PDA

View Full Version : Find compromised PCs on network....


Hagforce
8th May 2006, 13:38
Hello

I see thet some ISPs send out mail that your PC (based on ip adress) is compromised (spyware/virus).

Is there any software\tools for linux that can provide this service for my network?.


Thanks.

falko
9th May 2006, 01:13
Have a look here: http://www.howtoforge.com/faq/1_38_en.html

Hagforce
9th May 2006, 23:09
I`m sorry I didn`t explain myself well.

I wanted to see if any of the windows clients on my network is generating traffic that indicates that their computer is infected with virus or spyware, so that I can send them a warning.

I saw a message like this from a ISP, so I would like to try to do this for my users.

falko
9th May 2006, 23:35
I guess your ISP can see this in his log files, e.g. when you send an unusual amount of emails, etc.
Maybe your router has a traffic analyzer? You can also have a look at tools such as Nagios, Zabbix, etc.