[Sysadmin] LogWatch for tempest

root root at tempest.evolt.org
Sun Feb 22 06:25:36 CST 2009


 ################### LogWatch 5.2.2 (06/23/04) #################### 
       Processing Initiated: Sun Feb 22 06:25:18 2009
       Date Range Processed: yesterday
     Detail Level of Output: 10
          Logfiles for Host: tempest
 ################################################################ 

 --------------------- Cron Begin ------------------------ 

Commands Run:
   User dmah:
      /home/dmah/bin/article_reminder.pl: 1 Time(s)
      /home/dmah/bin/comment_reminder.pl: 1 Time(s)
   User mailman:
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/checkdbs: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/disabled: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/gate_news: 288 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/nightly_gzip: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/senddigests: 1 Time(s)
   User neuro:
      ~neuro/beo/oldbeo/mkarchivesize >/dev/null 2>&1: 1 Time(s)
   User root:
         run-parts --report /etc/cron.hourly: 24 Time(s)
        [ -d /var/lib/php4 ] && find /var/lib/php4/ -type f -cmin +$(/usr/lib/php4/maxlifetime) -print0 | xargs -r -0 rm: 48 Time(s)
      /store/host/browsers.evolt.org/mkarchivesize: 1 Time(s)
      /usr/bin/freshclam --quiet -l /var/log/clam-update.log: 1 Time(s)
      /usr/sbin/ntpdate -su us.pool.ntp.org us.pool.ntp.org: 1 Time(s)
      /var/qmail/bin/qmailstats 1>/dev/null 2>/dev/null: 1 Time(s)
      if [ -x /usr/bin/vnstat ] && [ `ls /var/lib/vnstat/ | wc -l` -ge 1 ]; then /usr/bin/vnstat -u; fi: 288 Time(s)
      test -x /usr/sbin/anacron || run-parts --report /etc/cron.daily: 1 Time(s)
      test -x /usr/sbin/cron-apt && /usr/sbin/cron-apt: 1 Time(s)
   User www-data:
      [ -x /usr/lib/cgi-bin/awstats.pl -a -f /etc/awstats/awstats.conf -a -r /var/log/apache/access.log ] && /usr/lib/cgi-bin/awstats.pl -config=awstats -update >/dev/null: 144 Time(s)

 ---------------------- Cron End ------------------------- 


 --------------------- EXIM Begin ------------------------ 


--- Messages history ---

3 messages delivered immediately to 3 total recipients

 ---------------------- EXIM End ------------------------- 


 --------------------- httpd Begin ------------------------ 

1.40 MB transfered in 1115 responses  (1xx 0, 2xx 1, 3xx 36, 4xx 1078, 5xx 0) 
 54 Images (0.02 MB),
 9 Documents (0.00 MB),
 955 Content pages (1.36 MB),
 97 Other (0.03 MB) 

Attempts to use 1 known hacks were logged 117 time(s)
  phpmyadmin   by 
          72.167.62.200 117 time(s) 

A total of 1 sites probed the server 
  72.167.62.200  

A total of 78 unidentified 'other' records logged
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?annotate=1.19&hideattic=0 HTTP/1.1 with response code(s) 1 404 responses
  GET /index.cfm?from=60 HTTP/1.1 with response code(s) 1 404 responses
  GET /node/60384 HTTP/1.1 with response code(s) 1 404 responses
  GET /index.cfm?from=1140 HTTP/1.1 with response code(s) 1 404 responses
  GET /ia_usability HTTP/1.1 with response code(s) 1 404 responses
  GET /jswiders HTTP/1.1 with response code(s) 1 404 responses
  GET /index.cfm?from=20 HTTP/1.1 with response code(s) 1 404 responses
  GET /mccreath/potatosalad/archives/~amnsnow.mpe HTTP/1.0 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/*checkout*/weo_theme/print.module HTTP/1.1 with response code(s) 1 404 responses
  GET /user/71456 HTTP/1.1 with response code(s) 1 404 responses
  GET /node/61431 HTTP/1.1 with response code(s) 1 404 responses
  GET /faq HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?rev=1.7&sortby=log&view=markup HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?rev=1.2&hideattic=0&only_with_tag=MAIN&view=log HTTP/1.1 with response code(s) 1 404 responses
  GET /index.cfm?from=80 HTTP/1.1 with response code(s) 1 404 responses
  GET /index.cfm?from=70 HTTP/1.1 with response code(s) 1 404 responses
  GET /community_news HTTP/1.1 with response code(s) 1 404 responses
  GET /node/60261 HTTP/1.1 with response code(s) 1 404 responses
  GET /rss/articles.rss HTTP/1.0 with response code(s) 1 404 responses
  GET /user/776 HTTP/1.1 with response code(s) 1 404 responses
  GET /top-10-leugens-die-klanten-vertellen HTTP/1.1 with response code(s) 1 404 responses
  GET /user/register HTTP/1.1 with response code(s) 1 404 responses
  GET /user/77052 HTTP/1.1 with response code(s) 1 404 responses
  - with response code(s) 5 408 responses
  GET /design-for-iphone HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/js_url_variables/index.cfm HTTP/1.1 with response code(s) 2 404 responses
  GET /reviews_and_links HTTP/1.1 with response code(s) 1 404 responses
  GET /do-you-really-need-a-website-1 HTTP/1.1 with response code(s) 1 404 responses
  GET /commentary_and_society HTTP/1.1 with response code(s) 1 404 responses
  GET /node/60390 HTTP/1.1 with response code(s) 1 404 responses
  GET /bheerssen HTTP/1.1 with response code(s) 1 404 responses
  GET /submit HTTP/1.1 with response code(s) 1 404 responses
  GET /when-wikis-go-bad HTTP/1.1 with response code(s) 1 404 responses
  GET /index.cfm?from=40 HTTP/1.1 with response code(s) 1 404 responses
  GET /backend HTTP/1.1 with response code(s) 1 404 responses
  GET /php_login_script_with_remember_me_feature HTTP/1.1 with response code(s) 1 404 responses
  GET /jobs HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?annotate=1.22&sortby=log HTTP/1.1 with response code(s) 1 404 responses
  GET /arijit/dw_ext HTTP/1.1 with response code(s) 2 404 responses
  GET /taxonomy/term/23 HTTP/1.1 with response code(s) 1 404 responses
  GET /cms-trench-warfare HTTP/1.1 with response code(s) 1 404 responses
  GET /node/28241 HTTP/1.1 with response code(s) 1 404 responses
  GET /site_development HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?sortby=log&r2=1.22&r1=1.20 HTTP/1.1 with response code(s) 1 404 responses
  GET /signup.cfm HTTP/1.1 with response code(s) 4 404 responses
  GET /user/76908 HTTP/1.1 with response code(s) 1 404 responses
  GET /suggestions HTTP/1.1 with response code(s) 1 404 responses
  GET /visual_design HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/dhtml_form_rollover/index.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1 with response code(s) 6 400 responses
  GET /node/22700 HTTP/1.1 with response code(s) 1 404 responses
  GET /index.cfm?from=30 HTTP/1.1 with response code(s) 1 404 responses
  GET /danfascia/index.cfm?case=pneumonia&section=clinical&page=1 HTTP/1.1 with response code(s) 1 404 responses
  GET /php-login-system-with-admin-features HTTP/1.1 with response code(s) 1 404 responses
  GET /user/1607 HTTP/1.1 with response code(s) 1 404 responses
  GET /index.cfm?from=50 HTTP/1.1 with response code(s) 1 404 responses
  GET /node/60265 HTTP/1.1 with response code(s) 1 404 responses
  GET /news HTTP/1.1 with response code(s) 1 404 responses
  GET /node/61675 HTTP/1.1 with response code(s) 1 404 responses
  GET /help_support_evolt HTTP/1.1 with response code(s) 1 404 responses
  GET /index.cfm?from=10 HTTP/1.1 with response code(s) 1 404 responses
  GET /node/61391 HTTP/1.1 with response code(s) 1 404 responses
  GET /10volt_help_move_us_forward HTTP/1.1 with response code(s) 1 404 responses
  GET /contact HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/mkarchivesize?rev=1.12 HTTP/1.0 with response code(s) 1 404 responses
  GET /jeff/code/preload_n_rollover HTTP/1.1 with response code(s) 3 404 responses
  GET /code HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/imagemap_rollover/index.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /mccreath/potatosalad/archives/pooh_n_me.jpe HTTP/1.0 with response code(s) 1 404 responses
  GET /burhankhalid/raymond HTTP/1.1 with response code(s) 1 404 responses
  GET /burhankhalid HTTP/1.0 with response code(s) 1 404 responses
  GET /garrett/site/books/factual HTTP/1.1 with response code(s) 4 404 responses
  GET /gnarly/evolt_bits/small_evolt_logo.psd HTTP/1.0 with response code(s) 1 404 responses
  GET /software HTTP/1.1 with response code(s) 1 404 responses
  GET /simple-captcha HTTP/1.1 with response code(s) 1 404 responses
  GET /simonc/php/bookmarklet.phps HTTP/1.1 with response code(s) 1 404 responses
  GET /node/60180 with response code(s) 1 404 responses
  GET /turkif HTTP/1.1 with response code(s) 1 404 responses

A total of 13 ROBOTS were logged 
      larbin_2.6.3 (gqnmgsp at ruc.edu.cn) 1 time(s) 
      Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp) 4 time(s) 
      Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) 1 time(s) 
      Sosospider+(+http://help.soso.com/webspider.htm) 1 time(s) 
      Googlebot-Image/1.0 1 time(s) 
      msnbot-media/1.1 (+http://search.msn.com/msnbot.htm) 3 time(s) 
      Mozilla/4.0 (compatible; MSIE 5.01; Windows NT) 2 time(s) 
      larbin_2.6.3 (larbin2.6.3 at unspecified.mail) 1 time(s) 
      Speedy Spider (http://www.entireweb.com/about/search_tech/speedy_spider/) 1 time(s) 
      TurnitinBot/2.1 (http://www.turnitin.com/robot/crawlerinfo.html) 1 time(s) 
      msnbot/1.1 (+http://search.msn.com/msnbot.htm) 20 time(s) 
      Mozilla/5.0 (Twiceler-0.9 http://www.cuil.com/twiceler/robot.html) 1 time(s) 
      Mozilla/5.0 (compatible; ScoutJet; +http://www.scoutjet.com/) 5 time(s) 

 ---------------------- httpd End ------------------------- 


 --------------------- Kernel Begin ------------------------ 


1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:13268/80 shrinks window 231747145:231750065. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:18098/80 shrinks window 322742253:322745173. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:25584/80 shrinks window 437939902:437942822. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:35720/80 shrinks window 259805366:259808286. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:44683/80 shrinks window 475475243:475476826. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:45532/80 shrinks window 3928951494:3928954390. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:51107/80 shrinks window 413377373:413380293. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:52455/80 shrinks window 479967170:479970090. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:52971/80 shrinks window 717745205:717746665. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:58529/80 shrinks window 183985859:183990239. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:58893/80 shrinks window 315959092:315962012. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:11619/80 shrinks window 2685651773:2685654693. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:11626/80 shrinks window 950673044:950673302. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:13669/80 shrinks window 3598584574:3598587494. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:15691/80 shrinks window 3304572390:3304575310. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:17654/80 shrinks window 4265603146:4265604606. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:18291/80 shrinks window 364463584:364464591. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:19408/80 shrinks window 4169869000:4169870448. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:20289/80 shrinks window 846086252:846087712. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:20404/80 shrinks window 3896389126:3896389684. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:20429/80 shrinks window 2013338653:2013340594. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:20482/80 shrinks window 3660029715:3660031163. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:21235/80 shrinks window 1880340107:1880343027. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:21978/80 shrinks window 1326295827:1326297275. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:22691/80 shrinks window 236855734:236856934. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:23451/80 shrinks window 3470229040:3470230500. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:24065/80 shrinks window 3852839722:3852841182. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:24074/80 shrinks window 1564307934:1564309394. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:26208/80 shrinks window 573560417:573564214. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:26892/80 shrinks window 4094977373:4094978833. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:26892/80 shrinks window 4095016793:4095019713. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:26892/80 shrinks window 4095044533:4095045993. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:28264/80 shrinks window 1685568990:1685570450. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:28437/80 shrinks window 2631750836:2631750880. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:29665/80 shrinks window 3829493241:3829494689. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:30625/80 shrinks window 3567316447:3567317907. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:32473/80 shrinks window 618083510:618083876. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:33250/80 shrinks window 790920737:790923350. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:33304/80 shrinks window 1740792725:1740795621. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:33932/80 shrinks window 1698510883:1698512343. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:36918/80 shrinks window 1038075515:1038076975. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:37022/80 shrinks window 1495622955:1495625875. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:37678/80 shrinks window 784377980:784379440. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:38488/80 shrinks window 4076373828:4076375276. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:39755/80 shrinks window 2207582712:2207585632. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:39959/80 shrinks window 2781716216:2781716850. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:40215/80 shrinks window 178970804:178973724. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:40308/80 shrinks window 1883524784:1883526232. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:40386/80 shrinks window 4114736931:4114738379. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:41535/80 shrinks window 1754750211:1754751659. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:41561/80 shrinks window 1357039233:1357042153. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:41913/80 shrinks window 1210816302:1210817485. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:41969/80 shrinks window 646653156:646653346. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:42093/80 shrinks window 2335907677:2335909137. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:43163/80 shrinks window 1633098966:1633100414. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:43353/80 shrinks window 3673699931:3673702851. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:43495/80 shrinks window 647057853:647062233. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:46661/80 shrinks window 2945393630:2945396550. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:46661/80 shrinks window 2945419910:2945424290. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:46661/80 shrinks window 2945447650:2945449110. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:47897/80 shrinks window 1559608603:1559610063. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:49152/80 shrinks window 3563442918:3563445814. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:49257/80 shrinks window 346397528:346401908. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:49356/80 shrinks window 2127503402:2127503639. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:50160/80 shrinks window 1374647763:1374650683. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:50656/80 shrinks window 1598078361:1598079821. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:50749/80 shrinks window 1975981150:1975984070. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:50990/80 shrinks window 46716593:46718041. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:51185/80 shrinks window 3726901179:3726902639. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:51185/80 shrinks window 3726927459:3726928919. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:51185/80 shrinks window 3726953739:3726955199. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:51958/80 shrinks window 1931394227:1931395687. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:52978/80 shrinks window 4259443853:4259445301. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:53157/80 shrinks window 3777955661:3777957109. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:53686/80 shrinks window 4087652889:4087654349. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:55292/80 shrinks window 1195804508:1195808852. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:55700/80 shrinks window 919118948:919120408. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:56263/80 shrinks window 3438179733:3438181193. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:57785/80 shrinks window 3101331513:3101334433. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:59413/80 shrinks window 3073417130:3073420050. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:59639/80 shrinks window 3748606123:3748607571. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:60992/80 shrinks window 3995101072:3995102532. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:61632/80 shrinks window 4135342675:4135344135. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:61805/80 shrinks window 3350271871:3350273331. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:62069/80 shrinks window 1332822040:1332824960. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:62888/80 shrinks window 263837984:263842364. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:63208/80 shrinks window 3524736567:3524739487. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:63316/80 shrinks window 2087622006:2087624926. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:64209/80 shrinks window 4040635354:4040638274. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:64319/80 shrinks window 1670770360:1670770830. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:64867/80 shrinks window 803825727:803825733. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:65368/80 shrinks window 4023888365:4023889813. Repaired.
1 Time(s): device eth0 entered promiscuous mode
1 Time(s): device eth0 left promiscuous mode
10 Time(s): sending pkt_too_big (len[1500] pmtu[1400]) to self

 ---------------------- Kernel End ------------------------- 


 --------------------- pam_unix Begin ------------------------ 

cron:
   Sessions Opened:
      root: 366 Time(s)
      mailman: 292 Time(s)
      www-data: 144 Time(s)
      dmah: 2 Time(s)
      neuro: 1 Time(s)

su:
   Sessions Opened:
      (uid=0) -> nobody: 1 Time(s)


 ---------------------- pam_unix End ------------------------- 


 --------------------- sendmail Begin ------------------------ 


ERROR: Could not open /etc/mail/local-host-names

ERROR: Could not open /etc/mail/access


Message Size Distribution:
Range          # Msgs       KBytes
0 - 10k             0            0
10k - 20k           0            0
20k - 50k           0            0
50k - 100k          0            0
100k - 500k         0            0
500k - 1Mb          0            0
1Mb - 2Mb           0            0
2Mb - 5Mb           0            0
5Mb - 10Mb          0            0
10Mb+               0            0
----------------------------------
TOTAL               0            0

 ---------------------- sendmail End ------------------------- 


 --------------------- SSHD Begin ------------------------ 


Couldn't resolve these IPs:
   173-15-8-11-illinois.hfc.comcastbusiness.net: 51 Time(s)

Didn't receive an ident from these IPs:
   203.113.137.190: 5 Time(s)
   219.93.21.134: 3 Time(s)
   64.185.230.175: 1 Time(s)

Failed logins from these:
   aaron/password from 195.56.65.40: 3 Time(s)
   admin/password from 173.15.8.11: 2 Time(s)
   admin/password from 195.56.65.40: 3 Time(s)
   bind/password from 64.185.230.175: 1 Time(s)
   gt05/password from 195.56.65.40: 3 Time(s)
   guest/password from 173.15.8.11: 2 Time(s)
   http/password from 173.15.8.11: 1 Time(s)
   mysql/password from 173.15.8.11: 1 Time(s)
   oracle/password from 173.15.8.11: 2 Time(s)
   oracle/password from 64.185.230.175: 1 Time(s)
   recruit/password from 203.113.137.190: 2 Time(s)
   root/password from 173.15.8.11: 23 Time(s)
   root/password from 195.56.65.40: 11 Time(s)
   root/password from 219.93.21.134: 2 Time(s)
   root/password from 64.185.230.175: 27 Time(s)
   root/password from 64.185.238.20: 96 Time(s)
   sales/password from 203.113.137.190: 2 Time(s)
   staff/password from 203.113.137.190: 5 Time(s)
   stephanie/password from 195.56.65.40: 3 Time(s)
   stud/password from 195.56.65.40: 3 Time(s)
   system/password from 64.185.238.20: 3 Time(s)
   t3st/password from 173.15.8.11: 2 Time(s)
   test/password from 173.15.8.11: 2 Time(s)
   test1/password from 173.15.8.11: 1 Time(s)
   test2/password from 173.15.8.11: 1 Time(s)
   test3/password from 173.15.8.11: 1 Time(s)
   test4/password from 173.15.8.11: 1 Time(s)
   test5/password from 173.15.8.11: 1 Time(s)
   trash/password from 195.56.65.40: 3 Time(s)
   user/password from 173.15.8.11: 2 Time(s)
   user1/password from 173.15.8.11: 1 Time(s)
   user2/password from 173.15.8.11: 1 Time(s)
   user4/password from 173.15.8.11: 2 Time(s)
   user5/password from 173.15.8.11: 1 Time(s)
   web/password from 173.15.8.11: 2 Time(s)
   william/password from 195.56.65.40: 3 Time(s)
   www/password from 173.15.8.11: 2 Time(s)

Illegal users from these:
   aaron/none from 195.56.65.40: 3 Time(s)
   aaron/password from 195.56.65.40: 3 Time(s)
   admin/none from 173.15.8.11: 2 Time(s)
   admin/none from 195.56.65.40: 3 Time(s)
   admin/password from 173.15.8.11: 2 Time(s)
   admin/password from 195.56.65.40: 3 Time(s)
   gt05/none from 195.56.65.40: 3 Time(s)
   gt05/password from 195.56.65.40: 3 Time(s)
   guest/none from 173.15.8.11: 2 Time(s)
   guest/password from 173.15.8.11: 2 Time(s)
   http/none from 173.15.8.11: 1 Time(s)
   http/password from 173.15.8.11: 1 Time(s)
   oracle/none from 173.15.8.11: 2 Time(s)
   oracle/none from 64.185.230.175: 1 Time(s)
   oracle/password from 173.15.8.11: 2 Time(s)
   oracle/password from 64.185.230.175: 1 Time(s)
   recruit/none from 203.113.137.190: 2 Time(s)
   recruit/password from 203.113.137.190: 2 Time(s)
   sales/none from 203.113.137.190: 2 Time(s)
   sales/password from 203.113.137.190: 2 Time(s)
   staff/none from 203.113.137.190: 5 Time(s)
   staff/password from 203.113.137.190: 5 Time(s)
   stephanie/none from 195.56.65.40: 3 Time(s)
   stephanie/password from 195.56.65.40: 3 Time(s)
   stud/none from 195.56.65.40: 3 Time(s)
   stud/password from 195.56.65.40: 3 Time(s)
   system/none from 64.185.238.20: 3 Time(s)
   system/password from 64.185.238.20: 3 Time(s)
   t3st/none from 173.15.8.11: 2 Time(s)
   t3st/password from 173.15.8.11: 2 Time(s)
   test/none from 173.15.8.11: 2 Time(s)
   test/password from 173.15.8.11: 2 Time(s)
   test1/none from 173.15.8.11: 1 Time(s)
   test1/password from 173.15.8.11: 1 Time(s)
   test2/none from 173.15.8.11: 1 Time(s)
   test2/password from 173.15.8.11: 1 Time(s)
   test3/none from 173.15.8.11: 1 Time(s)
   test3/password from 173.15.8.11: 1 Time(s)
   test4/none from 173.15.8.11: 1 Time(s)
   test4/password from 173.15.8.11: 1 Time(s)
   test5/none from 173.15.8.11: 1 Time(s)
   test5/password from 173.15.8.11: 1 Time(s)
   trash/none from 195.56.65.40: 3 Time(s)
   trash/password from 195.56.65.40: 3 Time(s)
   user/none from 173.15.8.11: 2 Time(s)
   user/password from 173.15.8.11: 2 Time(s)
   user1/none from 173.15.8.11: 1 Time(s)
   user1/password from 173.15.8.11: 1 Time(s)
   user2/none from 173.15.8.11: 1 Time(s)
   user2/password from 173.15.8.11: 1 Time(s)
   user4/none from 173.15.8.11: 2 Time(s)
   user4/password from 173.15.8.11: 2 Time(s)
   user5/none from 173.15.8.11: 1 Time(s)
   user5/password from 173.15.8.11: 1 Time(s)
   web/none from 173.15.8.11: 2 Time(s)
   web/password from 173.15.8.11: 2 Time(s)
   william/none from 195.56.65.40: 3 Time(s)
   william/password from 195.56.65.40: 3 Time(s)
   www/none from 173.15.8.11: 2 Time(s)
   www/password from 173.15.8.11: 2 Time(s)

**Unmatched Entries**
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER

 ---------------------- SSHD End ------------------------- 


 --------------------- Syslogd Begin ------------------------ 


Syslogd started 1 Time(s)

 ---------------------- Syslogd End ------------------------- 



------------------ Disk Space --------------------

/dev/hda3              72G   53G   16G  78% /
/dev/hda1              92M  6.3M   81M   8% /boot


 ###################### LogWatch End ######################### 




More information about the Sysadmin mailing list