2 Mar
2021
2 Mar
'21
20:53
On 02/03/2021 20.07, colony.three@protonmail.ch wrote:
‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐ On Tuesday, March 2, 2021 10:46 AM, James Knott
wrote: btw, the shadow password file was changed at the same time as that .dhcpd file was created. Since there were only 3 login password in it and I know 2 of them still work, I assume the test account password was changed.
Game over. He's rooted you.
Maybe not, if he directly loged in as "test". Should be in the log. If he were root, he would have deleted the traces.
Wish you'd respond to my questions so it may help the rest of us.
-- Cheers / Saludos, Carlos E. R. (from 15.2 x86_64 at Telcontar)