Log files track the activity on a computer so administrators can see who has used the computer, what they did, how long they stayed connected, and where they came from. Since a log file can also record the activity of an unauthorized intruder, much like a surveillance camera can record a burglar breaking into a store, hackers look for the log file as soon as they get access into the computer. Script kiddies often delete the log files to prevent the administrator from seeing exactly what they did on the computer. Unfortunately, deleting the log file reveals the presence of an intruder as blatantly as using a stick of dynamite to get rid of a surveillance camera. The moment an administrator notices that someone has deleted the log file, he or she immediately knows that a hacker must be on the system. |