>If your system has been compromised the commands you need include
>'[sc]fdisk', 'mke2fs' and similar, followed by a data restore. I would
>not try to restore from a backup to a compromised system. If you wish
>to ignore that advice then carry out a full restore to another disk and do
>a recursive diff between the two filesystems.
Where did you get the idea that I'm restoring from the backup? I never said that. I said I wanted to audit the system!
The reason I'm interested in this is because rdiff-backup would allow me to see file changes over time...
I'm NOT looking for restoration.