|Last night I went to help a person accused of trying to hack their web-host. We'd been told their IP had done it, so it was either packet-sniffing-and-spoofing, a trojan on the windows box, or some rootkitting on the Linux. After some monkeying around, the Windows box was cleared of guilt. The rootkit was suspected when we discovered make and gcc to be apparently missing from the Linux. It was confirmed with ipchains not existing on the Linux, and yet ipchains blocking my UDP port scan. So, fun with rootkits.