G'day...

Nothing has happened to the machine recently (that we know about) ... The 
machine is a firewall, router, and VPN server. The VPN was restarted last 
Thursday, but that is about all.

Prelude was installed at installation time, so it seems wierd for it to 
stop and start itself.  I'm curious.

Mike
---
Michael S. E. Kraus
Administration
Capital Holdings Group (NSW) Pty Ltd
[EMAIL PROTECTED]
phone (02) 9955 8000 fax (02) 9955 8144




James Gregory <[EMAIL PROTECTED]>
Sent by: [EMAIL PROTECTED]
03/02/2003 11:28 AM

 
        To:     [EMAIL PROTECTED]
        cc:     [EMAIL PROTECTED]
        Subject:        Re: [SLUG] Security break? Cron <root@mail> nice -n 19 
run-parts 
/etc/cron.daily


On Mon, 2003-02-03 at 10:08, [EMAIL PROTECTED] wrote:
> G'day all...
> 
> On our firewall/router (Mandrake 8.2) cron normally sends nice little 
> security messages, however one of the last couple of runs was different.
> 
> It's attached below, normally the shutting down and starting up parts 
> aren't there...
> 
> Any ideas...?

not really. I find those emails annoying so I turn them off. The
mandrake security whatsit isn't very smart.

It doesn't look like an entirely unusual thing for it to be doing, but
unless you made a change to the system I would be suspicious. I'd look
at the crontab, look at the programs it's running etc. As I recall all
these tools are written in perl, so vim should be all you need to see if
they're at all different. It could be that upgrading initscripts caused
a change in the way the reporting output gets written -- if you upgraded
initscripts :) -- just canvassing some less alarming possibilities.

Is the INN stuff normally there? perhaps it's just doing this because
something has gone wrong with your news daemon.

What sort of stuff has happened to this machine lately?

HTH

James.


-- 
SLUG - Sydney Linux User's Group - http://slug.org.au/
More Info: http://lists.slug.org.au/listinfo/slug



-- 
SLUG - Sydney Linux User's Group - http://slug.org.au/
More Info: http://lists.slug.org.au/listinfo/slug

Reply via email to