LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-27-2004, 12:08 AM   #1
Invaderzim2004
LQ Newbie
 
Registered: Sep 2004
Posts: 5

Rep: Reputation: 0
Last -i shows an unknown ip


My last -i shows a weired ip for when i log on with a user account:

<user shown here> :0 20.127.3.64 Sun Sep 26 20:52 - down (00:00)

I dont know what the ip 20.127.3.64 is from, it shows it on almost all of my user logins, but not from root logins to vc/1 just to my user logins to :0 which i started froma root shell in vc/1.

If someone can tell me if this is normall, it would really help me out, thanks
 
Old 09-27-2004, 12:10 AM   #2
Invaderzim2004
LQ Newbie
 
Registered: Sep 2004
Posts: 5

Original Poster
Rep: Reputation: 0
PS What i do is log into vc/1 with root then do a telinit 5 to get to X and then login with my user, is this a bad thing to do, is it safe?
 
Old 09-27-2004, 12:20 AM   #3
Bruce Hill
HCL Maintainer
 
Registered: Jun 2003
Location: McCalla, AL, USA
Distribution: Arch, Gentoo
Posts: 6,940

Rep: Reputation: 129Reputation: 129
I can't tell you about the login to vc/1, but I can show you how to find an IP

Code:
mingdao@james:~$ whois 20.127.3.64

OrgName:    Computer Sciences Corporation
OrgID:      CSC-68
Address:    3170 Fairview Park Drive
City:       Falls Church
StateProv:  VA
PostalCode: 22042
Country:    US

NetRange:   20.0.0.0 - 20.255.255.255
CIDR:       20.0.0.0/8
NetName:    CSC
NetHandle:  NET-20-0-0-0-1
Parent:
NetType:    Direct Assignment
NameServer: NS1.CSC.COM
NameServer: NS2.CSC.COM
Comment:
RegDate:    1989-09-04
Updated:    2002-05-31

TechHandle: PG618-ARIN
TechName:   Gross, Pete
TechPhone:  +1-703-641-3322
TechEmail:  pgross@csc.com

OrgAbuseHandle: PG618-ARIN
OrgAbuseName:   Gross, Pete
OrgAbusePhone:  +1-703-641-3322
OrgAbuseEmail:  pgross@csc.com

OrgTechHandle: PG618-ARIN
OrgTechName:   Gross, Pete
OrgTechPhone:  +1-703-641-3322
OrgTechEmail:  pgross@csc.com

# ARIN WHOIS database, last updated 2004-09-26 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
 
Old 09-27-2004, 12:47 AM   #4
Invaderzim2004
LQ Newbie
 
Registered: Sep 2004
Posts: 5

Original Poster
Rep: Reputation: 0
How is it that it shows me logging in from that address when i log in from my home desktop computer?
 
Old 09-27-2004, 12:54 AM   #5
Invaderzim2004
LQ Newbie
 
Registered: Sep 2004
Posts: 5

Original Poster
Rep: Reputation: 0
BTW, im using Mandrake Linux 10.
 
Old 09-27-2004, 01:54 AM   #6
Bruce Hill
HCL Maintainer
 
Registered: Jun 2003
Location: McCalla, AL, USA
Distribution: Arch, Gentoo
Posts: 6,940

Rep: Reputation: 129Reputation: 129
Quote:
Originally posted by Invaderzim2004
How is it that it shows me logging in from that address when i log in from my home desktop computer?
Sorry, I already told you
Quote:
Originally posted by Chinaman
I can't tell you about the login to vc/1, but I can show you how to find an IP
What is vc? If that means virtual console, you could start by issuing and reading "man console"

And instead of having to say, "btw I'm using <distribution>" just put it in your LQ UserCP
 
Old 09-27-2004, 04:38 AM   #7
qwijibow
LQ Guru
 
Registered: Apr 2003
Location: nottingham england
Distribution: Gentoo
Posts: 2,672

Rep: Reputation: 47
are you definatly sure this is NOT the ip or your ISP ?
if not, some1 is logging into your machine.

change your passwords weekly test your system for root kits, and resrtict the ip addressed from which can loggin via ssh with iptables.
 
Old 09-27-2004, 08:24 AM   #8
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
I think you're seeeing this bug:

http://bugs.mandrakelinux.com/query.php?bug=532
 
Old 09-27-2004, 07:32 PM   #9
Invaderzim2004
LQ Newbie
 
Registered: Sep 2004
Posts: 5

Original Poster
Rep: Reputation: 0
Thank you Capt_Caveman, that really explains alot.
 
Old 09-29-2004, 10:47 AM   #10
linuxboy69
Member
 
Registered: Oct 2003
Distribution: Redhat 9
Posts: 138

Rep: Reputation: 15
I had the exact same problem and it turned out to be just a bug.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
9.3- yast online update shows 'unknown' for product and version prkix SUSE / openSUSE 2 11-12-2005 03:54 PM
ls pci shows "Subsystem: Intel Corp.: Unknown device 1011" hugle Linux - Software 0 07-10-2004 02:11 AM
snmp staus shows it running but on trying MRTG, it shows public@ipaddr not giving res swati220781 Linux - Networking 3 07-08-2004 05:32 PM
Who shows old logins mcq Debian 1 07-06-2004 10:17 AM
desktop shows on TV but movie shows black screen litrelord Mandriva 6 07-05-2004 05:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:42 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration