Forensics 12. Use of lsof

The sian program being run by user 'bob' turns out to be our old friend eggdrop again:

  bash# lsof -p 18276
  [...]
  sian 18276 bob 3u inet TCP *:8000
  sian 18276 bob 4u inet TCP foo:59372->bar1:6667
  sian 18276 bob 5u inet TCP foo:59795->bar2:9000

We asked what files process 18276 (sian) was using - found that it was listening on port 8000 for TCP connections and also connected in turn to bar1 and bar2