LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices



Reply
 
Search this Thread
Old 01-20-2005, 08:46 AM   #1
raymond117
LQ Newbie
 
Registered: Jan 2005
Posts: 5

Rep: Reputation: 0
Error log in /var/log/messages


Hi all. Need your help .. thx.

I am using Redhat 9 2.4.26

I found the following logs in /var/log/messages these days... (occurs 3~4 times this week.. no other log is found in the same time as these log:

kernel: NET: 1 messages suppressed.
kernel: NET: 2 messages suppressed.
kernel: NET: 1 messages suppressed.
kernel: NET: 6 messages suppressed.
kernel: NET: 1 messages suppressed.
kernel: NET: 2 messages suppressed.


Anyone knows what are they ?
Any bad impact to my linux box?
what should I do ??

Thanks !!
 
Old 01-21-2005, 10:24 AM   #2
wimdh
LQ Newbie
 
Registered: Aug 2004
Location: Dendermonde, Belgium
Distribution: Ubuntu latest
Posts: 28

Rep: Reputation: 15
Can you launch ethereal or tcpdump.
you can match the timestamps and see what's going on..
 
Old 01-21-2005, 10:43 AM   #3
raymond117
LQ Newbie
 
Registered: Jan 2005
Posts: 5

Original Poster
Rep: Reputation: 0
thx...

but... how to post it out ???
 
Old 01-21-2005, 10:53 AM   #4
wimdh
LQ Newbie
 
Registered: Aug 2004
Location: Dendermonde, Belgium
Distribution: Ubuntu latest
Posts: 28

Rep: Reputation: 15
Installing iptables and log all packets is also an option...
Then you'll have to see where they come from..

success
 
Old 01-21-2005, 11:13 AM   #5
raymond117
LQ Newbie
 
Registered: Jan 2005
Posts: 5

Original Poster
Rep: Reputation: 0
sorry , I am new to Linux..

any command / any specific files I can try to see ?



Thx for your kind help !
 
Old 01-22-2005, 05:47 AM   #6
vhh
LQ Newbie
 
Registered: Jan 2005
Posts: 11

Rep: Reputation: 0
Hello,

I got an other problem in the log file /var/log/message which I don't understand what it is.
------------------------------
Jan 19 09:32:15 myhost userhelper: pam_timestamp: `/' permissions are lax
------------------------------

I tried: #ls -ld /

It returned: drwxrwx--x 20 root root 4096 Jan 12 12:51

What's happend? And How do I do now?

Thank you,
 
Old 01-24-2005, 06:02 AM   #7
wimdh
LQ Newbie
 
Registered: Aug 2004
Location: Dendermonde, Belgium
Distribution: Ubuntu latest
Posts: 28

Rep: Reputation: 15
Hey Raymond,

http://www.linuxmigration.com/quickr.../ethereal.html

is a good startingpoint :-)

Success
 
Old 01-24-2005, 06:06 AM   #8
wimdh
LQ Newbie
 
Registered: Aug 2004
Location: Dendermonde, Belgium
Distribution: Ubuntu latest
Posts: 28

Rep: Reputation: 15
Hey vhh

your root dir seems to be group writable.
do a:

Code:
chmod g-w /
success
 
Old 01-26-2005, 07:56 AM   #9
vhh
LQ Newbie
 
Registered: Jan 2005
Posts: 11

Rep: Reputation: 0
Thanks wimdh! I've done it already.

Why did it show me the notice under username "userhelper"? Did someone hack at me?

Anyway, thank you.
 
Old 01-26-2005, 08:17 AM   #10
wimdh
LQ Newbie
 
Registered: Aug 2004
Location: Dendermonde, Belgium
Distribution: Ubuntu latest
Posts: 28

Rep: Reputation: 15
Hi vhh

userhelper is a part of PAM
try man userhelper.
PAM reported the error when someone autenticated I think...
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Deleted /var/log/messages, can't log any files-iptables chingyenccy Linux - Newbie 7 02-27-2005 05:03 PM
How to log conversation between server in /var/log/messages? juris Linux - Software 1 11-23-2004 10:54 AM
Error /var/log/messages arthur_NGIT Linux - Software 0 05-26-2004 05:15 PM
iptables, changing log file from /var/log/messages acid2000 Linux - Networking 3 03-11-2003 09:38 PM
Error in /var/log/messages pk21 Linux - General 4 10-25-2002 08:34 AM


All times are GMT -5. The time now is 03:12 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration