/rwho rwhod 1028 tim cwd DIR 3,1 4096 61671 /var/spool/rwho crond 1112 root cwd DIR 3,1 4096 14 /var/spool crond 1112 root 1w FIFO 0,5 1826 1112 root 2w FIFO 0,5 1827 pipe nessusd 1166 root cwd DIR 3,1 4096 2 nessusd 1166 root rtd DIR 3,1 4096 2 nessusd 1166 root txt REG 3,6 1424003 323952 init 1 root cwd DIR 3,1 4096 2 init 1 root rtd DIR 3,1 4096 2 init 1 root txt REG 3,1 31384 75197 The connections in this listing look normal. The connection via the rwho service might give you pause. You would want to make sure that a valid user on your system is using this command legitimately. If this account belonged to a nontechnical secretary type, you might want to investigate this further. You can also use lsof to look for a specific file. If you want to see if anyone was accessing your password file, you could use the following command:
lsof path/filename
Replace path/filename with the specific path and filename you are interested in, in this case, /etc/passwd. You have to give lsof the whole path for it to find the file. Another way to use lsof is to have it list all the open socket files. This shows if there is a server listening that you don't know about. The format of this command is: lsof i This produces output similar to Listing 11.3. You can see all the programs you are running, including sshd and nessusd, which are the daemons for Nessus and SSH. You can even see the individual connections to these services. It looks like someone is using the Nessus server at the moment. Checking the IP address, you can see that it is an internal user. In fact, it is your own machine! So there is nothing to worry about this time. Listing 11.3. lsof i OutputCOMMAND PID USER FD TYPE DEVICE SIZE NODE NAME portmap 733 rpc 3u IPv4 1417 UDP *:sunrpc portmap 733 rpc 4u IPv4 1426 TCP *:sunrpc (LISTEN) sshd 962 root 3u IPv4 1703 TCP *:ssh (LISTEN) xinetd 1007 root 5u IPv4 1728 TCP localhost.localdomain:1024 (LISTEN) rwhod 1028 root 3u IPv4 1747 UDP *:who nessusd 1166 root 4u IPv4 1971 TCP *:1241 (LISTEN) nessusd 1564 root 5u IPv4 1972 TCP 192.168.1.101:1241->192.168.1.2:1994 You can specify a particular IP address or host to look for by putting an @ (at sign) and the address after the -i switch. For example: lsof -i@192.168.1.0/24 shows any connections coming from within your network, assuming your internal network is 192.168.1.0/24. | ||||||||||||||||||||||||
|
|
< Day Day Up > |
|