On Sun, Jul 24, 2005 at 07:40:21PM +0200, Nejc Novak wrote: > that means, that the process was started at 17:31 today. So i checked
> I killed the process and webserver and at 19:31 the process again > started with the same lines in syslog. Check your crontabs (in various locations) and atq. It sounds as if the attackers have added something there. // Ulf -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]