General Program for collecting evidence using linux-general Linux technology-Linux programming and kernel information. The following is a detailed description. In the redhat linux family
Step 1 determine the system: cat/etc/redhat-release
Red Hat Enterprise Linux AS release 4 (Nahant Update 4)
Step 2 determine the host name, IP address, and other network settings
Step 4: Check who has logged in and where it came from
[Root @ localhost t] # cat var/log/secure
Nov 5 10:54:49 apollo in. telnetd [680]: connect from 207.239.115.11
Nov 6 02:59:23 apollo in. ftpd [973]: connect from 128.121.247.126
Nov 8 00:08:40 apollo in. telnetd [2077]: connect from 216.216.74.2
Nov 8 00:08:40 apollo in. telnetd [2078]: connect from 216.216.74.2
[Root @ localhost t] #
Part 5 check the program startup and shutdown processes
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.