TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: how do you know if your systems are rooted?

1 点作者 quackerhacker大约 11 年前
I have been upping all my security lately at the expense of downtime. The first signs I knew that something was wrong is when my logs were logging to /dev/null, and I had unknown ip routes. There are many tools out there for prevention and analysis (clamscan, nmap, wireshark), but I'd really love to know some methods to KNOW when something IS wrong.

1 comment

ycombinatorial9大约 11 年前
Some tools of note here: ossec, alienvault ossiem, selinux, pf, iptables etc. what you need is a hids, system accounting, and hardened os (proper acls, selinux, upto date binaries, firewalls etc).<p>Log correlation helps too. Oh and chuck in notifications for all the above (e-mail, pager etc.) and I think you should be set for future. But please remember, these are not silver bullet.