LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-25-2006, 11:10 AM   #1
xtremeclones
Member
 
Registered: Jan 2006
Posts: 70

Rep: Reputation: 15
Log question


Hey guys,

Im getting these on my /var/log/messages running on SUSE 10.0

Oct 25 05:30:13 xxx su: (to nobody) root on none
Oct 25 05:30:13 xxx su: (to nobody) root on none
Oct 25 05:30:13 xxx su: (to nobody) root on none
Oct 25 05:30:13 xxx su: (to nobody) root on none
Oct 25 05:30:14 xxx su: (to nobody) root on none
Oct 25 05:30:14 xxx su: (to nobody) root on none
Oct 25 05:30:14 xxx su: (to nobody) root on none

Im the only one who is supposed to have access to the system.

Does this mean someone might have gotten in?

THanks for the help.
 
Old 10-25-2006, 01:00 PM   #2
jayjwa
Member
 
Registered: Jul 2003
Location: NY
Distribution: Slackware, Termux
Posts: 787

Rep: Reputation: 250Reputation: 250Reputation: 250
There's several "su"'s out there, but yours looks like it reports both source and target user. If they start at 'root', and are dropping down to 'nobody', I'd say it was more like a script running that needed to drop root privs before running. I had an IRC server that had to be run as a normal user, yet the script to control it was root-only. I used to su down to nobody as a solution before I changed to my current setup.

Try grepping thru some system start scripts and see if you see it: fgrep 'su nobody' /etc/rc.d/rc.* (or where ever you keep your startup and rc scripts). At 5:30 a.m., that might be a cron job running.

You need to worry when you see user "nobody" trying for user "root".


PS: Is your hostname/domainname set correctly?
 
Old 10-25-2006, 04:11 PM   #3
xtremeclones
Member
 
Registered: Jan 2006
Posts: 70

Original Poster
Rep: Reputation: 15
OK,

i didnt find any under root, so i guess its ok.

If you're talking about the hostname = XXX i changed that to hide it.
Thanks for the awesome advice.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Opennms Logs - where are web.log, web_rtc.log and webauth.log referenced? not_much_of_a_guru Linux - Networking 0 07-12-2006 10:28 AM
Log File Question windisch Linux - General 6 06-15-2006 07:00 AM
Log file question InJesus Linux - General 1 11-09-2005 10:36 AM
Log in/out question Dralnu SUSE / openSUSE 2 08-12-2005 07:39 PM
Question 1 Firewall Log Question 2 Network Monitor Soulful93 Linux - Networking 4 08-04-2004 11:05 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:06 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration