LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-08-2011, 03:15 AM   #1
dmdickie
LQ Newbie
 
Registered: Nov 2011
Posts: 2

Rep: Reputation: Disabled
strange file contents in var/log/mail/statistics


hi .. i am a newbie .. 5 weeks into setting up and securing VPS
rhel centos 5.7 running plesk 9.5

file under scutiny is
/var/log/mail/statistics

ls -l gives
-rw------ 1 root root 1448 May 28 2010 statistics

if i do

[root@server mail]# cat statistics

i get

Þ±âCñK¨[root@centos-plesk mail]# PuTTY

Not sure what this means, if anything

why isn't [root...] on new line
why is PuTTy after #

i can delete PuTTy and use CLI after # as normal

i did a search for Þ±âCñK¨ and got some google hits for 'spambot killer'

nano statistics gives


ޱ^A^@^D^@^@^@�C�K^@^@^@^@�^E^@^@^@^@^@^@^C^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^ @^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^ @^@$


should i be worried at all

thanks for looking
richard
 
Old 11-08-2011, 07:23 AM   #2
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
Here might be a good place to start. It offers one explanation, at least: http://linux.die.net/man/8/mailstats The file /var/log/mail/statistics is normally the statistics file for sendmail. The Unix and by extension, Linux philosophy is that data should be textual when possible and binary formats should be avoided, but this isn't always adhered to. The data you have displayed looks like binary data with some blank fields to me. Machine code would be binary by its nature, but the file is not executable, which says that it is not this. Unless you have other evidence of a compromised system, this alone doesn't appear to be a problem. To confirm that it is a statistics file, I would try to read it with the utility mentioned in the link.

My guess is that the PuTTY is a reference to the Putty SSH or telnet client. Looking at the line, it appears that you may be logging in as root remotely. This is not a good practice. Instead, log in via a normal user account and then elevate to root, or better yet use SUDO, for the operations required.

Last edited by Noway2; 11-08-2011 at 07:23 AM. Reason: typo
 
Old 11-08-2011, 12:17 PM   #3
dmdickie
LQ Newbie
 
Registered: Nov 2011
Posts: 2

Original Poster
Rep: Reputation: Disabled
thanks very much noway2 for your reply

i tried
mailstat /var/log/mail/statistics and it gave me ->

Total Number Folder
----- ------ ------
0 1 ## Þ±âCñK¨
----- ------
0 1

I'm afraid it doesn't mean much to me!

i disabled PermitRootLogin and login as another user
then do sudo su - to give me root priviledges .. not sure if i am doing that the right way

I still don't understand why PuTTy text would come out of nowhere though ..

thanks again for your time to reply and suggestions
richard

ps to all .. i meant scrutiny not scutiny .. serves me right for trying to use a 'big' word eh
bloomin newbies
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[Perl] Idea on statistics for duplication file contents Kunsheng Linux - Software 1 10-24-2009 02:40 AM
[Perl] Idea on statistics for duplication file contents Kunsheng Programming 2 10-23-2009 11:42 PM
My /var/log/ directory contents dissapeared! guarriman Linux - Security 3 01-05-2008 01:01 PM
Strange results in /var/log/apache/access.log subt13 Linux - Security 2 08-03-2004 01:21 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:07 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration