glance into log file I sew a strange situation:
drwxr-xr-x 2 root root 4096 Nov 13 15:03 net-5-94-155-9.cust.vodafonedsl.it/
-rw-r----- 1 root adm 726 Nov 13 15:03 user.log
cat user.log
Nov 13 15:03:25 net-5-94-155-9.cust.vodafonedsl.it #026#003#001#001 #001#000#001#034#003#0037g
Nov 13 15:03:25 net-5-94-155-9.cust.vodafonedsl.it A#024��=�#026�JٿU#037�Nw���]q�Up#022�� 9�Sj��� #003/3@#005��3)E�H�,��l�B��#000>#023#002#023#003#023#001�,�0#000�̨̩̪�+�/#000��$�(#000k�#�'#000g�
Nov 13 15:03:25 net-5-94-155-9.cust.vodafonedsl.it �#024#0009�#011�#023#0003#000�#000#000=#000<#0005#000/#000�#001#000#000#000#013#000#004#003#000#001#002
Nov 13 15:03:25 net-5-94-155-9.cust.vodafonedsl.it #000#014
Nov 13 15:03:25 net-5-94-155-9.cust.vodafonedsl.it #000#035#000#027#000#036#000#031#000#030#000##000#000#000#026#000#000#000#027#000#000#000#015#0000#000.#004#003#005#003#006#003#010#007#010#010#010#011#010
inside /var/log/messages same thing:
Nov 13 15:03:25 net-5-94-155-9.cust.vodafonedsl.it #026#003#001#001 #001#000#001#034#003#0037g<9E>^?
Nov 13 15:03:25 net-5-94-155-9.cust.vodafonedsl.it A#024��=�#026�JٿU#037�Nw���]q�Up#022�� 9�<90>Sj��� #003/3@#005��3)E��<86>H<88>,<8D>�l�B��#000>#023#002#023#003#
023#001�,�0#000<9F>̨̩̪�+�/#000<9E>�$�(#000k�#�'#000g�
Nov 13 15:03:25 net-5-94-155-9.cust.vodafonedsl.it �#024#0009�#011�#023#0003#000<9D>#000<9C>#000=#000<#0005#000/#000�#001#000#000<95>#000#013#000#004#003#000#001#0
02
Nov 13 15:03:25 net-5-94-155-9.cust.vodafonedsl.it #000#014
Nov 13 15:03:25 net-5-94-155-9.cust.vodafonedsl.it #000#035#000#027#000#036#000#031#000#030#000##000#000#000#026#000#000#000#027#000#000#000#015#0000#000.#004#003#
005#003#006#003#010#007#010#010#010#011#010
exactly I don't understand if my server has been hacked