Linux.com

Question for the Author

Posted by: Anonymous Coward on April 02, 2005 04:25 AM
I'm no system administrator or security expert, but isn't executing su, w, and passwd as some of the first commands a bad idea?

I would have tried to find out what I can with regular user access and ensure that su or passwd stuff hasn't been touched. Only then would I get root access and actually try to investigate further/clean up the system.

#

Return to Tips for when hackers strike