[Sysadmin] LogWatch for tempest

root root at tempest.evolt.org
Sun Oct 14 06:25:43 CDT 2007


 ################### LogWatch 5.2.2 (06/23/04) #################### 
       Processing Initiated: Sun Oct 14 06:25:17 2007
       Date Range Processed: yesterday
     Detail Level of Output: 10
          Logfiles for Host: tempest
 ################################################################ 

 --------------------- Cron Begin ------------------------ 

Commands Run:
   User dkaufman:
      /bin/date > $HOME/date.txt: 1440 Time(s)
   User dmah:
      /home/dmah/bin/article_reminder.pl: 1 Time(s)
      /home/dmah/bin/comment_reminder.pl: 1 Time(s)
   User mailman:
      /home/mailman/bin/discardbysubj.pl: 24 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/checkdbs: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/disabled: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/gate_news: 288 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/nightly_gzip: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/senddigests: 1 Time(s)
   User root:
         run-parts --report /etc/cron.hourly: 24 Time(s)
        [ -d /var/lib/php4 ] && find /var/lib/php4/ -type f -cmin +$(/usr/lib/php4/maxlifetime) -print0 | xargs -r -0 rm: 48 Time(s)
      /store/host/browsers.evolt.org/mkarchivesize: 1 Time(s)
      /usr/bin/freshclam --quiet -l /var/log/clam-update.log: 1 Time(s)
      /usr/local/bin/planetupdate 1>/dev/null 2>&1: 24 Time(s)
      /usr/sbin/ntpdate -su us.pool.ntp.org us.pool.ntp.org: 1 Time(s)
      /var/qmail/bin/qmailstats 1>/dev/null 2>/dev/null: 1 Time(s)
      if [ -x /usr/bin/vnstat ] && [ `ls /var/lib/vnstat/ | wc -l` -ge 1 ]; then /usr/bin/vnstat -u; fi: 288 Time(s)
      test -x /usr/sbin/anacron || run-parts --report /etc/cron.daily: 1 Time(s)
      test -x /usr/sbin/cron-apt && /usr/sbin/cron-apt: 1 Time(s)
      wget -O - -q http://evolt.org/cron.php: 72 Time(s)
   User www-data:
      [ -x /usr/lib/cgi-bin/awstats.pl -a -f /etc/awstats/awstats.conf -a -r /var/log/apache/access.log ] && /usr/lib/cgi-bin/awstats.pl -config=awstats -update >/dev/null: 144 Time(s)

 ---------------------- Cron End ------------------------- 


 --------------------- EXIM Begin ------------------------ 


--- Messages history ---

-MsgID: 1IgM4m-0006EZ-00: 
	2007-10-13 06:25:41 => root at lists.evolt.org <root at tempest.evolt.org> R=passToQmail T=local_smtp H=lists.evolt.org [67.19.100.195]*
	2007-10-13 06:25:41 Completed
22 messages delivered immediately to 22 total recipients

 ---------------------- EXIM End ------------------------- 


 --------------------- httpd Begin ------------------------ 

5.75 MB transfered in 752 responses  (1xx 0, 2xx 444, 3xx 24, 4xx 284, 5xx 0) 
 34 Images (0.01 MB),
 17 Documents (0.00 MB),
 2 Archives (0.02 MB),
 534 Content pages (4.35 MB),
 37 Program source files (0.16 MB),
 1 mod_proxy connection attempts (0.00 MB),
 127 Other (1.21 MB) 

Connection attempts using mod_proxy:
   208.254.109.248 -> http://lti-mail01.ltinetworks.com:25 : 1 Time(s)

A total of 77 unidentified 'other' records logged
  GET /shaggy/javascript/create_slideshow HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/square-bullet-default.gif?view=graph HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?r1=1.5&r2=1.6 HTTP/1.0 with response code(s) 1 200 responses
  GET /gozz/stripcr.cfm HTTP/1.0 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?rev=1.7&sortby=log&view=markup HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating11.gif?rev=1.2&content-type=text/vnd.viewcvs-markup HTTP/1.0 with response code(s) 1 200 responses
  GET /help_support_evolt HTTP/1.0 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/goldcube.gif?content-type=text%2fplain&rev=1.1 HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/6alt_rating11.gif?rev=1.1 HTTP/1.0 with response code(s) 1 200 responses
  GET /signup.cfm HTTP/1.0 with response code(s) 5 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_html/evoltorg.psd?rev=1.1&content-type=text/vnd.viewcvs-markup HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/goldcube.gif?content-type=text%2fplain&rev=1.7 HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/goldcube.gif?content-type=text%2fplain&rev=1.5 HTTP/1.0 with response code(s) 1 200 responses
  GET /luminosity/thoughts/thoughts.rss HTTP/1.0 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/noc/favicon.ico?rev=1.1&sortdir=down&view=log HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/goldcube.gif?content-type=text%2fplain&rev=1.4 HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/.cvsignore?view=log&only_with_tag=weo_theme-4-5&r1=1.2 HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/nostar.gif?rev=1.1 HTTP/1.0 with response code(s) 1 200 responses
  GET /article/PHP_coding_guidelines/18/60247/inde x.html HTTP/1.1 with response code(s) 1 400 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?rev=1.25&r1=1.15&view=log HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/cubes-1.png?view=graph HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/dns/org.evolt?rev=1.31&view=auto HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/6alt_rating11.gif?rev=1.2 HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/goldcube.gif?content-type=text%2fplain&rev=1.2 HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/Attic/evolt.ico?only_with_tag=MAIN HTTP/1.0 with response code(s) 1 200 responses
  GET /mantruc/blog HTTP/1.0 with response code(s) 2 404 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/.cvsignore HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/cubes-4.png?rev=1.1 HTTP/1.0 with response code(s) 1 200 responses
  - with response code(s) 24 408 responses
  GET /mantruc/blog HTTP/1.1 with response code(s) 2 404 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/6alt_rating10.gif?rev=1.2 HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/dns/org.evolt?r1=1.27&r2=1.28&sortby=date HTTP/1.0 with response code(s) 1 200 responses
  GET /luminosity/thoughts/thoughts.rss HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/goldcube.gif?content-type=text%2fplain&rev=1.6 HTTP/1.0 with response code(s) 1 200 responses
  GET /jesteruk HTTP/1.0 with response code(s) 2 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/wiki.png?view=log&only_with_tag=weo_theme-4-5&r1=1.1 HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/goldcube.gif?rev=1.7&content-type=text/vnd.viewcvs-markup HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?rev=1.24&content-type=text/vnd.viewcvs-markup HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/goldcube.gif?content-type=text%2fplain&rev=1.3 HTTP/1.0 with response code(s) 1 200 responses
  GET /jeff/code/form_to_window/index.cfm HTTP/1.0 with response code(s) 1 404 responses
  GET /burhankhalid/index.rdf HTTP/1.0 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating03.gif?rev=1.1&view=markup HTTP/1.0 with response code(s) 1 200 responses
  GET /jeff/code/character_converting_textarea.cfm HTTP/1.0 with response code(s) 1 404 responses
  GET /signup.cfm HTTP/1.1 with response code(s) 12 404 responses
  GET /liorean HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/yahoo.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/wiki.png?content-type=text%2fplain HTTP/1.0 with response code(s) 1 200 responses
  GET /jeff/wip/photoshop/index.cfm HTTP/1.0 with response code(s) 1 404 responses
  GET /jeff/yahoo.cfm HTTP/1.0 with response code(s) 1 404 responses
  GET /garrett/feo3.html. HTTP/1.0 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_html/evoltorg.psd?view=log&only_with_tag=HEAD&r1=1.1 HTTP/1.0 with response code(s) 1 200 responses
  GET /evoltgear HTTP/1.0 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/Attic/star.png?view=graph HTTP/1.0 with response code(s) 1 200 responses
  GET /jeff/code/dhtml_form_rollover/index.cfm HTTP/1.0 with response code(s) 2 404 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/6alt_rating10.gif?rev=1.1 HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/atom03.gif?rev=1.1&view=markup HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/Attic/red-cube.png?rev=1.1&content-type=text/vnd.viewcvs-markup HTTP/1.0 with response code(s) 1 200 responses
  GET /winddancer HTTP/1.0 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/Attic/evolt.ico?only_with_tag=v3_0_0 HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating05.gif?rev=1.2&view=markup HTTP/1.0 with response code(s) 1 200 responses
  GET /article/mod_deflate_and_Apache_2_0_x/20/601 04/ HTTP/1.1 with response code(s) 1 400 responses
  GET /djc/evolt/temp/index.cfm HTTP/1.0 with response code(s) 1 404 responses
  GET //level/16/exec/-///show/configuration HTTP/1.1 with response code(s) 3 404 responses
  GET /cgi-bin/viewcvs.cgi/dns/org.evolt?annotate=1.22 HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/cubes-5.png?sortby=log&only_with_tag=HEAD HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/workcube.gif?content-type=text%2fplain&rev=1.2 HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?rev=1.23&content-type=text/vnd.viewcvs-markup HTTP/1.0 with response code(s) 1 200 responses
  GET /jeff/code/preload_n_rollover HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating02.gif?rev=1.2&view=markup HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_html/evolt-logo.ai?content-type=text%2fplain HTTP/1.0 with response code(s) 1 200 responses
  GET /admin/Powered By: KingCMS 3.0 Beta HTTP/1.1 with response code(s) 1 400 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating04.gif?rev=1.2&view=log HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/rss10.gif?content-type=text%2fplain&rev=1.1 HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/Attic/evolt-logo.ai?annotate=1.2 HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating04.gif?view=graph HTTP/1.0 with response code(s) 1 200 responses
  GET /dshadovi/MM_resources.cfm HTTP/1.0 with response code(s) 3 404 responses
  GET /garrett/site/books/factual HTTP/1.1 with response code(s) 5 404 responses

A total of 13 ROBOTS were logged 
      NG/2.0 1 time(s) 
      Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp) 5 time(s) 
      Mozilla/5.0 (compatible; BecomeBot/3.0; +http://www.become.com/site_owners.html) 3 time(s) 
      Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) 2 time(s) 
      Mozilla/2.0 (compatible; Ask Jeeves/Teoma) 1 time(s) 
      polybot 1.0 (http://cis.poly.edu/polybot/) 1 time(s) 
      lmspider/Nutch-0.9-dev (For research purposes.; www.nuance.com) 1 time(s) 
      noxtrumbot/1.0 (crawler at noxtrum.com) 1 time(s) 
      msnbot/1.0 (+http://search.msn.com/msnbot.htm) 17 time(s) 
      Mozilla/5.0 (compatible; Yahoo! Slurp China; http://misc.yahoo.com.cn/help.html) 1 time(s) 
      ConveraCrawler/0.9e (+http://www.authoritativeweb.com/crawl) 1 time(s) 
      msnbot-media/1.0 (+http://search.msn.com/msnbot.htm) 7 time(s) 
      Speedy Spider (http://www.entireweb.com/about/search_tech/speedy_spider/) 1 time(s) 

 ---------------------- httpd End ------------------------- 


 --------------------- Kernel Begin ------------------------ 


1 Time(s): NET: 1 messages suppressed.
2 Time(s): NET: 10 messages suppressed.
1 Time(s): NET: 114 messages suppressed.
1 Time(s): NET: 12 messages suppressed.
1 Time(s): NET: 13 messages suppressed.
2 Time(s): NET: 15 messages suppressed.
1 Time(s): NET: 16 messages suppressed.
2 Time(s): NET: 17 messages suppressed.
1 Time(s): NET: 18 messages suppressed.
1 Time(s): NET: 19 messages suppressed.
2 Time(s): NET: 2 messages suppressed.
1 Time(s): NET: 20 messages suppressed.
1 Time(s): NET: 21 messages suppressed.
1 Time(s): NET: 22 messages suppressed.
2 Time(s): NET: 23 messages suppressed.
1 Time(s): NET: 25 messages suppressed.
1 Time(s): NET: 26 messages suppressed.
4 Time(s): NET: 27 messages suppressed.
2 Time(s): NET: 28 messages suppressed.
1 Time(s): NET: 30 messages suppressed.
2 Time(s): NET: 31 messages suppressed.
1 Time(s): NET: 33 messages suppressed.
2 Time(s): NET: 34 messages suppressed.
1 Time(s): NET: 35 messages suppressed.
1 Time(s): NET: 36 messages suppressed.
1 Time(s): NET: 37 messages suppressed.
1 Time(s): NET: 38 messages suppressed.
1 Time(s): NET: 39 messages suppressed.
2 Time(s): NET: 4 messages suppressed.
1 Time(s): NET: 40 messages suppressed.
2 Time(s): NET: 41 messages suppressed.
1 Time(s): NET: 42 messages suppressed.
3 Time(s): NET: 43 messages suppressed.
1 Time(s): NET: 44 messages suppressed.
1 Time(s): NET: 47 messages suppressed.
1 Time(s): NET: 49 messages suppressed.
1 Time(s): NET: 5 messages suppressed.
1 Time(s): NET: 50 messages suppressed.
1 Time(s): NET: 52 messages suppressed.
1 Time(s): NET: 58 messages suppressed.
2 Time(s): NET: 59 messages suppressed.
1 Time(s): NET: 6 messages suppressed.
2 Time(s): NET: 61 messages suppressed.
2 Time(s): NET: 62 messages suppressed.
2 Time(s): NET: 63 messages suppressed.
1 Time(s): NET: 67 messages suppressed.
3 Time(s): NET: 7 messages suppressed.
1 Time(s): NET: 70 messages suppressed.
1 Time(s): NET: 73 messages suppressed.
1 Time(s): NET: 77 messages suppressed.
2 Time(s): NET: 8 messages suppressed.
1 Time(s): NET: 81 messages suppressed.
1 Time(s): NET: 85 messages suppressed.
4 Time(s): NET: 9 messages suppressed.
1 Time(s): NET: 91 messages suppressed.
1 Time(s): TCP: drop open request from 12.150.207.5/4826
1 Time(s): TCP: drop open request from 12.158.13.140/14266
1 Time(s): TCP: drop open request from 12.36.119.194/15977
1 Time(s): TCP: drop open request from 12.40.36.215/26755
1 Time(s): TCP: drop open request from 129.79.1.116/1038
1 Time(s): TCP: drop open request from 133.43.247.9/44136
1 Time(s): TCP: drop open request from 137.153.0.14/33379
1 Time(s): TCP: drop open request from 141.213.75.29/33396
1 Time(s): TCP: drop open request from 142.166.169.26/51330
1 Time(s): TCP: drop open request from 142.176.45.195/34196
1 Time(s): TCP: drop open request from 143.115.171.77/31024
1 Time(s): TCP: drop open request from 149.68.14.11/53336
1 Time(s): TCP: drop open request from 159.105.222.102/57028
1 Time(s): TCP: drop open request from 168.61.60.71/50086
1 Time(s): TCP: drop open request from 193.113.210.246/33695
1 Time(s): TCP: drop open request from 193.141.188.98/40822
1 Time(s): TCP: drop open request from 193.168.140.72/51310
1 Time(s): TCP: drop open request from 193.41.240.35/55723
1 Time(s): TCP: drop open request from 195.101.16.112/34945
1 Time(s): TCP: drop open request from 195.129.34.130/51461
1 Time(s): TCP: drop open request from 195.92.195.229/4370
1 Time(s): TCP: drop open request from 198.232.247.84/45288
1 Time(s): TCP: drop open request from 198.66.222.156/3713
1 Time(s): TCP: drop open request from 199.185.88.147/37122
1 Time(s): TCP: drop open request from 199.249.20.36/45351
1 Time(s): TCP: drop open request from 200.89.55.160/60179
1 Time(s): TCP: drop open request from 202.67.56.96/59251
1 Time(s): TCP: drop open request from 202.8.6.40/36392
1 Time(s): TCP: drop open request from 203.129.220.2/44278
1 Time(s): TCP: drop open request from 203.129.72.243/43797
1 Time(s): TCP: drop open request from 203.140.81.18/38197
1 Time(s): TCP: drop open request from 204.50.135.40/61420
1 Time(s): TCP: drop open request from 205.207.98.81/44157
1 Time(s): TCP: drop open request from 206.163.232.46/57726
1 Time(s): TCP: drop open request from 206.190.59.127/29380
1 Time(s): TCP: drop open request from 206.252.145.84/57190
1 Time(s): TCP: drop open request from 207.115.36.76/17696
1 Time(s): TCP: drop open request from 207.115.36.82/41795
1 Time(s): TCP: drop open request from 207.154.60.60/36122
1 Time(s): TCP: drop open request from 207.155.252.4/56976
1 Time(s): TCP: drop open request from 207.54.98.225/58695
1 Time(s): TCP: drop open request from 207.8.214.5/33366
1 Time(s): TCP: drop open request from 207.99.47.95/49903
1 Time(s): TCP: drop open request from 208.0.145.22/61815
1 Time(s): TCP: drop open request from 208.0.145.24/61916
1 Time(s): TCP: drop open request from 208.13.158.9/3410
1 Time(s): TCP: drop open request from 209.120.191.30/3583
1 Time(s): TCP: drop open request from 209.134.128.2/43479
1 Time(s): TCP: drop open request from 209.23.129.242/20969
1 Time(s): TCP: drop open request from 209.68.1.45/52869
1 Time(s): TCP: drop open request from 210.157.1.53/54519
1 Time(s): TCP: drop open request from 210.251.91.160/6019
1 Time(s): TCP: drop open request from 212.147.50.97/43123
1 Time(s): TCP: drop open request from 212.180.1.122/42386
1 Time(s): TCP: drop open request from 212.185.119.169/37429
1 Time(s): TCP: drop open request from 212.208.150.151/60394
1 Time(s): TCP: drop open request from 212.241.249.219/3143
1 Time(s): TCP: drop open request from 212.247.154.193/59087
1 Time(s): TCP: drop open request from 212.51.32.152/33754
1 Time(s): TCP: drop open request from 213.133.221.99/23868
1 Time(s): TCP: drop open request from 213.188.12.36/54516
1 Time(s): TCP: drop open request from 213.253.171.5/41182
1 Time(s): TCP: drop open request from 213.82.237.190/60027
1 Time(s): TCP: drop open request from 216.129.98.150/59991
1 Time(s): TCP: drop open request from 216.161.16.106/14079
1 Time(s): TCP: drop open request from 216.168.61.71/55557
1 Time(s): TCP: drop open request from 216.231.14.227/15545
1 Time(s): TCP: drop open request from 216.237.12.146/33998
1 Time(s): TCP: drop open request from 216.46.93.210/17901
1 Time(s): TCP: drop open request from 216.71.32.22/1959
1 Time(s): TCP: drop open request from 217.18.99.186/24876
1 Time(s): TCP: drop open request from 217.30.97.13/56157
1 Time(s): TCP: drop open request from 217.64.112.27/39026
1 Time(s): TCP: drop open request from 218.216.24.114/52559
1 Time(s): TCP: drop open request from 219.110.2.182/47559
1 Time(s): TCP: drop open request from 222.146.40.208/47221
1 Time(s): TCP: drop open request from 24.28.204.23/36039
1 Time(s): TCP: drop open request from 24.39.83.123/43565
1 Time(s): TCP: drop open request from 24.75.96.150/37101
1 Time(s): TCP: drop open request from 61.121.215.237/4366
1 Time(s): TCP: drop open request from 61.135.145.21/15918
1 Time(s): TCP: drop open request from 61.154.167.130/2297
1 Time(s): TCP: drop open request from 62.22.13.61/31074
1 Time(s): TCP: drop open request from 62.94.0.34/57274
1 Time(s): TCP: drop open request from 62.99.145.30/37790
1 Time(s): TCP: drop open request from 63.163.73.13/1600
1 Time(s): TCP: drop open request from 63.170.36.62/51048
1 Time(s): TCP: drop open request from 63.170.36.62/52116
1 Time(s): TCP: drop open request from 63.255.188.12/41053
1 Time(s): TCP: drop open request from 64.13.229.134/36980
1 Time(s): TCP: drop open request from 64.132.56.90/52049
1 Time(s): TCP: drop open request from 64.140.224.12/42762
1 Time(s): TCP: drop open request from 64.200.200.10/64062
1 Time(s): TCP: drop open request from 64.29.147.215/58326
1 Time(s): TCP: drop open request from 64.34.161.7/41643
1 Time(s): TCP: drop open request from 64.60.152.217/50504
1 Time(s): TCP: drop open request from 64.74.223.56/4870
1 Time(s): TCP: drop open request from 64.75.176.23/3068
1 Time(s): TCP: drop open request from 64.78.186.55/46685
1 Time(s): TCP: drop open request from 65.183.32.11/2407
1 Time(s): TCP: drop open request from 65.216.196.53/45279
1 Time(s): TCP: drop open request from 65.24.7.63/13576
1 Time(s): TCP: drop open request from 65.66.238.251/53633
1 Time(s): TCP: drop open request from 66.103.128.195/41944
1 Time(s): TCP: drop open request from 66.165.162.174/45349
1 Time(s): TCP: drop open request from 66.194.66.133/45216
1 Time(s): TCP: drop open request from 66.207.221.245/27172
1 Time(s): TCP: drop open request from 66.211.136.12/7564
1 Time(s): TCP: drop open request from 66.238.195.195/10189
1 Time(s): TCP: drop open request from 66.75.160.130/34674
1 Time(s): TCP: drop open request from 66.75.160.145/35699
1 Time(s): TCP: drop open request from 66.83.75.134/32927
1 Time(s): TCP: drop open request from 66.93.109.98/35443
1 Time(s): TCP: drop open request from 66.93.19.107/37179
1 Time(s): TCP: drop open request from 67.112.102.126/64005
1 Time(s): TCP: drop open request from 67.121.157.153/46735
1 Time(s): TCP: drop open request from 67.137.25.178/54315
1 Time(s): TCP: drop open request from 67.158.118.171/13365
1 Time(s): TCP: drop open request from 67.18.219.74/57251
1 Time(s): TCP: drop open request from 68.15.126.229/24598
1 Time(s): TCP: drop open request from 68.152.49.57/53077
1 Time(s): TCP: drop open request from 68.165.156.106/4318
1 Time(s): TCP: drop open request from 68.17.122.194/57121
1 Time(s): TCP: drop open request from 68.185.2.115/1717
1 Time(s): TCP: drop open request from 69.26.213.243/50615
1 Time(s): TCP: drop open request from 69.93.230.226/35003
1 Time(s): TCP: drop open request from 70.154.129.66/63977
1 Time(s): TCP: drop open request from 70.167.30.231/15759
1 Time(s): TCP: drop open request from 70.85.82.66/34170
1 Time(s): TCP: drop open request from 70.86.188.98/41255
1 Time(s): TCP: drop open request from 71.126.251.131/35102
1 Time(s): TCP: drop open request from 72.19.242.245/48731
1 Time(s): TCP: drop open request from 74.200.203.250/34898
1 Time(s): TCP: drop open request from 74.218.167.194/23165
1 Time(s): TCP: drop open request from 74.53.83.98/54891
1 Time(s): TCP: drop open request from 75.126.225.234/50403
1 Time(s): TCP: drop open request from 79.125.224.196/2159
1 Time(s): TCP: drop open request from 80.120.254.162/8414
1 Time(s): TCP: drop open request from 82.110.3.210/31432
1 Time(s): TCP: drop open request from 82.116.225.190/35524
1 Time(s): TCP: drop open request from 82.150.2.42/45004
1 Time(s): TCP: drop open request from 84.40.22.104/35295
1 Time(s): UDP: bad checksum. From 12.96.160.115:53 to 67.19.100.194:44631 ulen 39
1 Time(s): UDP: bad checksum. From 12.96.160.115:53 to 67.19.100.194:45998 ulen 39
1 Time(s): UDP: bad checksum. From 12.96.160.115:53 to 67.19.100.194:53176 ulen 39
1 Time(s): UDP: short packet: 12.96.160.115:53 158/142 to 67.19.100.194:64715
1 Time(s): UDP: short packet: 12.96.160.115:53 177/161 to 67.19.100.194:64715
1 Time(s): UDP: short packet: 12.96.160.115:53 183/167 to 67.19.100.194:41321
2 Time(s): UDP: short packet: 12.96.160.115:53 186/170 to 67.19.100.194:64715
1 Time(s): UDP: short packet: 12.96.160.115:53 190/174 to 67.19.100.194:15093
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:37560
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:42402
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:54635
1 Time(s): UDP: short packet: 12.96.160.115:53 281/265 to 67.19.100.194:64715
1 Time(s): UDP: short packet: 12.96.160.115:53 306/290 to 67.19.100.194:34534
1 Time(s): UDP: short packet: 12.96.160.115:53 308/292 to 67.19.100.194:55187
1 Time(s): UDP: short packet: 12.96.160.115:53 313/297 to 67.19.100.194:44910
1 Time(s): UDP: short packet: 12.96.160.115:53 313/297 to 67.19.100.194:48790
1 Time(s): UDP: short packet: 12.96.160.115:53 315/299 to 67.19.100.194:49898
1 Time(s): UDP: short packet: 12.96.160.115:53 509/493 to 67.19.100.194:64715
1 Time(s): UDP: short packet: 12.96.160.115:53 530/514 to 67.19.100.194:50600
1 Time(s): device eth0 entered promiscuous mode
1 Time(s): device eth0 left promiscuous mode

 ---------------------- Kernel End ------------------------- 


 --------------------- Named Begin ------------------------ 


**Unmatched Entries**
   notify question section contains no SOA: 1 Time(s)

 ---------------------- Named End ------------------------- 


 --------------------- pam_unix Begin ------------------------ 

cron:
   Sessions Opened:
      dkaufman: 1440 Time(s)
      root: 462 Time(s)
      mailman: 316 Time(s)
      www-data: 144 Time(s)
      dmah: 2 Time(s)

sshd:
   Authentication Failures:
      dmah (s010600c049d9e99b.cg.shawcable.net): 1 Time(s)
   Sessions Opened:
      dmah: 4 Time(s)

su:
   Sessions Opened:
      dmah(uid=0) -> root: 2 Time(s)
      (uid=0) -> nobody: 1 Time(s)


 ---------------------- pam_unix End ------------------------- 


 --------------------- sendmail Begin ------------------------ 


ERROR: Could not open /etc/mail/local-host-names

ERROR: Could not open /etc/mail/access


Message Size Distribution:
Range          # Msgs       KBytes
0 - 10k             0            0
10k - 20k           0            0
20k - 50k           0            0
50k - 100k          0            0
100k - 500k         0            0
500k - 1Mb          0            0
1Mb - 2Mb           0            0
2Mb - 5Mb           0            0
5Mb - 10Mb          0            0
10Mb+               0            0
----------------------------------
TOTAL               0            0

 ---------------------- sendmail End ------------------------- 


 --------------------- SSHD Begin ------------------------ 


Couldn't resolve these IPs:
   74-94-201-22-pennsylvania.hfc.comcastbusiness.net: 43 Time(s)

Didn't receive an ident from these IPs:
   74-94-201-22-Pennsylvania.hfc.comcastbusiness.net (74.94.201.22): 5 Time(s)
   81.28.41.110: 2 Time(s)
   S010600e02995d83c.cg.shawcable.net (68.145.103.61): 10 Time(s)
   bmesolaris.inje.ac.kr (203.241.227.13): 5 Time(s)
   gnf98.internetdsl.tpnet.pl (83.3.83.98): 5 Time(s)

Failed logins from these:
   admin/password from 68.145.103.61: 10 Time(s)
   guest/password from 68.145.103.61: 116 Time(s)
   recruit/password from 203.241.227.13: 1 Time(s)
   root/password from 74.94.201.22: 43 Time(s)
   sales/password from 203.241.227.13: 3 Time(s)
   staff/password from 203.241.227.13: 3 Time(s)
   staff/password from 81.28.41.110: 2 Time(s)

Illegal users from these:
   admin/none from 68.145.103.61: 10 Time(s)
   admin/password from 68.145.103.61: 10 Time(s)
   guest/none from 68.145.103.61: 116 Time(s)
   guest/password from 68.145.103.61: 116 Time(s)
   recruit/none from 203.241.227.13: 1 Time(s)
   recruit/password from 203.241.227.13: 1 Time(s)
   sales/none from 203.241.227.13: 3 Time(s)
   sales/password from 203.241.227.13: 3 Time(s)
   staff/none from 203.241.227.13: 3 Time(s)
   staff/none from 81.28.41.110: 2 Time(s)
   staff/password from 203.241.227.13: 3 Time(s)
   staff/password from 81.28.41.110: 2 Time(s)

Users logging in through sshd:
   dmah:
      S010600c049d9e99b.cg.shawcable.net (70.73.105.151): 4 times

Error in PAM authentication:
   Authentication failure for dmah from s010600c049d9e99b.cg.shawcable.net : 1 Time(s)

**Unmatched Entries**
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER

 ---------------------- SSHD End ------------------------- 


 --------------------- Sudo (secure-log) Begin ------------------------ 

==============================================================================
dmah => root
------------------------------------------------------------------------------
/bin/su -
/sbin/iptables -nvL http
/bin/su -

 ---------------------- Sudo (secure-log) End ------------------------- 


 --------------------- Syslogd Begin ------------------------ 


Syslogd started 1 Time(s)

 ---------------------- Syslogd End ------------------------- 



------------------ Disk Space --------------------

/dev/hda3              72G   29G   40G  42% /
/dev/hda1              92M  6.3M   81M   8% /boot


 ###################### LogWatch End ######################### 




More information about the Sysadmin mailing list