LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-06-2007, 06:12 PM   #1
budword
Member
 
Registered: Apr 2003
Location: Wisconsin
Distribution: Switched to regualr Ubuntu, because I don't like KDE4, at all. Looks like vista on crack.....
Posts: 675

Rep: Reputation: 31
Hacked ? Multiple who entries......


Hi, I don't know if this means anything or not, and goggling didn't help. Yesterday, while in kdm, waiting to choose a Desktop to login to, a box popped up saying something about my usual user already logged in (tty:3 or something like it.), which startled me a bit. When I had time (next morning) I did a quick who, and got multiple simultaneous log ins for the same user. Is this usual ? Here is the output of that command...

me :0 2007-09-06 09:52
me pts/0 2007-09-06 17:33 (:0.0)
me pts/1 2007-09-06 17:36 (:0.0)

This box was running overnight before I did the who command, so I didn't worry about the timestamps, but I haven't logged into any terminals.

So am I worried for nothing ? I finally have this box set up the way I want it, and I don't want to nuke it from orbit, I don't even want to upgrade when the next version of Kubuntu comes out. I'm running Kubuntu feisty, if it matters. I use kde, gnome, and fluxbox, though I doubt that matters much. One other detail, that I just thought was a KDE bug, if kde has been running for any length of time, I sometimes have trouble starting some new processes. Starting gaim or rox for instance. They just stop working, and I don't know why. I tried starting from a terminal hoping for an error message, but never get one. Same thing has never happened in gnome or fluxbox, so I just thought it was a kde bug or config problem, figured I screwed something up on my own.

I haven't found any funny processes running either, or weird bandwith issues.

Anyway, I'm hoping someone who knows much more than me will just pop on here for a minute and tell me I have nothing to worry about.

Thanks much...

David
 
Old 09-06-2007, 06:22 PM   #2
Simon Bridge
LQ Guru
 
Registered: Oct 2003
Location: Waiheke NZ
Distribution: Ubuntu
Posts: 9,211

Rep: Reputation: 198Reputation: 198
That's normal... it is saying that you have an x terminal (:0) open and two command-line terminals (pts/0 and pts/1) open. Each of these is a login. Enjoy.
 
Old 09-06-2007, 06:22 PM   #3
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
'w' may tell you a bit more. For example:

Code:
bash-3.1$ w 
19:20:17 up 14 days, 19:21,  6 users,  load average: 0.08, 0.29, 0.19
USER     TTY      FROM              LOGIN@   IDLE   JCPU   PCPU WHAT
ron      tty1     -                22Aug07 14days 25.34s  0.00s /bin/sh /usr/bin/startx
ron      pts/1    :0               23Aug07 14days  0.00s 44.20s kded [kdeinit] --new-startup                   
ron      pts/2    :0               Fri23    3days  0.26s  0.25s ssh ron@xx.xxx.xxx.xx -p 5001
ron      pts/4    :0               Sun23    0.00s  0.01s  0.00s w
ron      pts/0    :0               23Aug07 14days  8:21   0.00s bash
Also, try 'lsof'.

Last edited by unixfool; 09-06-2007 at 06:23 PM. Reason: forgot to add something
 
Old 09-06-2007, 06:38 PM   #4
budword
Member
 
Registered: Apr 2003
Location: Wisconsin
Distribution: Switched to regualr Ubuntu, because I don't like KDE4, at all. Looks like vista on crack.....
Posts: 675

Original Poster
Rep: Reputation: 31
Ahhhh I see. I feel very silly. Thanks much for putting my mind at ease. I've installed vmware and most of the vnc's and been messing around with some fun encryption stuff, and I was worried somewhere along the way I had exposed box in a stupid way. I just had a few konsoles open.

Thanks guys...

David
 
Old 09-06-2007, 06:49 PM   #5
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940
Yeah, this is based on the so-called utmp information which is not always entirely accurate anyway. (man utmp is rather interesting.)
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
gnucash: change multiple entries pixellany Linux - Software 0 05-25-2007 07:30 PM
Multiple entries in KDE menu roler SUSE / openSUSE 3 01-09-2007 01:30 PM
Apache entries - Hacked?? lawadm1 Linux - Security 2 11-27-2005 08:49 PM
Multiple same entries in volume controls or1onas Linux - Newbie 4 02-07-2005 12:21 PM
Trident Cyberblade - multiple X log entries. mcleodnine Linux - Hardware 1 04-17-2003 05:15 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:21 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration