user priviledge escalation
I'm using redhat linux 6.1, I find new user tianbu created two weeks ago, I suspect the linux server is compromised by this user with root right, how can we track any priviledge escalation by this user? any history can be tracked?
|