- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - checking for remote logging... holy guacamole batman REMOTE LOGGING DETECTED I hope you can get to these other computer(s): 000.000.00.000 cuz this computer is LOGGING to it... - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - How this could be acomplished is intresting, i guess it sent something that just HAD to be logged by the system, then it checked if some kind of remote traffic was initiated at the same time, i.e. Syslogd traffic to some remote system. I'd encrypted this data, and transmit data on regular times, and definitly on some other port than Syslog normally would use, not at the time when it would be suspicious. So anyway...