(SOLVED) nologin: Attempted login by root on UNKNOWN

2006-07-19 Thread Tuc at T-B-O-H
> You'll have to figure out how that person is getting access as > apparently they are reaching the box. > Hi, Turns out has NOTHING to do with someone trying to hack the box. I narrowed it down to every time there was a "clean" message from SpamAssassin I would get the message.

Re: nologin: Attempted login by root on UNKNOWN

2006-07-19 Thread Tuc at T-B-O-H.NET
> > Tuc at T-B-O-H.NET wrote: > > >>>Jul 18 14:08:47 asgard nologin: Attempted login by root on UNKNOWN > >>> > >>> > Something running *as* root is trying to "su" to an account which has > /bin/nologin as a shell > > e.

Re: nologin: Attempted login by root on UNKNOWN

2006-07-19 Thread Alex Zbyslaw
Tuc at T-B-O-H.NET wrote: Jul 18 14:08:47 asgard nologin: Attempted login by root on UNKNOWN Something running *as* root is trying to "su" to an account which has /bin/nologin as a shell e.g. # su avahi cartman nologin: Attempted login by alex on /dev/ttyp7 avahi:*:558

Re: nologin: Attempted login by root on UNKNOWN

2006-07-18 Thread Tuc at T-B-O-H.NET
> > Tuc at T-B-O-H.NET wrote: > >>>> Jul 18 14:21:02 asgard nologin: Attempted login by root on UNKNOWN > >>>> Jul 18 14:21:02 asgard kernel: Jul 18 14:21:02 asgard nologin: > >>>> Attempted login by root on UNKNOWN > >>>>

Re: nologin: Attempted login by root on UNKNOWN

2006-07-18 Thread Darek M
Tuc at T-B-O-H.NET wrote: Jul 18 14:21:02 asgard nologin: Attempted login by root on UNKNOWN Jul 18 14:21:02 asgard kernel: Jul 18 14:21:02 asgard nologin: Attempted login by root on UNKNOWN I'm not sure who/what/where to start looking. Ideas? Hey Darek, Good to

Re: nologin: Attempted login by root on UNKNOWN

2006-07-18 Thread Tuc at T-B-O-H.NET
> > Jul 18 14:08:47 asgard nologin: Attempted login by root on UNKNOWN > > Jul 18 14:08:47 asgard kernel: Jul 18 14:08:47 asgard nologin: Attempted > > login by root on UNKNOWN > > Jul 18 14:21:02 asgard nologin: Attempted login by root on UNKNOWN > > Jul 18 14:21:

Re: nologin: Attempted login by root on UNKNOWN

2006-07-18 Thread Tuc at T-B-O-H.NET
> >> Jul 18 14:21:02 asgard nologin: Attempted login by root on UNKNOWN > >> Jul 18 14:21:02 asgard kernel: Jul 18 14:21:02 asgard nologin: > >> Attempted login by root on UNKNOWN > >> > >> I'm not sure who/what/where to start looking.

Re: nologin: Attempted login by root on UNKNOWN

2006-07-18 Thread Darek M
doug wrote: On Tue, 18 Jul 2006, Tuc at T-B-O-H wrote: Hi, All of a sudden today I'm getting : nologin: Attempted login by root on UNKNOWN on a server... Its happening QUITE a bit : Jul 18 13:16:01 asgard nologin: Attempted login by root on UNKNOWN Jul 18 13:16:01 asgard k

Re: nologin: Attempted login by root on UNKNOWN

2006-07-18 Thread doug
On Tue, 18 Jul 2006, Tuc at T-B-O-H wrote: Hi, All of a sudden today I'm getting : nologin: Attempted login by root on UNKNOWN on a server... Its happening QUITE a bit : Jul 18 13:16:01 asgard nologin: Attempted login by root on UNKNOWN Jul 18 13:16:01 asgard kernel: J

nologin: Attempted login by root on UNKNOWN

2006-07-18 Thread Tuc at T-B-O-H
Hi, All of a sudden today I'm getting : nologin: Attempted login by root on UNKNOWN on a server... Its happening QUITE a bit : Jul 18 13:16:01 asgard nologin: Attempted login by root on UNKNOWN Jul 18 13:16:01 asgard kernel: Jul 18 13:16:01 asgard nologin: Attempted logi