Re: Possible hack? Logs clear & syslogd restarted...need help!

From: Bit Twister (BitTwister_at_localhost.localdomain)
Date: 02/01/04

Date: Sun, 01 Feb 2004 17:51:43 GMT

On 1 Feb 2004 09:40:54 -0800, Robert wrote:
> Is there a reason why these are clear? I never empty these manually.
> Is there something that does this automatically or am I being
> paranoid?

I'll bet you left your system on overnight and /etc/cron.daily had a
chance to run. In that directory you might find something like
logrotate which said since it is Sunday, I'll rotate the logs.

If not, you might look on for code to see if root
kits have been installed.

You also can do a
    rpm -Va | grep '..5' > /tmp/verify
to see what has changed on the system.
   man rpm
to understand /tmp/verify contents.

Relevant Pages

  • Re: forensic DNA testing
    ... kits sit unopened in crime labs and storage facilities." ... Lab tests required fully equipped labs. ... against the use of volunteers. ... I will try to reason with you. ...
  • Re: How to copy non-contiguous columns to a text file
    ... newline character sequence) by affixing, not concatenating, ... The point of my "ironic" statement above was: Garry subsequently suggested the use of SaveAs, which I prefer myself, but which leaves the very empty last line that you and he are working so hard to avoid. ... I was willing to acquiesce to avoiding it when I was do the Print#s myself; then, there was no good reason not to avoid it. ...
  • Re: An update is needed Fedora!
    ... a hard reason for PHP5 requirement. ... development SRPMs. ... > Could you send one more example for compiling, installing, configuring, etc? ... they should then be installed as an update using: rpm -Uvh ...
  • cannot replace binaries after being rootkitted
    ... `ifconfig', `pstree' and `login' are infected; ... `init' was affected (i.e. the cracker replaced my init with one that ... but I think `rpm' may be infected as well. ... very insecure FTP server and Samba (for no reason other than I was lazy ...
  • Re: New Editor for MR
    ... what they can do with RTR trains and buildings. ... They preferred to buy two RTR cars by Atlas instead of four kits by Accurail. ... Labelle and others used to be hobby shop staples. ... IMO, the main reason MR is losing readership is the same as the reason all craft and hobby magazines, all magazines in fact, are losing readership. ...