[Sysadmin] LogWatch for tempest

root root at tempest.evolt.org
Sat Feb 28 06:25:59 CST 2009


 ################### LogWatch 5.2.2 (06/23/04) #################### 
       Processing Initiated: Sat Feb 28 06:25:17 2009
       Date Range Processed: yesterday
     Detail Level of Output: 10
          Logfiles for Host: tempest
 ################################################################ 

 --------------------- Cron Begin ------------------------ 

Commands Run:
   User dmah:
      /home/dmah/bin/article_reminder.pl: 1 Time(s)
      /home/dmah/bin/comment_reminder.pl: 1 Time(s)
   User mailman:
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/checkdbs: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/disabled: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/gate_news: 288 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/nightly_gzip: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/senddigests: 1 Time(s)
   User neuro:
      ~neuro/beo/oldbeo/mkarchivesize >/dev/null 2>&1: 1 Time(s)
   User root:
         run-parts --report /etc/cron.hourly: 24 Time(s)
        [ -d /var/lib/php4 ] && find /var/lib/php4/ -type f -cmin +$(/usr/lib/php4/maxlifetime) -print0 | xargs -r -0 rm: 48 Time(s)
      /store/host/browsers.evolt.org/mkarchivesize: 1 Time(s)
      /usr/bin/freshclam --quiet -l /var/log/clam-update.log: 1 Time(s)
      /usr/sbin/ntpdate -su us.pool.ntp.org us.pool.ntp.org: 1 Time(s)
      /var/qmail/bin/qmailstats 1>/dev/null 2>/dev/null: 1 Time(s)
      if [ -x /usr/bin/vnstat ] && [ `ls /var/lib/vnstat/ | wc -l` -ge 1 ]; then /usr/bin/vnstat -u; fi: 288 Time(s)
      test -x /usr/sbin/anacron || run-parts --report /etc/cron.daily: 1 Time(s)
      test -x /usr/sbin/cron-apt && /usr/sbin/cron-apt: 1 Time(s)
   User www-data:
      [ -x /usr/lib/cgi-bin/awstats.pl -a -f /etc/awstats/awstats.conf -a -r /var/log/apache/access.log ] && /usr/lib/cgi-bin/awstats.pl -config=awstats -update >/dev/null: 144 Time(s)

 ---------------------- Cron End ------------------------- 


 --------------------- EXIM Begin ------------------------ 


--- Messages history ---

-MsgID: 1LchEP-00035z-00: 
	2009-02-27 06:27:36 => root at lists.evolt.org <root at tempest.evolt.org> R=passToQmail T=local_smtp H=lists.evolt.org [67.19.100.195]*
	2009-02-27 06:27:36 Completed
3 messages delivered immediately to 3 total recipients

 ---------------------- EXIM End ------------------------- 


 --------------------- httpd Begin ------------------------ 

2.48 MB transfered in 6274 responses  (1xx 0, 2xx 2, 3xx 5403, 4xx 869, 5xx 0) 
 74 Images (0.02 MB),
 9 Documents (0.00 MB),
 6089 Content pages (2.44 MB),
 4 Program source files (0.00 MB),
 98 Other (0.02 MB) 

Attempts to use 1 known hacks were logged 5 time(s)
  phpmyadmin   by 
          216.121.67.35 4 time(s) 
          66.249.71.16 1 time(s) 

A total of 2 sites probed the server 
  216.121.67.35  
  66.249.71.16  

A total of 45 unidentified 'other' records logged
  GET /dshadovi/traffic.cfm HTTP/1.0 with response code(s) 1 404 responses
  GET /djc/stdio/index.cfm/daddy/show/mommy/94 HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?hideattic=0&only_with_tag=MAIN&r2=1.2&r1=1.1 HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/CHANGELOG?hideattic=0&sortdir=down&rev=1.2&only_with_tag=MAIN&sortby=date&view=auto HTTP/1.1 with response code(s) 1 404 responses
  GET /rudy HTTP/1.0 with response code(s) 1 404 responses
  GET /doofs/... HTTP/1.1 with response code(s) 1 404 responses
  GET /PHP-Login-System-with-Admin-Features/ll tell you. If you look in constants.php you HTTP/1.1 with response code(s) 1 400 responses
  GET /signup.cfm HTTP/1.1 with response code(s) 3 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?hideattic=0&r1=1.13&r2=1.14 HTTP/1.1 with response code(s) 1 404 responses
  GET /doofs/home.php... HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?rev=1.6&sortby=log&view=markup HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?hideattic=0&only_with_tag=HEAD HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?annotate=1.3&hideattic=0 HTTP/1.1 with response code(s) 1 404 responses
  GET /signup.cfm HTTP/1.0 with response code(s) 1 404 responses
  GET /PHP-Login-System-with-Admin-Features/, make sure your database name and password information is specified correctly in constants.php. If you still can HTTP/1.1 with response code(s) 1 400 responses
  GET /winddancer HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/dhtml_form_rollover/index.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1 with response code(s) 3 400 responses
  GET /jeff/code/rollover_n_click/index.cfm HTTP/1.0 with response code(s) 2 404 responses
  GET /w00tw00t.at.ISC.SANS.test0:) HTTP/1.1 with response code(s) 2 400 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?rev=1.25&hideattic=0&r1=1.17&view=log HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/unchecking_radio_buttons.cfm HTTP/1.1 with response code(s) 2 404 responses
  GET /jeff/code/rank_select.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/dhtml_form_rollover/index.cfm HTTP/1.0 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?rev=1.25&hideattic=0&r1=1.25&view=log HTTP/1.1 with response code(s) 1 404 responses
  GET /isaac/photos/index.cfm?currentnum=18 HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?rev=1.10&content-type=text/vnd.viewcvs-markup&sortby=log HTTP/1.1 with response code(s) 1 404 responses
  GET /email/index.cfm?action=detail&cid=15576 HTTP/1.0 with response code(s) 1 404 responses
  GET /rss/articles.rss HTTP/1.0 with response code(s) 2 404 responses
  - with response code(s) 42 408 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?rev=1.1&content-type=text/vnd.viewcvs-markup&sortby=log HTTP/1.1 with response code(s) 1 404 responses
  GET /mwarden/weblog HTTP/1.0 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/beo_ng/favicon.ico?hideattic=0&sortdir=down&rev=1.1&only_with_tag=MAIN&sortby=date&view=log HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/js_url_variables/index.cfm HTTP/1.1 with response code(s) 3 404 responses
  GET /mantruc/blog HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/form_to_window/index.cfm HTTP/1.1 with response code(s) 2 404 responses
  GET /nmk HTTP/1.1 with response code(s) 1 404 responses
  GET /help/caspdoc/html/ado_recordset_object_absolutepage HTTP/1.1 with response code(s) 1 404 responses
  GET /mwarden/weblog HTTP/1.1 with response code(s) 1 404 responses
  GET /isaac/photos/index.cfm?currentnum=46 HTTP/1.1 with response code(s) 1 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/.cvsignore?rev=1.2&hideattic=0&only_with_tag=HEAD&sortdir=down&view=log HTTP/1.1 with response code(s) 1 404 responses
  GET /~atdt1991/uploads HTTP/1.1 with response code(s) 1 404 responses
  GET /djc HTTP/1.1 with response code(s) 1 404 responses
  GET /garrett/site/books/factual HTTP/1.1 with response code(s) 2 404 responses
  GET /cgi-bin/viewcvs.cgi/weo_theme/print.module?hideattic=0&r1=1.19&r2=1.20 HTTP/1.1 with response code(s) 1 404 responses

A total of 10 ROBOTS were logged 
      Mozilla/5.0 (compatible; Ask Jeeves/Teoma; +http://about.ask.com/en/docs/about/webmasters.shtml) 1 time(s) 
      Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp) 8 time(s) 
      Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) 1 time(s) 
      Googlebot-Image/1.0 1 time(s) 
      org_viewer (larbin2.6.3 at unspecified.mail) 5 time(s) 
      ia_archiver (+http://www.alexa.com/site/help/webmasters; crawler at alexa.com) 1 time(s) 
      msnbot/1.1 (+http://search.msn.com/msnbot.htm) 19 time(s) 
      Mozilla/5.0 (Twiceler-0.9 http://www.cuil.com/twiceler/robot.html) 2 time(s) 
      Mozilla/5.0 (compatible; ScoutJet; +http://www.scoutjet.com/) 1 time(s) 
      Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705) 1 time(s) 

 ---------------------- httpd End ------------------------- 


 --------------------- Kernel Begin ------------------------ 


1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:12691/80 shrinks window 1888633327:1888634775. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:15296/80 shrinks window 2002634737:2002636185. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:15573/80 shrinks window 3296951437:3296952885. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:16724/80 shrinks window 2322909431:2322909437. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:16969/80 shrinks window 1213462820:1213465716. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:17357/80 shrinks window 3832009066:3832010514. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:18954/80 shrinks window 704489649:704491097. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:19068/80 shrinks window 1814619813:1814621261. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:19068/80 shrinks window 1814647325:1814648773. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:20984/80 shrinks window 2305602753:2305604201. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:21178/80 shrinks window 3396805168:3396806616. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:21608/80 shrinks window 2654847935:2654849383. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:21734/80 shrinks window 2805646142:2805647590. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:22866/80 shrinks window 2152492288:2152493736. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:22866/80 shrinks window 2152518352:2152521248. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:22866/80 shrinks window 2152544416:2152545864. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:26593/80 shrinks window 1507279145:1507280593. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:27465/80 shrinks window 2347998783:2348000231. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:28085/80 shrinks window 3082956484:3082959380. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:30444/80 shrinks window 861151220:861152668. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:35580/80 shrinks window 3451169358:3451170806. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:36126/80 shrinks window 1759598850:1759600298. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:41506/80 shrinks window 2589795550:2589796998. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:45817/80 shrinks window 2749415385:2749416833. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:46499/80 shrinks window 2517975303:2517976751. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:46499/80 shrinks window 2518001367:2518002815. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:47706/80 shrinks window 459117457:459120353. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:50137/80 shrinks window 3731057042:3731058490. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:50893/80 shrinks window 1360601853:1360603301. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:52828/80 shrinks window 3229263586:3229265034. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:53777/80 shrinks window 3484655114:3484655427. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:54365/80 shrinks window 3043743601:3043745049. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:55420/80 shrinks window 1697333212:1697334347. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:55625/80 shrinks window 2031916707:2031919603. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:56679/80 shrinks window 824743733:824745181. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:56983/80 shrinks window 1573244460:1573245908. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:60409/80 shrinks window 2470967067:2470968515. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:61172/80 shrinks window 3929202884:3929204332. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:61561/80 shrinks window 3620207851:3620210747. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.112:63524/80 shrinks window 1033038282:1033039730. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:10552/80 shrinks window 986485455:986486903. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:11487/80 shrinks window 1632703532:1632706428. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:34065/80 shrinks window 4136183695:4136185143. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:34606/80 shrinks window 975171291:975172739. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:37012/80 shrinks window 4198053563:4198055011. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:38910/80 shrinks window 1662155197:1662156645. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:38910/80 shrinks window 1662182709:1662185605. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:42029/80 shrinks window 1629202018:1629203466. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:48854/80 shrinks window 1755513156:1755514604. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:53986/80 shrinks window 4227715905:4227718801. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:54335/80 shrinks window 1426725634:1426729978. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:55560/80 shrinks window 1044279078:1044280526. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:62404/80 shrinks window 926127079:926129975. Repaired.
2 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:62565/80 shrinks window 4165605443:4165608339. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:62565/80 shrinks window 4165632955:4165634403. Repaired.
1 Time(s): TCP: Treason uncloaked! Peer 38.108.180.43:64626/80 shrinks window 1705617290:1705620186. Repaired.
1 Time(s): device eth0 entered promiscuous mode
1 Time(s): device eth0 left promiscuous mode
1 Time(s): sending pkt_too_big (len[1450] pmtu[1420]) to self
1 Time(s): sending pkt_too_big (len[1500] pmtu[1496]) to self

 ---------------------- Kernel End ------------------------- 


 --------------------- pam_unix Begin ------------------------ 

cron:
   Sessions Opened:
      root: 366 Time(s)
      mailman: 292 Time(s)
      www-data: 144 Time(s)
      dmah: 2 Time(s)
      neuro: 1 Time(s)

sshd:
   Sessions Opened:
      dmah: 1 Time(s)

su:
   Sessions Opened:
      (uid=0) -> nobody: 1 Time(s)
      dmah(uid=0) -> root: 1 Time(s)


 ---------------------- pam_unix End ------------------------- 


 --------------------- sendmail Begin ------------------------ 


ERROR: Could not open /etc/mail/local-host-names

ERROR: Could not open /etc/mail/access


Message Size Distribution:
Range          # Msgs       KBytes
0 - 10k             0            0
10k - 20k           0            0
20k - 50k           0            0
50k - 100k          0            0
100k - 500k         0            0
500k - 1Mb          0            0
1Mb - 2Mb           0            0
2Mb - 5Mb           0            0
5Mb - 10Mb          0            0
10Mb+               0            0
----------------------------------
TOTAL               0            0

 ---------------------- sendmail End ------------------------- 


 --------------------- SSHD Begin ------------------------ 


Couldn't resolve these IPs:
   unknown.caratnetworks.com: 2 Time(s)

Didn't receive an ident from these IPs:
   219.140.253.199: 5 Time(s)
   4a.d5.1343.static.theplanet.com (67.19.213.74): 5 Time(s)
   60.220.218.88: 3 Time(s)
   67.76.187.169: 5 Time(s)
   h-66-167-107-139.lsanca54.covad.net (66.167.107.139): 3 Time(s)
   mail.waiconnor.net (66.167.107.138): 2 Time(s)
   unknown.caratnetworks.com (174.137.52.170): 2 Time(s)

Failed logins from these:
   admin/password from 219.140.253.199: 4 Time(s)
   admin/password from 60.220.218.88: 9 Time(s)
   admin/password from 67.19.213.74: 5 Time(s)
   admin1/password from 66.167.107.138: 7 Time(s)
   admin1/password from 66.167.107.139: 3 Time(s)
   andrea/password from 219.140.253.199: 4 Time(s)
   backup/password from 219.140.253.199: 2 Time(s)
   cnasftp/password from 88.191.97.219: 3 Time(s)
   contribute/password from 88.191.97.219: 3 Time(s)
   customer/password from 66.167.107.138: 1 Time(s)
   customer/password from 66.167.107.139: 2 Time(s)
   d13943/password from 88.191.97.219: 3 Time(s)
   dedicated/password from 66.167.107.138: 6 Time(s)
   dedicated/password from 66.167.107.139: 2 Time(s)
   etienk/password from 88.191.97.219: 6 Time(s)
   ftp/password from 219.140.253.199: 5 Time(s)
   ftp/password from 67.76.187.169: 5 Time(s)
   ftpuser/password from 67.76.187.169: 4 Time(s)
   guest/password from 219.140.253.199: 1 Time(s)
   harrisi/password from 88.191.97.219: 6 Time(s)
   html/password from 66.167.107.138: 6 Time(s)
   html/password from 66.167.107.139: 2 Time(s)
   janus/password from 88.191.97.219: 6 Time(s)
   jirka/password from 88.191.97.219: 6 Time(s)
   mail/password from 67.76.187.169: 3 Time(s)
   mailer/password from 67.76.187.169: 2 Time(s)
   mantis/password from 88.191.97.219: 9 Time(s)
   mayomo/password from 88.191.97.219: 6 Time(s)
   miquelfi/password from 60.220.218.88: 3 Time(s)
   monster/password from 88.191.97.219: 3 Time(s)
   office/password from 67.76.187.169: 2 Time(s)
   peanut/password from 66.167.107.138: 2 Time(s)
   peanut/password from 66.167.107.139: 1 Time(s)
   peanutlinux/password from 66.167.107.138: 1 Time(s)
   rajjw/password from 88.191.97.219: 3 Time(s)
   robust/password from 88.191.97.219: 3 Time(s)
   root/password from 174.137.52.170: 2 Time(s)
   root/password from 219.140.253.199: 5 Time(s)
   root/password from 60.220.218.88: 108 Time(s)
   root/password from 66.167.107.138: 21 Time(s)
   root/password from 66.167.107.139: 18 Time(s)
   root/password from 67.19.213.74: 65 Time(s)
   root/password from 88.191.97.219: 82 Time(s)
   sales/password from 219.140.253.199: 5 Time(s)
   smbtest/password from 88.191.97.219: 6 Time(s)
   sysmanager/password from 66.167.107.138: 4 Time(s)
   sysmanager/password from 66.167.107.139: 2 Time(s)
   user/password from 67.76.187.169: 2 Time(s)
   user1/password from 66.167.107.138: 3 Time(s)
   user1/password from 66.167.107.139: 5 Time(s)
   webmaster/password from 219.140.253.199: 5 Time(s)

Illegal users from these:
   admin/none from 219.140.253.199: 4 Time(s)
   admin/none from 60.220.218.88: 9 Time(s)
   admin/none from 67.19.213.74: 5 Time(s)
   admin/password from 219.140.253.199: 4 Time(s)
   admin/password from 60.220.218.88: 9 Time(s)
   admin/password from 67.19.213.74: 5 Time(s)
   admin1/none from 66.167.107.138: 7 Time(s)
   admin1/none from 66.167.107.139: 3 Time(s)
   admin1/password from 66.167.107.138: 7 Time(s)
   admin1/password from 66.167.107.139: 3 Time(s)
   andrea/none from 219.140.253.199: 4 Time(s)
   andrea/password from 219.140.253.199: 4 Time(s)
   cnasftp/none from 88.191.97.219: 3 Time(s)
   cnasftp/password from 88.191.97.219: 3 Time(s)
   contribute/none from 88.191.97.219: 3 Time(s)
   contribute/password from 88.191.97.219: 3 Time(s)
   customer/none from 66.167.107.138: 1 Time(s)
   customer/none from 66.167.107.139: 2 Time(s)
   customer/password from 66.167.107.138: 1 Time(s)
   customer/password from 66.167.107.139: 2 Time(s)
   d13943/none from 88.191.97.219: 3 Time(s)
   d13943/password from 88.191.97.219: 3 Time(s)
   dedicated/none from 66.167.107.138: 6 Time(s)
   dedicated/none from 66.167.107.139: 2 Time(s)
   dedicated/password from 66.167.107.138: 6 Time(s)
   dedicated/password from 66.167.107.139: 2 Time(s)
   etienk/none from 88.191.97.219: 6 Time(s)
   etienk/password from 88.191.97.219: 6 Time(s)
   ftpuser/none from 67.76.187.169: 4 Time(s)
   ftpuser/password from 67.76.187.169: 4 Time(s)
   guest/none from 219.140.253.199: 1 Time(s)
   guest/password from 219.140.253.199: 1 Time(s)
   harrisi/none from 88.191.97.219: 6 Time(s)
   harrisi/password from 88.191.97.219: 6 Time(s)
   html/none from 66.167.107.138: 6 Time(s)
   html/none from 66.167.107.139: 2 Time(s)
   html/password from 66.167.107.138: 6 Time(s)
   html/password from 66.167.107.139: 2 Time(s)
   janus/none from 88.191.97.219: 6 Time(s)
   janus/password from 88.191.97.219: 6 Time(s)
   jirka/none from 88.191.97.219: 6 Time(s)
   jirka/password from 88.191.97.219: 6 Time(s)
   mailer/none from 67.76.187.169: 2 Time(s)
   mailer/password from 67.76.187.169: 2 Time(s)
   mantis/none from 88.191.97.219: 9 Time(s)
   mantis/password from 88.191.97.219: 9 Time(s)
   mayomo/none from 88.191.97.219: 6 Time(s)
   mayomo/password from 88.191.97.219: 6 Time(s)
   miquelfi/none from 60.220.218.88: 3 Time(s)
   miquelfi/password from 60.220.218.88: 3 Time(s)
   monster/none from 88.191.97.219: 3 Time(s)
   monster/password from 88.191.97.219: 3 Time(s)
   office/none from 67.76.187.169: 2 Time(s)
   office/password from 67.76.187.169: 2 Time(s)
   peanut/none from 66.167.107.138: 2 Time(s)
   peanut/none from 66.167.107.139: 1 Time(s)
   peanut/password from 66.167.107.138: 2 Time(s)
   peanut/password from 66.167.107.139: 1 Time(s)
   peanutlinux/none from 66.167.107.138: 1 Time(s)
   peanutlinux/password from 66.167.107.138: 1 Time(s)
   rajjw/none from 88.191.97.219: 3 Time(s)
   rajjw/password from 88.191.97.219: 3 Time(s)
   robust/none from 88.191.97.219: 3 Time(s)
   robust/password from 88.191.97.219: 3 Time(s)
   sales/none from 219.140.253.199: 5 Time(s)
   sales/password from 219.140.253.199: 5 Time(s)
   smbtest/none from 88.191.97.219: 6 Time(s)
   smbtest/password from 88.191.97.219: 6 Time(s)
   sysmanager/none from 66.167.107.138: 4 Time(s)
   sysmanager/none from 66.167.107.139: 2 Time(s)
   sysmanager/password from 66.167.107.138: 4 Time(s)
   sysmanager/password from 66.167.107.139: 2 Time(s)
   user/none from 67.76.187.169: 2 Time(s)
   user/password from 67.76.187.169: 2 Time(s)
   user1/none from 66.167.107.138: 3 Time(s)
   user1/none from 66.167.107.139: 5 Time(s)
   user1/password from 66.167.107.138: 3 Time(s)
   user1/password from 66.167.107.139: 5 Time(s)
   webmaster/none from 219.140.253.199: 5 Time(s)
   webmaster/password from 219.140.253.199: 5 Time(s)

Users logging in through sshd:
   dmah:
      S01060014d15c5152.cg.shawcable.net (70.72.12.124): 1 time

**Unmatched Entries**
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER

 ---------------------- SSHD End ------------------------- 


 --------------------- Sudo (secure-log) Begin ------------------------ 

==============================================================================
dmah => root
------------------------------------------------------------------------------
/bin/su -

 ---------------------- Sudo (secure-log) End ------------------------- 


 --------------------- Syslogd Begin ------------------------ 


Syslogd started 1 Time(s)

 ---------------------- Syslogd End ------------------------- 



------------------ Disk Space --------------------

/dev/hda3              72G   53G   16G  78% /
/dev/hda1              92M  6.3M   81M   8% /boot


 ###################### LogWatch End ######################### 




More information about the Sysadmin mailing list