[Sysadmin] LogWatch for tempest

root root at tempest.evolt.org
Mon Feb 23 06:25:26 CST 2009


 ################### LogWatch 5.2.2 (06/23/04) #################### 
       Processing Initiated: Mon Feb 23 06:25:13 2009
       Date Range Processed: yesterday
     Detail Level of Output: 10
          Logfiles for Host: tempest
 ################################################################ 

 --------------------- Cron Begin ------------------------ 

Commands Run:
   User dmah:
      /home/dmah/bin/article_reminder.pl: 1 Time(s)
      /home/dmah/bin/comment_reminder.pl: 1 Time(s)
   User mailman:
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/checkdbs: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/disabled: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/gate_news: 288 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/nightly_gzip: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/senddigests: 1 Time(s)
   User neuro:
      ~neuro/beo/oldbeo/mkarchivesize >/dev/null 2>&1: 1 Time(s)
   User root:
         run-parts --report /etc/cron.hourly: 24 Time(s)
        [ -d /var/lib/php4 ] && find /var/lib/php4/ -type f -cmin +$(/usr/lib/php4/maxlifetime) -print0 | xargs -r -0 rm: 48 Time(s)
      /store/host/browsers.evolt.org/mkarchivesize: 1 Time(s)
      /usr/bin/freshclam --quiet -l /var/log/clam-update.log: 1 Time(s)
      /usr/sbin/ntpdate -su us.pool.ntp.org us.pool.ntp.org: 1 Time(s)
      /var/qmail/bin/qmailstats 1>/dev/null 2>/dev/null: 1 Time(s)
      if [ -x /usr/bin/vnstat ] && [ `ls /var/lib/vnstat/ | wc -l` -ge 1 ]; then /usr/bin/vnstat -u; fi: 288 Time(s)
      test -x /usr/sbin/anacron || run-parts --report /etc/cron.daily: 1 Time(s)
      test -x /usr/sbin/anacron || run-parts --report /etc/cron.weekly: 1 Time(s)
      test -x /usr/sbin/cron-apt && /usr/sbin/cron-apt: 1 Time(s)
   User www-data:
      [ -x /usr/lib/cgi-bin/awstats.pl -a -f /etc/awstats/awstats.conf -a -r /var/log/apache/access.log ] && /usr/lib/cgi-bin/awstats.pl -config=awstats -update >/dev/null: 144 Time(s)

 ---------------------- Cron End ------------------------- 


 --------------------- EXIM Begin ------------------------ 


--- Messages history ---

3 messages delivered immediately to 3 total recipients

 ---------------------- EXIM End ------------------------- 


 --------------------- httpd Begin ------------------------ 

1.28 MB transfered in 703 responses  (1xx 0, 2xx 1, 3xx 31, 4xx 671, 5xx 0) 
 36 Images (0.01 MB),
 9 Documents (0.00 MB),
 2 Archives (0.00 MB),
 606 Content pages (1.26 MB),
 2 Program source files (0.00 MB),
 48 Other (0.01 MB) 

A total of 25 unidentified 'other' records logged
  GET /simonc/php/bookmarklet.phps HTTP/1.0 with response code(s) 1 404 responses
  GET /jeff/code/user_defined_colors.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /djc/stdio/index.cfm/daddy/show/mommy/94 HTTP/1.1 with response code(s) 1 404 responses
  GET /PHP-Login-System-with-Admin-Features%3ffrom=50%26comments_per_page=50%22%20%20lang=%22en%22%3EPHP%20Login%20System%20with%20Admin%20Features%20%7C%20%3Cwbr%20/%3Eevolt.org%3C/a%3E%3C/h3%3E%20-%20%3Ca%20href=%22http:/nl.babelfish.yahoo.com/translate_url?trurl=http%3A%2F%2Fevolt.org%2FPHP-Login-System-with-Admin-Features%3Ffrom%3D50%26comments_per_page%3D50&lp=en_nl&.intl=nl&fr=sfp%22%20target=%22_blank%22%3EVertaal%20deze%20pagina%3C/a%3E%20%3C/div%3E%3Cdiv%20class=%22abstr%22%20lang=%22en%22%3EA%20world%20community%20for%20web%20developers,%20evolt.org%20promotes%20the%20mutual%20free%20...%20(username%20and%20email)%20and%20link%20to%20main%20page%20(main.php)%20-%20there%20is%20no%20link%20to%20admin.%20...%3C/div%3E%3Cspan%20class=url%3Eevolt.org/PHP-Login-System-with-Admin-%3Cwbr%20/%3EFeatures?from=50&comments_per_%3Cwbr%20/%3Epage...%3C/span%3E%20-%20%3Cem%3E120k%3C/em%3E%20-%20%3Ca%20href=%22http:/nl.wrs.yahoo.com/_ylt=A0oGk20mOqJJ4AABriZzKAx./SIG=18k0s7qf5/EXP=1235454886/**http%3a/74.6.146.244/search/cache%3fei=UTF-8%26p=%2522%252F%253Fpage%253Dmain%2522%26n=100%26fr=sfp%26u=evolt.org/PHP-Login-System-with-Admin-Features%253Ffrom%253D50%2526comments_per_page%253D50%26w=%2522page%2bmain%2522%26d=BzmnLA-YSU9U%26icp=1%26.intl=nl%22%3EIn%20de%20cache%3C/a%3E%3C/div%3E%3C/li%3E%3Cli%3E%3Cdiv%20class=%22res%22%3E%3Cdiv%3E%3Ch3%3E%3Ca%20class=%22yschttl%20spt%22%20href=%22http:/nl.wrs.yahoo.com/_ylt=A0oGk20mOqJJ4AABryZzKAx.;_ylu=X3oDMTB0ZGQxaG90BHNlYwNzcgRwb3MDNDg2BGNvbG8Dc2sxBHZ0aWQD/SIG=11pvcgnco/EXP=1235454886/**http%3a/www.ipangasinan.com/school.htm%22%20%20lang=%22en%22%3ESchool%20Photos%3C/a%3E%3C/h3%3E%20-%20%3Ca%20href=%22http:/nl.babelfish.yahoo.com/translate_url?trurl=http%3A%2F%2Fwww.ipangasinan.com%2Fschool.htm&lp=en_nl&.intl=nl&fr=sfp%22%20target=%22_blank%22%3EVertaal%20deze%20pagina%3C/a%3E%20%3C/div%3E%3Cdiv%20class=%22abstr%22%20lang=%22en%22%3EMainPage%20MainPage.%20AGNO.%20ANHS.%20BOHS.%20AGUILAR.%20ACHS.%20BBHS.%20ALAMINOS%20CITY.%20ANHS.%20Central.%20GPC%20...%20MainPage%20Want%20your%20school%20included%20here,%20please%20let%20us%20know!%20...%3C/div%3E%3Cspan%20class=url%3Ewww.ipangasinan.com/school.htm%3C/span%3E%20-%20%3Ca%20href=%22http:/nl.wrs.yahoo.com/_ylt=A0oGk20mOqJJ4AABsCZzKAx./SIG=16nufk4n7/EXP=1235454886/**http%3a/74.6.146.244/search/cache%3fei=UTF-8%26p=%2522%252F%253Fpage%253Dmain%2522%26n=100%26fr=sfp%26u=www.ipangasinan.com/school.htm%26w=%2522page%2bmain%2522%26d=dPp_Iw-YSVmm%26icp=1%26.intl=nl%22%3EIn%20de%20cache%3C/a%3E%3C/div%3E%3C/li%3E%3Cli%3E%3Cdiv%20class=%22res%22%3E%3Cdiv%3E%3Ch3%3E%3Ca%20class=%22yschttl%20spt%22%20href=%22http:/nl.wrs.yahoo.com/_ylt=A0oGk20mOqJJ4AABsSZzKAx.;_ylu=X3oDMTB0NmEzY3JsBHNlYwNzcgRwb3MDNDg3BGNvbG8Dc2sxBHZ0aWQD/SIG=12jvmemf4/EXP=1235454886/**http%3a/www.thehindu.com/2006/10/07/stories/2006100707170100.htm%22%20%20lang=%22en%22%3EThe%20Hindu%20:%20Front%20Page%20:%20Main%20Sri%20%3Cwbr%20/%3ELankan%20parties%20agree%20to%20reach%20...%3C/a%3E%3C/h3%3E%20-%20%3Ca%20href=%22http:/nl.babelfish.yahoo.com/translate_url?trurl=http%3A%2F%2Fwww.thehindu.com%2F2006%2F10%2F07%2Fstories%2F2006100707170100.htm&lp=en_nl&.intl=nl&fr=sfp%22%20target=%22_blank%22%3EVertaal%20deze%20pagina%3C/a%3E%20%3C/div%3E%3Cdiv%20class=%22abstr%22%20lang=%22en%22%3EFront%20Page.%20Main%20Sri%20Lankan%20parties%20agree%20to%20reach%20consensus%20on%20ethnic%20issue.%20S.%20Dorairaj%20...%20Accord%20will%20impart%20greater%20credibility%20to%20peace%20process.%20G.L.%20Peiris%20...%3C/div%3E%3Cspan%20class=url%3Ewww.thehindu.com/2006/10/07/stories/%3Cwbr%20/%3E2006100707170100.htm%3C/span%3E%20-%20%3Ca%20href=%22http:/nl.wrs.yahoo.com/_ylt=A0oGk20mOqJJ4AABsiZzKAx./SIG=17h77pjll/EXP=1235454886/**http%3a/74.6.146.244/search/cache%3fei=UTF-8%26p=%2522%252F%253Fpage%253Dmain%2522%26n=100%26fr=sfp%26u=www.thehindu.com/2006/10/07/stories/2006100707170100.htm%26w=%2522page%2bmain%2522%26d=YYBKDA-YSNn-%26icp=1%26.intl=nl%22%3EIn%20de%20cache%3C/a%3E%3C/div%3E%3C/li%3E%3Cli%3E%3Cdiv%20class=%22res%22%3E%3Cdiv%3E%3Ch3%3E%3Ca%20class=%22yschttl%20spt%22%20href=%22http:/nl.wrs.yahoo.com/_ylt=A0oGk20mOqJJ4AABsyZzKAx.;_ylu=X3oDMTB0Mm5xYmtiBHNlYwNzcgRwb3MDNDg4BGNvbG8Dc2sxBHZ0aWQD/SIG=11j8n9e7f/EXP=1235454886/**http%3a/rejoicing.com/bread.html%22%20%20lang=%22en%22%3EPerpetual%20Bible%20Reading%20Schedule%20-%20Main%20%3Cwbr%20/%3EPage%3C/a%3E%3C/h3%3E%20-%20%3Ca%20href=%22http:/nl.babelfish.yahoo.com/translate_url?trurl=http%3A%2F%2Frejoicing.com%2Fbread.html&lp=en_nl&.intl=nl&fr=sfp%22%20target=%22_blank%22%3EVertaal%20deze%20pagina%3C/a%3E%20%3C/div%3E%3Cdiv%20class=%22abstr%22%20lang=%22en%22%3ELooking%20For%20A%20Fun%20Rewarding%20Bible%20Reading%20Schedule%20Planner%20Daytimer%20Organizer%20KJV%20...%20Online%20Bible%20Page%20%7C%7C%20Spiritual%20Encouragement%20Page%20%7C%7C%20Main%20Page%20...%3C/div%3E%3Cspan%20class=url%3Erejoicing.com/bread.html%3C/span%3E%20-%20%3Ca%20href=%22http:/nl.wrs.yahoo.com/_ylt=A0oGk20mOqJJ4AABtCZzKAx./SIG=16h1u06km/EXP=1235454886/**http%3a/74.6.146.244/search/cache%3fei=UTF-8%26p=%2522%252F%253Fpage%253Dmain%2522%26n=100%26fr=sfp%26u=rejoicing.com/bread.html%26w=%2522page%2bmain%2522%26d=BcXMdQ-YSMuZ%26icp=1%26.intl=nl%22%3EIn%20de%20cache%3C/a%3E%3C/div%3E%3C/li%3E%3Cli%3E%3Cdiv%20class=%22res%22%3E%3Cdiv%3E%3Ch3%3E%3Ca%20class=%22yschttl%20spt%22%20href=%22http:/nl.wrs.yahoo.com/_ylt=A0oGk20mOqJJ4AABtSZzKAx.;_ylu=X3oDMTB0bnNzajJjBHNlYwNzcgRwb3MDNDg5BGNvbG8Dc2sxBHZ0aWQD/SIG=12iha4iqt/EXP=1235454886/**http%3a/www.techonthenet.com/access/switchboard/report_page.php%22%20%20lang=%22en%22%3EAccess:%20Add%20a%20Preview%20Reports%20page%20to%20%3Cwbr%20/%3Ethe%20switchboard%20in%20Access%202003/XP%20...%3C/a%3E%3C/h3%3E%20-%20%3Ca%20href=%22http:/nl.babelfish.yahoo.com/translate_url?trurl=http%3A%2F%2Fwww.techonthenet.com%2Faccess%2Fswitchboard%2Freport_page.php&lp=en_nl&.intl=nl&fr=sfp%22%20target=%22_blank%22%3EVertaal%20deze%20pagina%3C/a%3E%20%3C/div%3E%3Cdiv%20class=%22abstr%22%20lang=%22en%22%3EIn%20Access%202003/XP/2000/97,%20on%20my%20main%20switchboard%20page,%20how%20can%20I%20have%20an%20option%20called%20Preview%20Reports%20which%20navigates%20to%20another%20page%20in%20my%20switchboard%20that%20lists%20...%3C/div%3E%3Cspan%20class=url%3Ewww.techonthenet.com/access/switchboard/%3Cwbr%20/%3Ereport_page.php%3C/span%3E%3C/div%3E%3C/li%3E%3Cli%3E%3Cdiv%20class=%22res%22%3E%3Cdiv%3E%3Ch3%3E%3Ca%20class=%22yschttl%20spt%22%20href=%22http:/nl.wrs.yahoo.com/_ylt=A0oGk20mOqJJ4AABtiZzKAx.;_ylu=X3oDMTB0djZoYTZtBHNlYwNzcgRwb3MDNDkwBGNvbG8Dc2sxBHZ0aWQD/SIG=11ro8bv1t/EXP=1235454886/**http%3a/www.crocodilian.com/paleosuchus/%22%20%20lang=%22en%22%3EPaleosuchus%20Page%20-%20Main%20page%3C/a%3E%3C/h3%3E%20-%20%3Ca%20href=%22http:/nl.babelfish.yahoo.com/translate_url?trurl=http%3A%2F%2Fwww.crocodilian.com%2Fpaleosuchus%2F&lp=en_nl&.intl=nl&fr=sfp%22%20target=%22_blank%22%3EVertaal%20deze%20pagina%3C/a%3E%20%3C/div%3E%3Cdiv%20class=%22abstr%22%20lang=%22en%22%3EIn%20this%20page,%20you'll%20find%20out%20all%20that%20you%20wanted%20to%20know%20about%20the%20crocodilian%20...%20We%20cover%20the%20naming,%20reproduction,%20habitat,%20captive%20care,%20conservation,%20...%3C/div%3E%3Cspan%20class=url%3Ewww.crocodilian.com/paleosuchus%3C/span%3E%20-%20%3Ca%20href=%22http:/nl.wrs.yahoo.com/_ylt=A0oGk20mOqJJ4AABtyZzKAx./SIG=16plrg4e8/EXP=1235454886/**http%3a/74.6.146.244/search/cache%3fei=UTF-8%26p=%2522%252F%253Fpage%253Dmain%2522%26n=100%26fr=sfp%26u=www.crocodilian.com/paleosuchus/%26w=%2522page%2bmain%2522%26d=KTdDiw-YSTSD%26icp=1%26.intl=nl%22%3EIn%20de%20cache%3C/a%3E%3C/div%3E%3C/li%3E%3Cli%3E%3Cdiv%20class=%22res%22%3E%3Cdiv%3E%3Ch3%3E%3Ca%20class=%22yschttl%20spt%22%20href=%22http:/nl.wrs.yahoo.com/_ylt=A0oGk20mOqJJ4AABuCZzKAx.;_ylu=X3oDMTB0ODVkcGxoBHNlYwNzcgRwb3MDNDkxBGNvbG8Dc2sxBHZ0aWQD/SIG=11drv034f/EXP=1235454886/**http%3a/nffa.tasc.infm.it/%22%20%20lang=%22en%22%3ENFFA%20Project%20:%20Main%20/%20Home%20Page%20:%20%3Cwbr%20/%3Ebrowse%3C/a%3E%3C/h3%3E%20-%20%3Ca%20href=%22http:/nl.babelfish.yahoo.com/translate_url?trurl=http%3A%2F%2Fnffa.tasc.infm.it%2F&lp=en_nl&.intl=nl&fr=sfp%22%20target=%22_blank%22%3EVertaal%20deze%20pagina%3C/a%3E%20%3C/div%3E%3Cdiv%20class=%22ab with response code(s) 2 414 responses
  GET /yournamehere HTTP/1.0 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?rev=1.25&hideattic=0&r1=1.7&view=log HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/table_cell_rollover.cfm HTTP/1.0 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/Attic/square-bullet.psd?rev=1.2&hideattic=0&only_with_tag=HEAD&sortdir=down&view=log HTTP/1.1 with response code(s) 1 404 responses
  GET /garrett/site/books/factual HTTP/1.0 with response code(s) 1 404 responses
  - with response code(s) 11 408 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?rev=1.6&hideattic=0&view=markup HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/calendar/index.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/js_url_variables/index.cfm HTTP/1.1 with response code(s) 2 404 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/mkarchivesize?rev=1.12 HTTP/1.0 with response code(s) 1 404 responses
  GET /signup.cfm HTTP/1.1 with response code(s) 2 404 responses
  GET /jeff/code/preload_n_rollover HTTP/1.1 with response code(s) 2 404 responses
  GET /jeff/code/index.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /jswiders/%5D. HTTP/1.1 with response code(s) 1 404 responses
  GET /jswiders HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/dhtml_form_rollover/index.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1 with response code(s) 9 400 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?sortby=log&r2=1.15&r1=1.20 HTTP/1.1 with response code(s) 1 404 responses
  GET /~atdt1991/uploads HTTP/1.1 with response code(s) 1 404 responses
  GET /garrett/site/books/factual HTTP/1.1 with response code(s) 2 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?hideattic=0&r1=1.13&r2=1.20 HTTP/1.1 with response code(s) 1 404 responses

A total of 8 ROBOTS were logged 
      Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp) 6 time(s) 
      Gaisbot/3.0+(robot06 at gais.cs.ccu.edu.tw;+http://gais.cs.ccu.edu.tw/robot.php) 1 time(s) 
      Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) 2 time(s) 
      Mozilla/5.0 (compatible; Charlotte/1.1; http://www.searchme.com/support/) 1 time(s) 
      msnbot-media/1.1 (+http://search.msn.com/msnbot.htm) 2 time(s) 
      msnbot/1.1 (+http://search.msn.com/msnbot.htm) 20 time(s) 
      Mozilla/5.0 (Twiceler-0.9 http://www.cuil.com/twiceler/robot.html) 2 time(s) 
      WinWebBot/1.0; (Balaena Ltd, UK); http://www.balaena.com/winwebbot.html; winwebbot at balaena.com;) 1 time(s) 

 ---------------------- httpd End ------------------------- 


 --------------------- Kernel Begin ------------------------ 


1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:15642/80 shrinks window 2118008451:2118009899. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:34431/80 shrinks window 2090223073:2090224521. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:24227/80 shrinks window 2162568368:2162569816. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:45521/80 shrinks window 2179348886:2179351782. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:46881/80 shrinks window 2298439446:2298441212. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:49557/80 shrinks window 2151363824:2151366720. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.42:51599/80 shrinks window 2026244040:2026244728. Repaired.
1 Time(s): device eth0 entered promiscuous mode
1 Time(s): device eth0 left promiscuous mode

 ---------------------- Kernel End ------------------------- 


 --------------------- pam_unix Begin ------------------------ 

cron:
   Sessions Opened:
      root: 367 Time(s)
      mailman: 292 Time(s)
      www-data: 144 Time(s)
      dmah: 2 Time(s)
      neuro: 1 Time(s)

su:
   Sessions Opened:
      (uid=0) -> nobody: 1 Time(s)


 ---------------------- pam_unix End ------------------------- 


 --------------------- sendmail Begin ------------------------ 


ERROR: Could not open /etc/mail/local-host-names

ERROR: Could not open /etc/mail/access


Message Size Distribution:
Range          # Msgs       KBytes
0 - 10k             0            0
10k - 20k           0            0
20k - 50k           0            0
50k - 100k          0            0
100k - 500k         0            0
500k - 1Mb          0            0
1Mb - 2Mb           0            0
2Mb - 5Mb           0            0
5Mb - 10Mb          0            0
10Mb+               0            0
----------------------------------
TOTAL               0            0

 ---------------------- sendmail End ------------------------- 


 --------------------- SSHD Begin ------------------------ 


Couldn't resolve these IPs:
   host04.notrio.com(74.53.84.218): 159 Time(s)
   sv1.ansiocorp.com: 20 Time(s)

Didn't receive an ident from these IPs:
   190.90.239.13: 5 Time(s)
   222.128.16.154: 2 Time(s)
   host04.notrio.com (74.53.84.218): 5 Time(s)

Failed logins from these:
   PlcmSpIp/password from 74.53.84.218: 5 Time(s)
   abcs/password from 74.53.84.218: 5 Time(s)
   ac/password from 74.53.84.218: 5 Time(s)
   admin/password from 222.128.16.154: 2 Time(s)
   applprod/password from 74.53.84.218: 5 Time(s)
   appltest/password from 74.53.84.218: 5 Time(s)
   applvis/password from 74.53.84.218: 5 Time(s)
   betxiwl/password from 74.53.84.218: 3 Time(s)
   bin/password from 74.53.84.218: 10 Time(s)
   bind/password from 74.53.84.218: 5 Time(s)
   cgi-bin/password from 74.53.84.218: 5 Time(s)
   collaudo/password from 74.53.84.218: 5 Time(s)
   cs/password from 74.53.84.218: 5 Time(s)
   eduredes/password from 74.53.84.218: 2 Time(s)
   ens/password from 74.53.84.218: 5 Time(s)
   fea/password from 74.53.84.218: 5 Time(s)
   gnats/password from 74.53.84.218: 5 Time(s)
   iony/password from 74.53.84.218: 5 Time(s)
   manux/password from 74.53.84.218: 5 Time(s)
   milma/password from 74.53.84.218: 5 Time(s)
   moell/password from 74.53.84.218: 5 Time(s)
   mythtv/password from 74.53.84.218: 5 Time(s)
   nagios/password from 74.53.84.218: 5 Time(s)
   nodes/password from 74.53.84.218: 5 Time(s)
   null/password from 74.53.84.218: 5 Time(s)
   oracle/password from 123.233.245.226: 2 Time(s)
   oracle/password from 74.53.84.218: 10 Time(s)
   ping/password from 74.53.84.218: 5 Time(s)
   root/password from 123.233.245.226: 26 Time(s)
   root/password from 221.3.131.110: 27 Time(s)
   root/password from 222.128.16.154: 2 Time(s)
   root/password from 69.13.198.202: 20 Time(s)
   services/password from 74.53.84.218: 5 Time(s)
   spamd/password from 74.53.84.218: 2 Time(s)
   test/password from 123.233.245.226: 2 Time(s)
   test/password from 74.53.84.218: 5 Time(s)
   vpn/password from 74.53.84.218: 5 Time(s)
   weblogic/password from 74.53.84.218: 4 Time(s)
   webmaster/password from 74.53.84.218: 3 Time(s)

Illegal users from these:
   PlcmSpIp/none from 74.53.84.218: 5 Time(s)
   PlcmSpIp/password from 74.53.84.218: 5 Time(s)
   abcs/none from 74.53.84.218: 5 Time(s)
   abcs/password from 74.53.84.218: 5 Time(s)
   ac/none from 74.53.84.218: 5 Time(s)
   ac/password from 74.53.84.218: 5 Time(s)
   admin/none from 222.128.16.154: 2 Time(s)
   admin/password from 222.128.16.154: 2 Time(s)
   applprod/none from 74.53.84.218: 5 Time(s)
   applprod/password from 74.53.84.218: 5 Time(s)
   appltest/none from 74.53.84.218: 5 Time(s)
   appltest/password from 74.53.84.218: 5 Time(s)
   applvis/none from 74.53.84.218: 5 Time(s)
   applvis/password from 74.53.84.218: 5 Time(s)
   betxiwl/none from 74.53.84.218: 3 Time(s)
   betxiwl/password from 74.53.84.218: 3 Time(s)
   cgi-bin/none from 74.53.84.218: 5 Time(s)
   cgi-bin/password from 74.53.84.218: 5 Time(s)
   collaudo/none from 74.53.84.218: 5 Time(s)
   collaudo/password from 74.53.84.218: 5 Time(s)
   cs/none from 74.53.84.218: 5 Time(s)
   cs/password from 74.53.84.218: 5 Time(s)
   eduredes/none from 74.53.84.218: 2 Time(s)
   eduredes/password from 74.53.84.218: 2 Time(s)
   ens/none from 74.53.84.218: 5 Time(s)
   ens/password from 74.53.84.218: 5 Time(s)
   fea/none from 74.53.84.218: 5 Time(s)
   fea/password from 74.53.84.218: 5 Time(s)
   iony/none from 74.53.84.218: 5 Time(s)
   iony/password from 74.53.84.218: 5 Time(s)
   manux/none from 74.53.84.218: 5 Time(s)
   manux/password from 74.53.84.218: 5 Time(s)
   milma/none from 74.53.84.218: 5 Time(s)
   milma/password from 74.53.84.218: 5 Time(s)
   moell/none from 74.53.84.218: 5 Time(s)
   moell/password from 74.53.84.218: 5 Time(s)
   mythtv/none from 74.53.84.218: 5 Time(s)
   mythtv/password from 74.53.84.218: 5 Time(s)
   nagios/none from 74.53.84.218: 5 Time(s)
   nagios/password from 74.53.84.218: 5 Time(s)
   nodes/none from 74.53.84.218: 5 Time(s)
   nodes/password from 74.53.84.218: 5 Time(s)
   null/none from 74.53.84.218: 5 Time(s)
   null/password from 74.53.84.218: 5 Time(s)
   oracle/none from 123.233.245.226: 2 Time(s)
   oracle/none from 74.53.84.218: 10 Time(s)
   oracle/password from 123.233.245.226: 2 Time(s)
   oracle/password from 74.53.84.218: 10 Time(s)
   ping/none from 74.53.84.218: 5 Time(s)
   ping/password from 74.53.84.218: 5 Time(s)
   services/none from 74.53.84.218: 5 Time(s)
   services/password from 74.53.84.218: 5 Time(s)
   spamd/none from 74.53.84.218: 2 Time(s)
   spamd/password from 74.53.84.218: 2 Time(s)
   test/none from 123.233.245.226: 2 Time(s)
   test/none from 74.53.84.218: 5 Time(s)
   test/password from 123.233.245.226: 2 Time(s)
   test/password from 74.53.84.218: 5 Time(s)
   vpn/none from 74.53.84.218: 5 Time(s)
   vpn/password from 74.53.84.218: 5 Time(s)
   weblogic/none from 74.53.84.218: 4 Time(s)
   weblogic/password from 74.53.84.218: 4 Time(s)
   webmaster/none from 74.53.84.218: 3 Time(s)
   webmaster/password from 74.53.84.218: 3 Time(s)

**Unmatched Entries**
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER

 ---------------------- SSHD End ------------------------- 


 --------------------- Syslogd Begin ------------------------ 


Syslogd started 2 Time(s)

 ---------------------- Syslogd End ------------------------- 



------------------ Disk Space --------------------

/dev/hda3              72G   52G   17G  77% /
/dev/hda1              92M  6.3M   81M   8% /boot


 ###################### LogWatch End ######################### 




More information about the Sysadmin mailing list