Fri Feb 21 19:06:40 HKT 2003
================================

Connected to ttyp0 snoop server...
Ctrl+'\' (ASCII 28) to suspend, Ctrl+'-' (ASCII 31) to terminate.
w
  7:06pm  up  4:47,  0 users,  load average: 0.15, 0.03, 0.01
USER     TTY      FROM              LOGIN@   IDLE   JCPU   PCPU  WHAT
]0;root@pc88: /root[root@pc88 /root]# cd /usr/bin/.tux/tools
]0;root@pc88: /usr/bin/.tux/tools[root@pc88 tools]# cd sniffer
]0;root@pc88: /usr/bin/.tux/tools/sniffer[root@pc88 sniffer]# ./read tcp.log
Fri Feb 21 19:07:10 HKT 2003
-rw-r--r--   1 root     root         4994 Feb 21 16:50 tcp.log
----------------------------------------------------------------------
106   pc88                        
----------------------------------------------------------------------
Fri Feb 21 19:07:10 HKT 2003
-------------------------------------------------------------------EOF
]0;root@pc88: /usr/bin/.tux/tools/sniffer[root@pc88 sniffer]# cd ..
]0;root@pc88: /usr/bin/.tux/tools[root@pc88 tools]# ls
bitchx         psybnc         sniffer        ssh
ecmf           psymicutz.tgz  socklist       synscan
exploits       scan           socklist.tgz   utils
]0;root@pc88: /usr/bin/.tux/tools[root@pc88 tools]# ./socklist
type  port      inode     uid    pid   fd  name
tcp    513       1202       0    840    8  xinetd
tcp    514       1201       0    840    7  xinetd
tcp    995       1203       0    840    9  xinetd
tcp   1030        918      29    591    6  rpc.statd
tcp   1607        373       0    214    4  java
tcp   6668        355       0    203    3  sshdu
tcp    143       1204       0    840   10  xinetd
tcp    111        870       0    569    4  portmap
tcp     80       6127       0   1112   17  httpd
tcp    465       1124       0    785    3  atd
tcp  10003         14       0     19    3  smbd
tcp     21       1198       0    840    3  xinetd
tcp     22       1382       0    979    3  data_mining
tcp     23       1200       0    840    5  xinetd
tcp     25       1279       0    895    4  sendmail
tcp   6010     514695       0  19255    3  data_mining
tcp    443       6126       0   1112   16  httpd
tcp   1035     514755       0  19282    5  number_cum
tcp     22     514690       0  19255    4  data_mining
tcp   1607     514017       0  19189    3  java
udp   1024        915      29    591    5  rpc.statd
udp    514     506961       0  19157    7  syslogd
udp     69       1199       0    840    4  xinetd
udp   3049      13980       0   1576    5  who
udp    111        869       0    569    3  portmap
udp    123       1421       0    995    6  ntpd
udp    123       1420       0    995    5  ntpd
udp    123       1419       0    995    4  ntpd
udp    767        908       0    591    4  rpc.statd
]0;root@pc88: /usr/bin/.tux/tools[root@pc88 tools]# telnet localhost 10003
Trying 127.0.0.1...
Connected to localhost.localdomain (127.0.0.1).
Escape character is '^]'.
SSH-1.5-By-ICE_4_All ( Hackers Not Allowed! )

Connection closed by foreign host.
]0;root@pc88: /usr/bin/.tux/tools[root@pc88 tools]# killall -9 -vq sshdu smbd' 
]0;root@pc88: /usr/bin/.tux/tools[root@pc88 tools]# kill -9 203 19
]0;root@pc88: /usr/bin/.tux/tools[root@pc88 tools]# ./socklist
type  port      inode     uid    pid   fd  name
tcp    513       1202       0    840    8  xinetd
tcp    514       1201       0    840    7  xinetd
tcp    995       1203       0    840    9  xinetd
tcp   1030        918      29    591    6  rpc.statd
tcp   1607        373       0    214    4  java
tcp    143       1204       0    840   10  xinetd
tcp    111        870       0    569    4  portmap
tcp     80       6127       0   1112   17  httpd
tcp    465       1124       0    785    3  atd
tcp     21       1198       0    840    3  xinetd
tcp     22       1382       0    979    3  data_mining
tcp     23       1200       0    840    5  xinetd
tcp     25       1279       0    895    4  sendmail
tcp   6010     514695       0  19255    3  data_mining
tcp    443       6126       0   1112   16  httpd
tcp   1035     514755       0  19282    5  number_cum
tcp     22     514690       0  19255    4  data_mining
tcp   1607     514017       0  19189    3  java
udp   1024        915      29    591    5  rpc.statd
udp    514     506961       0  19157    7  syslogd
udp     69       1199       0    840    4  xinetd
udp   3049      13980       0   1576    5  who
udp    111        869       0    569    3  portmap
udp    123       1421       0    995    6  ntpd
udp    123       1420       0    995    5  ntpd
udp    123       1419       0    995    4  ntpd
udp    767        908       0    591    4  rpc.statd
]0;root@pc88: /usr/bin/.tux/tools[root@pc88 tools]# cd psybnc
]0;root@pc88: /usr/bin/.tux/tools/psybnc[root@pc88 psybnc]# pico psybnc.conf
[?1048h[?1047h   UW PICO(tm) 4.0                New Buffer                                    ^G Get Help  ^O WriteOut  ^R Read File ^Y Prev Pg   ^K Cut Text  ^C Cur Pos   ^X Exit      ^J Justify   ^W Where is  ^V Next Pg   ^U UnCut Text^T To Spell  [ Reading file ][ Read 31 lines ]File: psybnc.confPSYBNC.SYSTEM.PORT1=6668PSYBNC.SYSTEM.HOST1=*PSYBNC.HOSTALLOWS.ENTRY0=*;*USER1.USER.LOGIN=sokeresUSER1.USER.USER=No InfoUSER1.USER.PASS=='I`J1v`z'd1o'70q1DUSER1.USER.RIGHTS=1USER1.USER.VLINK=0USER1.USER.PPORT=0USER1.USER.PARENT=0USER1.USER.QUITTED=0USER1.USER.DCCENABLED=1USER1.USER.AUTOGETDCC=0USER1.USER.AIDLE=0USER1.USER.LEAVEQUIT=0USER1.USER.AUTOREJOIN=1USER1.USER.SYSMSG=1USER1.USER.LASTLOG=0USER1.USER.AWAYNICK=micutzuUSER1.USER.QUITTED=0USER1.USER.DCCENABLED=1USER1.USER.AUTOGETDCC=0AIDLE=0LEAVEQUIT=0 AUTOREJOIN=1SYSMSGLASTLOG=0AWAYNICK=micutzuAWAY=^C4Nu m?ncred dec‚t Žn mine. ^_^BE mai bine!LEAVEMSG=Urmarit cautat De Toata Politia !VHOST=pc88.ie.cuhk.edu.hkNICK=mIcUtZzuCHANNELS.ENTRY6=#purelinuxCHANNELS.ENTRY8=#h-zoneCHANNELS.KEY6=r00tCHANNELS.ENTRY9=#iubaretziiSERVERS.SERVER1=atlanta.ga.us.undernet.orgSERVERS.PORT3=6667   LEAVEMSG=Urmarit cautat De Toata Politia !VHOST=pc88.ie.cuhk.edu.hkNICK=mIcUtZzuCHANNELS.ENTRY6=#purelinuxCHANNELS.ENTRY8=#h-zoneCHANNELS.KEY6=r00tCHANNELS.ENTRY9=#iubaretziiSERVERS.SERVER1=atlanta.ga.us.undernet.orgSERVERS.PORT3=6667   SERVERS.SERVER3=irc.hell.nlSERVERS.PORT1=6667[ line 32 of 32 (100%), character 873 of 873 (100%) ]Modified             Y Yes                                                            C Cancel    N No                                                             Save modified buffer (ANSWERING "No" WILL DESTROY CHANGES) ?                    No[?1047l[?1048l]0;root@pc88: /usr/bin/.tux/tools/psybnc[root@pc88 psybnc]# 
]0;root@pc88: /usr/bin/.tux/tools/psybnc[root@pc88 psybnc]# ./fam
.-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-.
 ,----.,----.,-.  ,-.,---.,--. ,-.,----. 
 |  O ||  ,-' \ \/ / | o ||   \| || ,--' 
 |  _/ _\  \   \  /  | o< | |\   || |__  
 |_|  |____/   |__|  |___||_|  \_| \___| 
      Version 2.2.2 (c) 1999-2001
              the most psychoid          
      and  the cool lam3rz Group IRCnet  
                                         
`-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=tCl=-'
Configuration File: psybnc.conf
No logfile specified, logging to log/psybnc.log
Listening on: 0.0.0.0 port 6668
psyBNC2.2.2-cBtITLdDMSNp started (PID 19330)
]0;root@pc88: /usr/bin/.tux/tools/psybnc[root@pc88 psybnc]# cd ..
]0;root@pc88: /usr/bin/.tux/tools[root@pc88 tools]# ./socklist
type  port      inode     uid    pid   fd  name
tcp    513       1202       0    840    8  xinetd
tcp    514       1201       0    840    7  xinetd
tcp    995       1203       0    840    9  xinetd
tcp   1030        918      29    591    6  rpc.statd
tcp   1607        373       0    214    4  java
tcp   6668     520381       0  19330    9  fam
tcp    143       1204       0    840   10  xinetd
tcp    111        870       0    569    4  portmap
tcp     80       6127       0   1112   17  httpd
tcp    465       1124       0    785    3  atd
tcp     21       1198       0    840    3  xinetd
tcp     22       1382       0    979    3  data_mining
tcp     23       1200       0    840    5  xinetd
tcp     25       1279       0    895    4  sendmail
tcp   6010     514695       0  19255    3  data_mining
tcp    443       6126       0   1112   16  httpd
tcp   6668     522291       0  19330   14  fam
tcp   6668          0       0      0    0  
tcp   1037     520389       0  19330   13  fam
tcp   1035     514755       0  19282    5  number_cum
tcp     22     514690       0  19255    4  data_mining
tcp   6668          0       0      0    0  
tcp   1607     514017       0  19189    3  java
udp   1024        915      29    591    5  rpc.statd
udp    514     506961       0  19157    7  syslogd
udp     69       1199       0    840    4  xinetd
udp   3049      13980       0   1576    5  who
udp    111        869       0    569    3  portmap
udp    123       1421       0    995    6  ntpd
udp    123       1420       0    995    5  ntpd
udp    123       1419       0    995    4  ntpd
udp    767        908       0    591    4  rpc.statd
]0;root@pc88: /usr/bin/.tux/tools[root@pc88 tools]# ifconfig
lo        Link encap:Local Loopback  
          inet addr:127.0.0.1  Bcast:127.255.255.255  Mask:255.0.0.0
          UP LOOPBACK RUNNING  MTU:16436  Metric:1
          RX packets:1280 errors:20 dropped:0 overruns:0
          TX packets:0 errors:0 dropped:0 overruns:1280

eth0      Link encap:10Mbps Ethernet  HWaddr 00:50:56:49:80:55
          inet addr:192.168.20.1  Bcast:192.168.20.255  Mask:255.255.255.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:895234 errors:12582 dropped:0 overruns:0
          TX packets:0 errors:0 dropped:0 overruns:681821
          Interrupt:11 Base address:0x1080 

]0;root@pc88: /usr/bin/.tux/tools[root@pc88 tools]# 
Back at local tty.
end at Fri Feb 21 19:10:28 HKT 2003
----------------------------------