hacking:determine_if_your_computer_is_hacked
Differences
This shows you the differences between two versions of the page.
Next revision | Previous revision | ||
hacking:determine_if_your_computer_is_hacked [2020/11/26 22:15] – created peter | hacking:determine_if_your_computer_is_hacked [2020/11/26 22:28] (current) – peter | ||
---|---|---|---|
Line 2: | Line 2: | ||
- | ===== Show a listing of last logged in users ===== | + | ===== Show a listing of users currently |
<code bash> | <code bash> | ||
Line 28: | Line 28: | ||
</ | </ | ||
+ | ---- | ||
+ | |||
+ | ===== Show a listing of last logged in users ===== | ||
+ | |||
+ | <code bash> | ||
+ | last | ||
+ | </ | ||
+ | |||
+ | returns: | ||
+ | |||
+ | <code bash> | ||
+ | ... | ||
+ | peter :0 : | ||
+ | reboot | ||
+ | peter :0 : | ||
+ | reboot | ||
+ | peter :0 : | ||
+ | reboot | ||
+ | peter :0 : | ||
+ | reboot | ||
+ | peter :0 : | ||
+ | reboot | ||
+ | peter :0 : | ||
+ | reboot | ||
+ | ... | ||
+ | </ | ||
+ | |||
+ | |||
+ | ---- | ||
+ | |||
+ | ===== Show last command by a user ===== | ||
+ | |||
+ | <code bash> | ||
+ | tail -n 100 ~/ | ||
+ | </ | ||
+ | |||
+ | returns: | ||
+ | |||
+ | <code bash> | ||
+ | ... | ||
+ | df | ||
+ | htop | ||
+ | ip addr | ||
+ | sudo apt update | ||
+ | sudo apt upgrade | ||
+ | systemd-resolve --status | ||
+ | sudo systemctl restart systemd-resolved | ||
+ | exit | ||
+ | ... | ||
+ | </ | ||
+ | |||
+ | ---- | ||
+ | |||
+ | ===== Find System Files that have recently changed ===== | ||
+ | |||
+ | <code bash> | ||
+ | sudo find /etc /var -mtime -2 | ||
+ | </ | ||
+ | |||
+ | returns: | ||
+ | |||
+ | <code bash> | ||
+ | ... | ||
+ | /etc | ||
+ | /etc/apport | ||
+ | / | ||
+ | / | ||
+ | / | ||
+ | / | ||
+ | /etc/grub.d | ||
+ | / | ||
+ | / | ||
+ | / | ||
+ | / | ||
+ | ... | ||
+ | </ | ||
hacking/determine_if_your_computer_is_hacked.1606428956.txt.gz · Last modified: 2020/11/26 22:15 by peter