Tuc at T-B-O-H.NET wrote:
Something running *as* root is trying to "su" to an account which has
/bin/nologin as a shell
Jul 18 14:08:47 asgard nologin: Attempted login by root on UNKNOWN
e.g. # su avahi
cartman nologin: Attempted login by alex on /dev/ttyp7
avahi:*:558:558:Avahi Daemon User:/nonexistent:/sbin/nologin
If it were running detached from a terminal (in the background; started
from an rc script) then it would have no terminal to report, hence UNKNOWN.
Tracking down what, is another matter. ps uagx and kill processes one
by one until the message stops! Or try ktracing suspects for a less
email@example.com mailing list
To unsubscribe, send any mail to "[EMAIL PROTECTED]"