[Sysadmin] LogWatch for tempest

root root at tempest.evolt.org
Sun Apr 18 06:25:40 CDT 2010


 ################### LogWatch 5.2.2 (06/23/04) #################### 
       Processing Initiated: Sun Apr 18 06:25:21 2010
       Date Range Processed: yesterday
     Detail Level of Output: 10
          Logfiles for Host: tempest
 ################################################################ 

 --------------------- Cron Begin ------------------------ 

Commands Run:
   User dmah:
      /home/dmah/bin/article_reminder.pl: 1 Time(s)
      /home/dmah/bin/comment_reminder.pl: 1 Time(s)
   User mailman:
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/checkdbs: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/disabled: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/gate_news: 288 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/nightly_gzip: 1 Time(s)
      /usr/bin/python -S /home/mailman/lists.evolt.org/cron/senddigests: 1 Time(s)
   User neuro:
      ~neuro/beo/oldbeo/mkarchivesize >/dev/null 2>&1: 1 Time(s)
   User root:
         run-parts --report /etc/cron.hourly: 24 Time(s)
        [ -d /var/lib/php4 ] && find /var/lib/php4/ -type f -cmin +$(/usr/lib/php4/maxlifetime) -print0 | xargs -r -0 rm: 48 Time(s)
      /home/dmah/bin/qmail-kill.sh 1> /dev/null 2>&1: 144 Time(s)
      /store/host/browsers.evolt.org/mkarchivesize: 1 Time(s)
      /usr/bin/freshclam --quiet -l /var/log/clam-update.log: 1 Time(s)
      /usr/sbin/ntpdate -su us.pool.ntp.org us.pool.ntp.org: 1 Time(s)
      /var/qmail/bin/qmailstats 1>/dev/null 2>/dev/null: 1 Time(s)
      if [ -x /usr/bin/vnstat ] && [ `ls /var/lib/vnstat/ | wc -l` -ge 1 ]; then /usr/bin/vnstat -u; fi: 288 Time(s)
      test -x /usr/sbin/anacron || run-parts --report /etc/cron.daily: 1 Time(s)
      test -x /usr/sbin/cron-apt && /usr/sbin/cron-apt: 1 Time(s)
   User www-data:
      [ -x /usr/lib/cgi-bin/awstats.pl -a -f /etc/awstats/awstats.conf -a -r /var/log/apache/access.log ] && /usr/lib/cgi-bin/awstats.pl -config=awstats -update >/dev/null: 144 Time(s)

 ---------------------- Cron End ------------------------- 


 --------------------- EXIM Begin ------------------------ 


--- Messages history ---

3 messages delivered immediately to 3 total recipients

 ---------------------- EXIM End ------------------------- 


 --------------------- httpd Begin ------------------------ 

0.08 MB transfered in 334 responses  (1xx 0, 2xx 0, 3xx 22, 4xx 312, 5xx 0) 
 17 Images (0.01 MB),
 8 Documents (0.00 MB),
 163 Content pages (0.04 MB),
 146 Other (0.03 MB) 

A total of 52 unidentified 'other' records logged
  GET /djc/stdio/index.cfm/daddy/show/mommy/94 HTTP/1.1 with response code(s) 2 404 responses
  GET /article/breadcrumbs_for_php_lovers/17/4455/\" class=http://papal.square7.ch/C99.PHP? HTTP/1.1 with response code(s) 1 400 responses
  GET /marceloslg HTTP/1.1 with response code(s) 1 404 responses
  GET http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-5396533251015167&format=468x15_0ads_al&output=html&h=15&w=468&lmt=1271492585&channel=0835057552&color_bg=D2E7F4&color_border=D2E7F4&color_link=000000&color_text=000000&color_url=000000&flash=10.0.45&url=http%3A%2F%2Fwww.tizag.com%2FmysqlTutorial%2Fmysqlfetcharray.php&dt=1271492601138&shv=r20100331&correlator=1271492600099&frm=0&ga_vid=298123264.1271492600&ga_sid=1271492600&ga_hid=1458358001&ga_fc=0&u_tz=330&u_his=1&u_java=0&u_h=768&u_w=1024&u_ah=740&u_aw=1024&u_cd=24&u_nplug=12&u_nmime=30&biw=1008&bih=583&ref=http%3A%2F%2Fwww.google.co.in%2Furl%3Fsa%3Dt%26source%3Dweb%26ct%3Dres%26cd%3D1%26ved%3D0CAYQFjAA%26url%3Dhttp%253A%252F%252Fwww.tizag.com%252FmysqlTutorial%252Fmysqlfetcharray.php%26rct%3Dj%26q%3Darray%2Bvariables%2Bin%2Bmysql%2Bexamples%26ei%3DQG_JS_q_FM2frAfXxayrBQ%26usg%3DAFQjCNGjkvocrn2T-AGV9bRx2m7AsoJzkA&fu=0&ifi=2&dtd=M&xpc=CsvU6tKBJI&p=http%3A//www.tizag.com HTTP/1.1 with response code(s) 1 404 responses
  GET /php_login_script_with_remember_me_feature\" class=http://platchuk.110mb.com/c99shell.txt HTTP/1.1 with response code(s) 1 400 responses
  GET /arijit/dw_ext HTTP/1.1 with response code(s) 1 404 responses
  GET http://pagead2.googlesyndication.com/pagead/imgad?id=CJOhpNanwazV8gEQoAEY2AQyCOKq29N5Qgao HTTP/1.1 with response code(s) 1 404 responses
  GET /jesteruk HTTP/1.1 with response code(s) 1 404 responses
  GET /signup.cfm HTTP/1.1 with response code(s) 7 404 responses
  GET http://us.search.yahoo.com/404handler?src=toolbar&fr=slv404-&type=&url=http%3A%2F%2Fgoogleads.g.doubleclick.net%2Fpagead%2Fads%3Fclient%3Dca-pub-5396533251015167%26format%3D468x15_0ads_al%26output%3Dhtml%26h%3D15%26w%3D468%26lmt%3D1271492585%26channel%3D0835057552%26color_bg%3DD2E7F4%26color_border%3DD2E7F4%26color_link%3D000000%26color_text%3D000000%26color_url%3D000000%26flash%3D10.0.45%26url%3Dhttp%253A%252F%252Fwww.tizag.com%252FmysqlTutorial%252Fmysqlfetcharray.php%26dt%3D1271492601138%26shv%3Dr20100331%26correlator%3D1271492600099%26frm%3D0%26ga_vid%3D298123264.1271492600%26ga_sid%3D1271492600%26ga_hid%3D1458358001%26ga_fc%3D0%26u_tz%3D330%26u_his%3D1%26u_java%3D0%26u_h%3D768%26u_w%3D1024%26u_ah%3D740%26u_aw%3D1024%26u_cd%3D24%26u_nplug%3D12%26u_nmime%3D30%26biw%3D1008%26bih%3D583%26ref%3Dhttp%253A%252F%252Fwww.google.co.in%252Furl%253Fsa%253Dt%2526source%253Dweb%2526ct%253Dres%2526cd%253D1%2526ved%253D0CAYQFjAA%2526url%253Dhttp%25253A%25252F%25252Fwww.tizag.com%25252FmysqlTutorial%25252Fmysqlfetcharray.php%2526rct%253Dj%2526q%253Darray%252Bvariables%252Bin%252Bmysql%252Bexamples%2526ei%253DQG_JS_q_FM2frAfXxayrBQ%2526usg%253DAFQjCNGjkvocrn2T-AGV9bRx2m7AsoJzkA%26fu%3D0%26ifi%3D2%26dtd%3DM%26xpc%3DCsvU6tKBJI%26p%3Dhttp%253A%2F%2Fwww.tizag.com HTTP/1.1 with response code(s) 1 404 responses
  =MmZ\x1c\xa6=a\xa2\xa1\x18\xf7lAzC\x88fiV\x85\xee\xb5\x88\xf5\xb5\xfbo\x03`\x14\xe6\xa7j\xbe\r\r\xa2\xd1\x7f\xc1oF<g\xd6_!\xa1j8\x91\xba/\x1e\xc0\\\x9d\xb3\x96\xb0\x85\xca2W\x8a\xb5\x0c\xe71\xa41\t\x1c\x80X`\xd4\xa9M\x92\x10\xe6\xf2JaJ\xac@\x97\x85\x1d\x05H\xf6\xc8\xe9Q\xd1\xbd\xd6\xcbd\xb7 with response code(s) 1 400 responses
  GET /djc/stdio/index.cfm/daddy/show/mommy/137 HTTP/1.1 with response code(s) 1 404 responses
  GET /signup.cfm HTTP/1.0 with response code(s) 1 404 responses
  GET /jswiders HTTP/1.1 with response code(s) 1 404 responses
  GET http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1612102651&utmcs=ISO-8859-1&utmsr=1024x768&utmsc=24-bit&utmul=en-us&utmje=0&utmfl=10.0%20r45&utmcn=1&utmdt=Perl%20Tutorial%20-%20MySQL%20Query&utmhn=www.tizag.com&utmhid=974653342&utmr=http://www.google.co.in/url?sa=t&source=web&ct=res&cd=2&ved=0CAkQFjAB&url=http%3A%2F%2Fwww.tizag.com%2FperlT%2Fperlmysqlquery.php&rct=j&q=array+variables+in+mysql+examples&ei=QG_JS_q_FM2frAfXxayrBQ&usg=AFQjCNEiH6K9BTJRqzCFEu3OJkniru36pQ&utmp=/perlT/perlmysqlquery.php&utmac=UA-138146-2&utmcc=__utma%3D219576220.650412022.1271492599.1271492599.1271492599.1%3B%2B__utmz%3D219576220.1271492610.1.1.utmccn%3D(organic)%7Cutmcsr%3Dgoogle%7Cutmctr%3Darray%2Bvariables%2Bin%2Bmysql%2Bexamples%7Cutmcmd%3Dorganic%3B%2B HTTP/1.1 with response code(s) 1 404 responses
  GET /user/soapCaller.bs?x=x HTTP/1.0 with response code(s) 2 404 responses
  GET /mwarden HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/dhtml_form_rollover/index.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1 with response code(s) 38 400 responses
  GET /jeff/code/dhtml_form_rollover/index.cfm HTTP/1.0 with response code(s) 1 404 responses
  GET /djc/stdio/index.cfm/daddy/show/mommy/116 HTTP/1.1 with response code(s) 1 404 responses
  GET http://pubads.g.doubleclick.net/gampad/ads?correlator=1271492588847&output=json_html&callback=GA_googleSetAdContentsBySlotForSync&impl=s&eid=,&client=ca-pub-5396533251015167&slotname=Tizag_MySQL_Content_468x60&page_slots=Tizag_MySQL_Content_468x60&cookie_enabled=1&ga_vid=298123264.1271492600&ga_sid=1271492600&ga_hid=1458358001&url=http%3A%2F%2Fwww.tizag.com%2FmysqlTutorial%2Fmysqlfetcharray.php&ref=http%3A%2F%2Fwww.google.co.in%2Furl%3Fsa%3Dt%26source%3Dweb%26ct%3Dres%26cd%3D1%26ved%3D0CAYQFjAA%26url%3Dhttp%253A%252F%252Fwww.tizag.com%252FmysqlTutorial%252Fmysqlfetcharray.php%26rct%3Dj%26q%3Darray%2Bvariables%2Bin%2Bmysql%2Bexamples%26ei%3DQG_JS_q_FM2frAfXxayrBQ%26usg%3DAFQjCNGjkvocrn2T-AGV9bRx2m7AsoJzkA&lmt=1271492585&dt=1271492600099&cc=100&biw=1008&bih=583&ifi=1&u_tz=330&u_his=1&u_h=768&u_w=1024&u_ah=740&u_aw=1024&u_cd=24&u_nplug=12&u_nmime=30&flash=10.0.45 HTTP/1.1 with response code(s) 1 404 responses
  GET /signup.cfm;\" HTTP/1.0 with response code(s) 1 404 responses
  GET /article/incoming_mail_and_php/18/27914/index.html\" class=http://papal.square7.ch/C99.PHP? HTTP/1.1 with response code(s) 1 400 responses
  GET /dshadovi/traffic.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /rudy HTTP/1.1 with response code(s) 1 404 responses
  GET /renaming_files_with_perl/t work.  The command line passes the exact string to the Perl program.  For instance, when using *.txt to rename all of the .txt files, the Perl script gets the string HTTP/1.1 with response code(s) 2 400 responses
  GET /desflynn HTTP/1.1 with response code(s) 1 404 responses
  GET http://pubads.g.doubleclick.net/gampad/ads?correlator=1271492588847&output=json_html&callback=GA_googleSetAdContentsBySlotForSync&impl=s&eid=,&client=ca-pub-5396533251015167&slotname=Tizag_MySQL_Skyscraper_160x600&page_slots=Tizag_MySQL_Content_468x60%2CTizag_MySQL_Skyscraper_160x600&cookie_enabled=1&ga_vid=650412022.1271492599&ga_sid=1271492599&ga_hid=1458358001&ga_fc=true&url=http%3A%2F%2Fwww.tizag.com%2FmysqlTutorial%2Fmysqlfetcharray.php&ref=http%3A%2F%2Fwww.google.co.in%2Furl%3Fsa%3Dt%26source%3Dweb%26ct%3Dres%26cd%3D1%26ved%3D0CAYQFjAA%26url%3Dhttp%253A%252F%252Fwww.tizag.com%252FmysqlTutorial%252Fmysqlfetcharray.php%26rct%3Dj%26q%3Darray%2Bvariables%2Bin%2Bmysql%2Bexamples%26ei%3DQG_JS_q_FM2frAfXxayrBQ%26usg%3DAFQjCNGjkvocrn2T-AGV9bRx2m7AsoJzkA&lmt=1271492585&dt=1271492610533&cc=100&biw=1008&bih=583&ifi=3&u_tz=330&u_his=1&u_h=768&u_w=1024&u_ah=740&u_aw=1024&u_cd=24&u_nplug=12&u_nmime=30&flash=10.0.45 HTTP/1.1 with response code(s) 1 404 responses
  GET /djc/stdio HTTP/1.1 with response code(s) 1 404 responses
  GET /simonc/php/bookmarklet.phps HTTP/1.0 with response code(s) 1 404 responses
  GET /lindsay/nav HTTP/1.1 with response code(s) 1 404 responses
  GET /yourusername HTTP/1.1 with response code(s) 1 404 responses
  - with response code(s) 46 408 responses
  GET /gozz/stripcr.cfm HTTP/1.1 with response code(s) 2 404 responses
  GET /mantruc/blog HTTP/1.1 with response code(s) 1 404 responses
  GET http://pagead2.googlesyndication.com/pagead/ads?client=ca-pub-0714075272818912&format=336x280_as&output=html&h=280&w=336&lmt=1271492593&ad_type=text_image&color_bg=FFFFFF&color_border=D20000&color_link=AA3300&color_text=000000&color_url=CC3300&flash=10.0.45&url=http%3A%2F%2Fwww.roseindia.net%2Fsoftware-tutorials%2Fdetail%2F23500&dt=1271492595626&shv=r20100331&prev_fmts=120x600_as&correlator=1271492594103&dblk=1&frm=0&ga_vid=23483497.1271492595&ga_sid=1271492595&ga_hid=753674935&ga_fc=0&u_tz=330&u_his=1&u_java=0&u_h=499&u_w=666&u_ah=481&u_aw=666&u_cd=24&u_nplug=12&u_nmime=30&biw=655&bih=369&ref=http%3A%2F%2Fwww.google.co.in%2Furl%3Fsa%3Dt%26source%3Dweb%26ct%3Dres%26cd%3D9%26ved%3D0CCIQFjAI%26url%3Dhttp%253A%252F%252Fwww.roseindia.net%252Fsoftware-tutorials%252Fdetail%252F23500%26rct%3Dj%26q%3Darray%2Bvariables%2Bin%2Bmysql%2Bexamples%26ei%3DQG_JS_q_FM2frAfXxayrBQ%26usg%3DAFQjCNF0-4FJSgdFaNt-Te6IvVBZcT_PuQ&fu=0&ifi=2&dtd=360 HTTP/1.1 with response code(s) 1 404 responses
  GET /dshadovi/cf_columnlist/demo.cfm HTTP/1.1 with response code(s) 1 404 responses
  HEAD /signup.cfm HTTP/1.1 with response code(s) 2 404 responses
  GET /mwarden/weblog HTTP/1.1 with response code(s) 1 404 responses
  GET /matthewo HTTP/1.1 with response code(s) 1 404 responses
  GET /node/60222 show.php?id=http://www.fileden.com/files/2009/12/18/2694402//irc.adelais.netinfo.txt? HTTP/1.1 with response code(s) 1 400 responses
  GET http://ds.addthis.com/red/psi/p.json?callback=_ate.hps&uid=4bc83175dd11cfb3&url=http%3A%2F%2Fwww.tizag.com%2FmysqlTutorial%2Fmysqlfetcharray.php&ref=www.google.co.in%2Furl%3Fsa%3Dt%26source%3Dweb%26ct%3Dres%26cd%3D1%26ved%3D0CAYQFjAA%26url%3Dhttp%253A%252F%252Fwww.tizag.com%252FmysqlTutorial%252Fmysqlfetcharray.php%26rct%3Dj%26q%3Darray%2Bvariables%2Bin%2Bmysql%2Bexamples%26ei%3DQG_JS_q_FM2frAfXxayrBQ%26usg%3DAFQjCNGjkvocrn2T-AGV9bRx2m7AsoJzkA&1fybwjs HTTP/1.1 with response code(s) 1 404 responses
  GET http://us.search.yahoo.com/404handler?src=toolbar&fr=slv404-&type=&url=http%3A%2F%2Fwww.dmcinsights.com%2Fphorum%2Fread.php%3F13%2C35622%2C35623 HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/imagemap_rollover/index.cfm HTTP/1.1 with response code(s) 1 404 responses
  GET /djc/stdio%20for%20news%20and HTTP/1.1 with response code(s) 1 404 responses
  GET /arijit HTTP/1.1 with response code(s) 1 404 responses
  GET http://us.search.yahoo.com/404handler?src=toolbar&fr=slv404-&type=&url=http%3A%2F%2Fpagead2.googlesyndication.com%2Fpagead%2Fads%3Fclient%3Dca-pub-0714075272818912%26format%3D336x280_as%26output%3Dhtml%26h%3D280%26w%3D336%26lmt%3D1271492593%26ad_type%3Dtext_image%26color_bg%3DFFFFFF%26color_border%3DD20000%26color_link%3DAA3300%26color_text%3D000000%26color_url%3DCC3300%26flash%3D10.0.45%26url%3Dhttp%253A%252F%252Fwww.roseindia.net%252Fsoftware-tutorials%252Fdetail%252F23500%26dt%3D1271492595626%26shv%3Dr20100331%26prev_fmts%3D120x600_as%26correlator%3D1271492594103%26dblk%3D1%26frm%3D0%26ga_vid%3D23483497.1271492595%26ga_sid%3D1271492595%26ga_hid%3D753674935%26ga_fc%3D0%26u_tz%3D330%26u_his%3D1%26u_java%3D0%26u_h%3D499%26u_w%3D666%26u_ah%3D481%26u_aw%3D666%26u_cd%3D24%26u_nplug%3D12%26u_nmime%3D30%26biw%3D655%26bih%3D369%26ref%3Dhttp%253A%252F%252Fwww.google.co.in%252Furl%253Fsa%253Dt%2526source%253Dweb%2526ct%253Dres%2526cd%253D9%2526ved%253D0CCIQFjAI%2526url%253Dhttp%25253A%25252F%25252Fwww.roseindia.net%25252Fsoftware-tutorials%25252Fdetail%25252F23500%2526rct%253Dj%2526q%253Darray%252Bvariables%252Bin%252Bmysql%252Bexamples%2526ei%253DQG_JS_q_FM2frAfXxayrBQ%2526usg%253DAFQjCNF0-4FJSgdFaNt-Te6IvVBZcT_PuQ%26fu%3D0%26ifi%3D2%26dtd%3D360 HTTP/1.1 with response code(s) 1 404 responses
  GET /node/60384 page.php?file=http://www.fileden.com/files/2009/12/18/2694402//irc.adelais.netinfo.txt? HTTP/1.1 with response code(s) 1 400 responses
  GET /garrett/site/books/factual HTTP/1.1 with response code(s) 2 404 responses
  GET /signup.cfm5%20l1%20e\"%20O6 HTTP/1.1 with response code(s) 1 404 responses
  GET /jeff/code/capture_window/index.cfm HTTP/1.1 with response code(s) 1 404 responses

A total of 12 ROBOTS were logged 
      Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp) 3 time(s) 
      Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) 2 time(s) 
      yacybot (amd64 Windows 2003 5.2; java 1.6.0_19; Europe/en) http://yacy.net/bot.html 1 time(s) 
      Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727) 1 time(s) 
      Yandex/1.01.001 (compatible; Win16; I) 2 time(s) 
      Mozilla/5.0 (compatible; spbot/2.0.2; +http://www.seoprofiler.com/bot/ ) 5 time(s) 
      Baiduspider+(+http://www.baidu.jp/spider/) 1 time(s) 
      Mozilla/5.0 (compatible; 008/0.83; http://www.80legs.com/spider.html;) Gecko/2008032620 1 time(s) 
      msnbot-media/1.1 (+http://search.msn.com/msnbot.htm) 1 time(s) 
      msnbot/2.0b (+http://search.msn.com/msnbot.htm) 38 time(s) 
      Mozilla/5.0 (Twiceler-0.9 http://www.cuil.com/twiceler/robot.html) 5 time(s) 
      Baiduspider+(+http://www.baidu.com/search/spider.htm) 2 time(s) 

 ---------------------- httpd End ------------------------- 


 --------------------- Kernel Begin ------------------------ 


1 Time(s): device eth0 entered promiscuous mode
1 Time(s): device eth0 left promiscuous mode

 ---------------------- Kernel End ------------------------- 


 --------------------- pam_unix Begin ------------------------ 

cron:
   Sessions Opened:
      root: 510 Time(s)
      mailman: 292 Time(s)
      www-data: 144 Time(s)
      dmah: 2 Time(s)
      neuro: 1 Time(s)

su:
   Sessions Opened:
      (uid=0) -> nobody: 1 Time(s)


 ---------------------- pam_unix End ------------------------- 


 --------------------- sendmail Begin ------------------------ 


ERROR: Could not open /etc/mail/local-host-names

ERROR: Could not open /etc/mail/access


Message Size Distribution:
Range          # Msgs       KBytes
0 - 10k             0            0
10k - 20k           0            0
20k - 50k           0            0
50k - 100k          0            0
100k - 500k         0            0
500k - 1Mb          0            0
1Mb - 2Mb           0            0
2Mb - 5Mb           0            0
5Mb - 10Mb          0            0
10Mb+               0            0
----------------------------------
TOTAL               0            0

 ---------------------- sendmail End ------------------------- 


 --------------------- SSHD Begin ------------------------ 


Couldn't resolve these IPs:
   187-50-29-42.customer.tdatabrasil.net.br: 73 Time(s)

Didn't receive an ident from these IPs:
   190.54.18.196: 2 Time(s)
   222.73.205.9: 4 Time(s)
   87-198-219-219.ptr.magnet.ie (87.198.219.219): 5 Time(s)
   ip-166.213-139-215.reverse.meteksan.net.tr (213.139.215.166): 5 Time(s)
   net-93-65-200-63.cust.dsl.vodafone.it (93.65.200.63): 1 Time(s)
   static-70-34-9-213.b2bdsl.de (213.9.34.70): 5 Time(s)

Failed logins from these:
   abhinav/password from 219.148.23.254: 5 Time(s)
   abhisheks/password from 219.148.23.254: 5 Time(s)
   admin/password from 222.73.205.9: 5 Time(s)
   admin/password from 87.198.219.219: 5 Time(s)
   alias/password from 93.65.200.63: 1 Time(s)
   arvind/password from 219.148.23.254: 5 Time(s)
   bhawdeep/password from 219.148.23.254: 5 Time(s)
   binit/password from 219.148.23.254: 5 Time(s)
   cyrus/password from 93.65.200.63: 1 Time(s)
   db2fenc1/password from 219.148.23.254: 9 Time(s)
   db2inst1/password from 219.148.23.254: 6 Time(s)
   deploy/password from 219.148.23.254: 1 Time(s)
   fluffy/password from 222.73.205.9: 6 Time(s)
   ghost/password from 87.198.219.219: 10 Time(s)
   gloria/password from 222.73.205.9: 1 Time(s)
   goddard/password from 222.73.205.9: 1 Time(s)
   godfrey/password from 222.73.205.9: 1 Time(s)
   gordon/password from 222.73.205.9: 1 Time(s)
   grace/password from 222.73.205.9: 1 Time(s)
   gracie/password from 222.73.205.9: 1 Time(s)
   graham/password from 222.73.205.9: 1 Time(s)
   grant/password from 222.73.205.9: 1 Time(s)
   greg/password from 222.73.205.9: 1 Time(s)
   gregg/password from 222.73.205.9: 1 Time(s)
   guest/password from 222.73.205.9: 4 Time(s)
   guest/password from 87.198.219.219: 5 Time(s)
   magnos/password from 87.198.219.219: 2 Time(s)
   mysql001/password from 187.50.29.42: 5 Time(s)
   mysql01/password from 187.50.29.42: 5 Time(s)
   mysql02/password from 187.50.29.42: 5 Time(s)
   mysql03/password from 187.50.29.42: 5 Time(s)
   mysql1/password from 187.50.29.42: 3 Time(s)
   mysql10/password from 187.50.29.42: 4 Time(s)
   office/password from 93.65.200.63: 1 Time(s)
   oracle/password from 93.65.200.63: 1 Time(s)
   recruit/password from 93.65.200.63: 1 Time(s)
   root/password from 210.51.180.212: 21 Time(s)
   root/password from 222.73.205.9: 6 Time(s)
   root/password from 87.198.219.219: 24 Time(s)
   sales/password from 93.65.200.63: 1 Time(s)
   samba/password from 93.65.200.63: 1 Time(s)
   spam/password from 93.65.200.63: 1 Time(s)
   staff/password from 93.65.200.63: 1 Time(s)
   test/password from 222.73.205.9: 5 Time(s)
   test/password from 87.198.219.219: 5 Time(s)
   tomcat/password from 93.65.200.63: 1 Time(s)
   virus/password from 93.65.200.63: 1 Time(s)
   web/password from 187.50.29.42: 5 Time(s)
   webadmin/password from 93.65.200.63: 1 Time(s)
   webmaster/password from 187.50.29.42: 5 Time(s)
   webmaster/password from 222.73.205.9: 1 Time(s)
   webmaster001/password from 187.50.29.42: 5 Time(s)
   webmaster01/password from 187.50.29.42: 5 Time(s)
   webmaster02/password from 187.50.29.42: 4 Time(s)
   webmaster03/password from 187.50.29.42: 4 Time(s)
   webmaster1/password from 187.50.29.42: 7 Time(s)
   webmaster10/password from 187.50.29.42: 4 Time(s)
   webmaster2/password from 187.50.29.42: 2 Time(s)
   www/password from 187.50.29.42: 5 Time(s)

Illegal users from these:
   abhinav/none from 219.148.23.254: 5 Time(s)
   abhinav/password from 219.148.23.254: 5 Time(s)
   abhisheks/none from 219.148.23.254: 5 Time(s)
   abhisheks/password from 219.148.23.254: 5 Time(s)
   admin/none from 222.73.205.9: 5 Time(s)
   admin/none from 87.198.219.219: 5 Time(s)
   admin/password from 222.73.205.9: 5 Time(s)
   admin/password from 87.198.219.219: 5 Time(s)
   alias/password from 93.65.200.63: 1 Time(s)
   arvind/none from 219.148.23.254: 5 Time(s)
   arvind/password from 219.148.23.254: 5 Time(s)
   bhawdeep/none from 219.148.23.254: 5 Time(s)
   bhawdeep/password from 219.148.23.254: 5 Time(s)
   binit/none from 219.148.23.254: 5 Time(s)
   binit/password from 219.148.23.254: 5 Time(s)
   cyrus/none from 93.65.200.63: 1 Time(s)
   cyrus/password from 93.65.200.63: 1 Time(s)
   db2fenc1/none from 219.148.23.254: 9 Time(s)
   db2fenc1/password from 219.148.23.254: 9 Time(s)
   db2inst1/none from 219.148.23.254: 6 Time(s)
   db2inst1/password from 219.148.23.254: 6 Time(s)
   deploy/none from 219.148.23.254: 1 Time(s)
   deploy/password from 219.148.23.254: 1 Time(s)
   fluffy/none from 222.73.205.9: 6 Time(s)
   fluffy/password from 222.73.205.9: 6 Time(s)
   ghost/none from 87.198.219.219: 10 Time(s)
   ghost/password from 87.198.219.219: 10 Time(s)
   gloria/none from 222.73.205.9: 1 Time(s)
   gloria/password from 222.73.205.9: 1 Time(s)
   goddard/none from 222.73.205.9: 1 Time(s)
   goddard/password from 222.73.205.9: 1 Time(s)
   godfrey/none from 222.73.205.9: 1 Time(s)
   godfrey/password from 222.73.205.9: 1 Time(s)
   gordon/none from 222.73.205.9: 1 Time(s)
   gordon/password from 222.73.205.9: 1 Time(s)
   grace/none from 222.73.205.9: 1 Time(s)
   grace/password from 222.73.205.9: 1 Time(s)
   gracie/none from 222.73.205.9: 1 Time(s)
   gracie/password from 222.73.205.9: 1 Time(s)
   graham/none from 222.73.205.9: 1 Time(s)
   graham/password from 222.73.205.9: 1 Time(s)
   grant/none from 222.73.205.9: 1 Time(s)
   grant/password from 222.73.205.9: 1 Time(s)
   greg/none from 222.73.205.9: 1 Time(s)
   greg/password from 222.73.205.9: 1 Time(s)
   gregg/none from 222.73.205.9: 1 Time(s)
   gregg/password from 222.73.205.9: 1 Time(s)
   guest/none from 222.73.205.9: 4 Time(s)
   guest/none from 87.198.219.219: 5 Time(s)
   guest/password from 222.73.205.9: 4 Time(s)
   guest/password from 87.198.219.219: 5 Time(s)
   magnos/none from 87.198.219.219: 2 Time(s)
   magnos/password from 87.198.219.219: 2 Time(s)
   mysql001/none from 187.50.29.42: 5 Time(s)
   mysql001/password from 187.50.29.42: 5 Time(s)
   mysql01/none from 187.50.29.42: 5 Time(s)
   mysql01/password from 187.50.29.42: 5 Time(s)
   mysql02/none from 187.50.29.42: 5 Time(s)
   mysql02/password from 187.50.29.42: 5 Time(s)
   mysql03/none from 187.50.29.42: 5 Time(s)
   mysql03/password from 187.50.29.42: 5 Time(s)
   mysql1/none from 187.50.29.42: 3 Time(s)
   mysql1/password from 187.50.29.42: 3 Time(s)
   mysql10/none from 187.50.29.42: 4 Time(s)
   mysql10/password from 187.50.29.42: 4 Time(s)
   office/none from 93.65.200.63: 1 Time(s)
   office/password from 93.65.200.63: 1 Time(s)
   oracle/none from 93.65.200.63: 1 Time(s)
   oracle/password from 93.65.200.63: 1 Time(s)
   recruit/none from 93.65.200.63: 1 Time(s)
   recruit/password from 93.65.200.63: 1 Time(s)
   sales/none from 93.65.200.63: 1 Time(s)
   sales/password from 93.65.200.63: 1 Time(s)
   samba/none from 93.65.200.63: 1 Time(s)
   samba/password from 93.65.200.63: 1 Time(s)
   spam/none from 93.65.200.63: 1 Time(s)
   spam/password from 93.65.200.63: 1 Time(s)
   staff/none from 93.65.200.63: 1 Time(s)
   staff/password from 93.65.200.63: 1 Time(s)
   test/none from 222.73.205.9: 5 Time(s)
   test/none from 87.198.219.219: 5 Time(s)
   test/password from 222.73.205.9: 5 Time(s)
   test/password from 87.198.219.219: 5 Time(s)
   tomcat/none from 93.65.200.63: 1 Time(s)
   tomcat/password from 93.65.200.63: 1 Time(s)
   virus/none from 93.65.200.63: 1 Time(s)
   virus/password from 93.65.200.63: 1 Time(s)
   web/none from 187.50.29.42: 5 Time(s)
   web/password from 187.50.29.42: 5 Time(s)
   webadmin/none from 93.65.200.63: 1 Time(s)
   webadmin/password from 93.65.200.63: 1 Time(s)
   webmaster/none from 187.50.29.42: 5 Time(s)
   webmaster/none from 222.73.205.9: 1 Time(s)
   webmaster/password from 187.50.29.42: 5 Time(s)
   webmaster/password from 222.73.205.9: 1 Time(s)
   webmaster001/none from 187.50.29.42: 5 Time(s)
   webmaster001/password from 187.50.29.42: 5 Time(s)
   webmaster01/none from 187.50.29.42: 5 Time(s)
   webmaster01/password from 187.50.29.42: 5 Time(s)
   webmaster02/none from 187.50.29.42: 4 Time(s)
   webmaster02/password from 187.50.29.42: 4 Time(s)
   webmaster03/none from 187.50.29.42: 4 Time(s)
   webmaster03/password from 187.50.29.42: 4 Time(s)
   webmaster1/none from 187.50.29.42: 7 Time(s)
   webmaster1/password from 187.50.29.42: 7 Time(s)
   webmaster10/none from 187.50.29.42: 4 Time(s)
   webmaster10/password from 187.50.29.42: 4 Time(s)
   webmaster2/none from 187.50.29.42: 2 Time(s)
   webmaster2/password from 187.50.29.42: 2 Time(s)
   www/none from 187.50.29.42: 5 Time(s)
   www/password from 187.50.29.42: 5 Time(s)

User login attempt failed because:
   shell /sbin/nologin does not exist:
      alias : 1 Time(s)

**Unmatched Entries**
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER
error: Could not get shadow information for NOUSER

 ---------------------- SSHD End ------------------------- 


 --------------------- Syslogd Begin ------------------------ 


Syslogd started 1 Time(s)

 ---------------------- Syslogd End ------------------------- 


 --------------------- vpopmail Begin ------------------------ 


No Such User Found:
	cbird@ - 1 Time(s)

 ---------------------- vpopmail End ------------------------- 



------------------ Disk Space --------------------

/dev/hda3              72G   57G   12G  84% /
/dev/hda1              92M  6.3M   81M   8% /boot


 ###################### LogWatch End ######################### 



More information about the Sysadmin mailing list