[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Am I infected with a rootkit?



On 16/04/2023 09:19, Jesper Dybdal wrote:
And there in the bash history were 4 lines that I had not written :-(

I am certain that nobody had been in my apartment while I was gone. And even if they had, nobody with a key to my apartment would dream of writing things like the 4 lines that I found in the history file.

The 4 lines were:
md5users
sp md5users
sp /x/md5users
ps /x/md5users
There is no file named "md5users" or directory named "/x" or command named "sp" on the Debian machine.

Which shell do you use, and how is it configured? Note that bash by default does not share history between sessions, so even if someone logged in as root (via other ssh session) and typed them, they would not appear in your ssh session.

See https://mywiki.wooledge.org/BashFAQ/088, or wait for Greg to chime in with details and corrections.


--
Eduardo M KALINOWSKI
eduardo@kalinowski.com.br


Reply to: