LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-05-2003, 07:25 PM   #16
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69

Wow, that is pretty strange. It sounds more like a bug than anything else. I double checked the bugzilla database and there is a bug reported, but it is associated with the last -i command. Try that and if you see that same ip address, it's the same bug (in SysVinit). Bet you went WTF when you saw that entry even with it not connected to anything. I think this is the bug (I believe the same one adme pointed out) in case your interested.

https://bugzilla.redhat.com/bugzilla...g.cgi?id=82540
 
Old 07-06-2003, 07:26 AM   #17
adme
Member
 
Registered: Jan 2003
Distribution: Redhat Psyche, Redhat Shrike, Solaris 9
Posts: 51

Original Poster
Rep: Reputation: 15
make a bug report @ bugzilla.redhat.com

i am sure, this is a bug. Please send me the link

kind regards

adme
 
Old 07-06-2003, 07:10 PM   #18
fanton
LQ Newbie
 
Registered: Jul 2003
Posts: 6

Rep: Reputation: 0
Now it's a bug

Ok, so I've confirmed the tests in other machines and the problem is reproductible. It's now officialy a bug...

It's reported in Bugzilla #98659 and is probably related to the one reported under #82540 as noticed by Capt. Caveman. (Thanks!)

https://bugzilla.redhat.com/bugzilla...g.cgi?id=98659

Thank you too adme!

Ufff... I fell reliefed now that I know that my system was not invaded!

Last edited by fanton; 07-06-2003 at 07:15 PM.
 
Old 07-18-2003, 12:30 PM   #19
jonathon
LQ Newbie
 
Registered: Jul 2001
Location: Sydney
Distribution: Yellow Dog
Posts: 11

Rep: Reputation: 0
hello fanton.
You might be interested to see the output for utmpdump /var/log/wtmp | grep 127 on my machine... note my "rogue" ip number is 127 not 128 as with your machine.
Code:
# utmpdump /var/log/wtmp | grep 127
Utmp dump of /var/log/wtmp
[7] [01129] [:0 ] [jonathon] [:0 ] [ ] [127.255.248.88 ] [Mon Jul 14 03:14:07 2003 EST]
[8] [00000] [:0 ] [        ] [:0 ] [ ] [127.255.248.40 ] [Mon Jul 14 09:22:39 2003 EST]
[7] [01078] [:0 ] [jonathon] [:0 ] [ ] [127.255.248.88 ] [Mon Jul 14 11:42:00 2003 EST]
[8] [00000] [:0 ] [        ] [:0 ] [ ] [127.255.248.40 ] [Mon Jul 14 18:31:36 2003 EST]
[7] [07521] [:0 ] [suzanne ] [:0 ] [ ] [127.255.248.88 ] [Mon Jul 14 18:32:06 2003 EST]
[8] [00000] [:0 ] [        ] [:0 ] [ ] [127.255.248.40 ] [Mon Jul 14 19:22:17 2003 EST]
[7] [12822] [:0 ] [jonathon] [:0 ] [ ] [127.255.248.88 ] [Tue Jul 15 00:21:02 2003 EST]
[8] [00000] [:0 ] [        ] [:0 ] [ ] [127.255.248.40 ] [Tue Jul 15 16:46:38 2003 EST]
[7] [00936] [:0 ] [jonathon] [:0 ] [ ] [127.255.248.88 ] [Wed Jul 16 16:51:58 2003 EST]
[8] [00000] [:0 ] [        ] [:0 ] [ ] [127.255.248.40 ] [Wed Jul 16 20:25:43 2003 EST]
[7] [00933] [:0 ] [jonathon] [:0 ] [ ] [127.255.248.88 ] [Thu Jul 17 01:43:09 2003 EST]
[8] [00000] [:0 ] [        ] [:0 ] [ ] [127.255.248.40 ] [Thu Jul 17 03:14:07 2003 EST]
[7] [00951] [:0 ] [jonathon] [:0 ] [ ] [127.255.248.88 ] [Thu Jul 17 12:46:02 2003 EST]
[8] [00000] [:0 ] [        ] [:0 ] [ ] [127.255.248.40 ] [Thu Jul 17 15:01:24 2003 EST]
[7] [01050] [:0 ] [jonathon] [:0 ] [ ] [127.255.248.88 ] [Thu Jul 17 18:55:55 2003 EST]
[8] [00000] [:0 ] [        ] [:0 ] [ ] [127.255.248.40 ] [Thu Jul 17 23:41:14 2003 EST]
[7] [04860] [:0 ] [jonathon] [:0 ] [ ] [127.255.248.88 ] [Thu Jul 17 23:41:27 2003 EST]
[8] [00000] [:0 ] [        ] [:0 ] [ ] [127.255.248.40 ] [Fri Jul 18 15:03:58 2003 EST]
[7] [00953] [:0 ] [jonathon] [:0 ] [ ] [127.255.248.88 ] [Fri Jul 18 22:59:27 2003 EST]
The pattern is similar.. same (almost) logins on [7] and [8] lines and from terminal :0

step 2 in your instructions at bugzilla is -
2. look at wtmp using 'utmdump /var/log/wtmp | grep 128.99
This is not necessarily so.. the number on my machine is 127... not 128.... maybe you should revise your bugzilla submission?

I'm using yellowdog (3.0) on ppc with dialup connection.. doesn't seem to matter if I'm connected or not, still get the logins.
 
Old 07-18-2003, 02:46 PM   #20
fanton
LQ Newbie
 
Registered: Jul 2003
Posts: 6

Rep: Reputation: 0
Hi, Jonathon

Thanks for your note. I've already updated the bugzilla submission (although no one seems to have looked at it yet!).

The problem seems to happen once at every boot. You may check if it's what happens in your case too.
 
Old 07-19-2003, 12:37 PM   #21
Robert0380
LQ Guru
 
Registered: Apr 2002
Location: Atlanta
Distribution: Gentoo
Posts: 1,280

Rep: Reputation: 47
[post deleted, contained no useful info]

Last edited by Robert0380; 07-19-2003 at 12:41 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
cracked or not cracked (tripwire & chrootkit) ddaas Linux - Security 1 04-27-2005 07:29 AM
Possible Cracked.... Aeiri Linux - Security 4 02-22-2005 08:15 AM
Does this mean I have been cracked? BajaNick Linux - Security 4 08-13-2004 10:10 PM
This just cracked me up! CragStar General 2 04-19-2002 11:13 PM
!!! THEMES.ORG gets cracked... rabidundead Linux - General 0 06-10-2001 03:03 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:56 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration