LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-22-2005, 10:41 AM   #1
Chuck23
Member
 
Registered: Jun 2004
Distribution: Fedora Core1
Posts: 63

Rep: Reputation: 15
failed xscreensaver login when x down?


Noticed a couple of strange things this morning when i flipped on my monitor, and I wonder if anyone can help me sort them out.

First of all, at the runlevel 3 login prompt, instead of seeing my normal blank

hostname login:

I saw this:

hostname login: e100:eth0 NIC Link is Down
e100: eth0 NIC Link is Up (speed)
e100: eth0 NIC Link is Down
e100: eth0 NIC Link is Up (speed)

The link went down overnight as I slept (no time given in any log that I could find) and for some reason the information just output to the login prompt? Weird, but not terribly worrisome... yet.

So I ran rkhunter. Everything looked fine until this:

Checking loaded kernel mods Warning! (found difference in output)

I did add a module recently, so that probably explains that.

But then I checked my security log and saw the strangest thing ever:

xscreensaver FAILED LOGIN

at 2:32, when I was sound asleep and the machine was running at rl 3...

Anybody have any idea what the xscreensaver login attempt is all about?
 
Old 02-23-2005, 08:12 AM   #2
Chuck23
Member
 
Registered: Jun 2004
Distribution: Fedora Core1
Posts: 63

Original Poster
Rep: Reputation: 15
Nobody has any idea about this xscreensaver failed login? Now I'm getting a little worried.
 
Old 02-23-2005, 09:01 AM   #3
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Unless someone was able to establish a remote X session, then the failed xscreensaver login had to be local. Check the output of last -i for login times that occurred overnight. What does the rkhunter logfile show as the module discrepency?
 
Old 02-23-2005, 08:32 PM   #4
Chuck23
Member
 
Registered: Jun 2004
Distribution: Fedora Core1
Posts: 63

Original Poster
Rep: Reputation: 15
last -i doesn't show any unusual activity. rkhunter didn't give specific info about the mod, just that something had changed, and it probably had to do with some tinkering with mysql. When I ran rkhunter again today, it didn't show anything wrong. Pretty sure I inserted a new mod since last time I ran rkhunter. Not worried about it.

I don't think anybody could establish a remote xsession unless they could figure out a way to do it through... well, let's not give them any ideas.

But as long as we're on the subject of security. This morning at 4:17, I got an email from winvn@news.ksc.nasa.gov

Subject: Hello,info,japanese girl VS playboy

Message: Content-Type: application/octet-stream;
name=jill stack@fastclick[1].txt
Content-Transfer-Encoding: base64Content-ID: <ZwF6s9780575W39tY94>cGx1dG8KNzM2MzgzMzI4fDB8ZTE0YTI5MmEtM
Tg5NC00YTUzLWE2ZmEtOTliM2IyMjk1YmM3fApmYXN0Y2xpY2submV0Lw
oxMDI0CjM4OTcwNzIzODQKMjk4Mzg5MjEKNDA3NDg2NTgwOAoyOTcxMT
k3NwoqCj==

What the hell is that all about?
 
Old 02-23-2005, 09:47 PM   #5
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
I don't think anybody could establish a remote xsession unless they could figure out a way to do it through... well, let's not give them any ideas.
It's possible (but not likely) that someone could establish a remote desktop session by connecting to your local X server, but you should see a remote login. Plus if you are normally in runlevel three, then someone would first have to remotely log into the box using some other method, then fire up X and then establish the remote desktop session (all of which is pretty unlikely). What's odd is that a failed xscreensaver login should only be possible in a desktop session, but from everything you've described it doesn't seem possible. Might want to add an iptables rule logging any incoming or outgoing X traffic.

What the hell is that all about?
Given that all I get in my inbox anymore is pr0n spam or a virus, I'd say it's one of those (Actually it's klez).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
xscreensaver installed, but no xscreensaver-demo command? dalesan Linux - Software 7 09-01-2004 01:06 PM
Login Failed abulafiar Linux - General 3 08-15-2004 09:23 PM
Failed Login through SSH? Help PLEASE tangman Linux - Newbie 8 03-31-2004 03:02 PM
Login Failed gmiles Linux - Newbie 6 08-23-2002 03:16 PM
login failed! clodur Linux - Software 1 08-17-2001 03:37 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:37 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration