看板FB_security
標 題Re: Hacked or not ?
發信站NCTU CSIE FreeBSD Server (Sat Jun 12 13:39:34 2004)
轉信站ptt!FreeBSD.csie.NCTU!not-for-mail
On Sat, 12 Jun 2004 14:39:21 +0200
"Peter Rosa" <
[email protected]> wrote:
PR> But what about the /var/log/messages logs absence ?
PR> And, how to test the machine, if it is healthy ?
Boot from CD and compare md5 checksums on system files. That's the first step.
Compare your kernel sources with clean ones, rebuild kernel and compare it with the running one. If you're running GENERIC, compare it with the distributed one.
Compare /modules directory with distribution one.
Check your (and system) .profile or .login etc.
After this step, you should have reasonably clean system.
--
Alex.
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"