this is someone doing network admin, and web proxy admin.
because lot of it is using vi, you have no way of knowing what they did inside those vi sessions, so no way of knowing what they actually did (unless you have a backup to compare those files with).
next time, to get more valuable answers, you should be more specific, just ask one question instead of copying and pasting 30 commands.
and give more context, such as "we think we had an intrusion on our proxy server, and would like to know what may have been hacked"
|