Hacked or not appendice

Peter Rosa prosa at pro.sk
Sat Jun 12 11:45:13 GMT 2004


Hi all again,

I must add, there are no log entries after June 9, 2004. "LKM" message first
apeared June 8, 2004, after this day, there is nothing in /var/messages,
/var/security .....

How could I look for suspicious LKM module ? How could I find it, if the
machine is hacked and I can not believe "ls", "find" etc. commands ?

Peter Rosa




More information about the freebsd-security mailing list