Check if the /etc/passwd file have been changed
Use commands like last, w and uptime.
2009/8/19 Eduardo Grosclaude <eduardo.grosclaude@xxxxxxxxx>
On Wed, Aug 19, 2009 at 1:57 AM, Bill Campbell<centos@xxxxxxxxxxxxx> wrote:As a corollary, the only safe way to audit a suspected system is
> You cannot trust tools like ``ps'', ``find'', ``netstat'', and
> ``lsof'' as these are frequently replaced by ones that are
> modified to hide the cracker's work.
booting your diagnostic tool from known good media (eg try a security
Live CD distro)
--
Eduardo Grosclaude
Universidad Nacional del Comahue
Neuquen, Argentina
_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
http://lists.centos.org/mailman/listinfo/centos
_______________________________________________ CentOS mailing list CentOS@xxxxxxxxxx http://lists.centos.org/mailman/listinfo/centos