Answer the question
In order to leave comments, you need to log in
How to identify if the server was hacked or not?
Hello. Recently, I noticed excessive activity on the network on my server, although I have many services installed, but there should not have been any activity, since ip, like the domain, I almost didn’t shine anywhere,
tell me how to fully monitor the network in linux debian 10?
And how can you detect a hack if there is one?
Answer the question
In order to leave comments, you need to log in
Here, in theory, there should be a Barmin patch :) But it won’t, because it will actually use it :)
although I have many services installed .... tell me how to fully monitor the network in linux debian 10We got into the car, pressed the gas, but you don’t know how to steer and slow down?)))
Traffic? Look at least at /var/log/auth.log, some services add authorization events there, including attempts to crack / guess a password. Maybe just network scanners are hammering you, trying to break through, that's the traffic ...
Find out if they've been hacked? You can check the binaries of installed programs with the debsums utility in case they are modified. Antivirus programs for UNIX-like also exist, you can use it.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question