Hi,

      I am currently using Redhat Linux 6.2, and i have disable all inetd
services, no ftp, telnet...etc... but ssh2.  I use public key to login into
my server.  As i notice, if I loggin throught my isp the login named will be
shown as pck0253.netvig....etc.   But below, I got one strange line.  saying
login from 208.139.110.83.  Is this indicated that I have been hacked.

root     pts/0        pcd049145.netvig Thu Apr  5 02:26   still logged in
root     pts/0        awork021238.netv Wed Apr  4 14:07 - 15:25  (01:17)
---->>root     pts/0        208.139.110.83   Wed Apr  4 05:51 - 06:51
(01:00)
root     pts/0        pcd113044.netvig Wed Apr  4 03:15 - 03:21  (00:06)
root     pts/0        awork021235.netv Tue Apr  3 12:14 - 12:18  (00:04)
root     pts/0        pcd102080.netvig Mon Apr  2 06:44 - 07:20  (00:35)
root     pts/0        pcd073169.netvig Mon Apr  2 04:31 - 04:32  (00:01)
root     pts/0        pcd115023.netvig Mon Apr  2 02:15 - 02:53  (00:37)
root     pts/0        pcd115116.netvig Sun Apr  1 23:14 - 23:15  (00:00)
root     pts/0        pcd115190.netvig Sun Apr  1 22:40 - 22:46  (00:06)


Thank you

Mark



_______________________________________________
Redhat-list mailing list
[EMAIL PROTECTED]
https://listman.redhat.com/mailman/listinfo/redhat-list

Reply via email to