The following has appeared in /var/log/messages, in amongst all the firewall notification that Windows worms are attacking my port 135!
Aug 13 16:01:02 localhost msec: changed mode of /var/log/linuxconf/boot.log from 644 to 640
Aug 13 16:01:02 localhost msec: changed mode of /var/log/wtmp from 664 to 640
Aug 13 16:01:02 localhost msec: changed group of /var/log/wtmp from utmp to adm
Aug 13 16:01:02 localhost msec: changed mode of /var/log/XFree86.0.log from 644 to 640
Aug 13 16:01:02 localhost msec: changed group of /var/log/XFree86.0.log from root to adm
Aug 13 16:01:02 localhost msec: changed mode of /var/log/ksyms.1 from 644 to 640
Aug 13 16:01:02 localhost msec: changed group of /var/log/ksyms.1 from root to adm
Aug 13 16:01:02 localhost msec: changed mode of /var/log/cups/error_log from 644 to 640
...and a few more lines similar. Is this unusual?
Kind regards,
Chris Wilkinson, Christchurch.
