LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-22-2008, 07:45 PM   #1
lastcall79
LQ Newbie
 
Registered: Aug 2008
Posts: 5

Rep: Reputation: 0
Logwatch explanations


Hi there Linux World
I would say that Im still junior level at the linux side. But i am using logwatch to run some reports on a couple of servers and I was wondering what this log information means if i can get some explanation that would be cool. Is it dangerous or not etc etc -

Attempts to use known hacks by 3 hosts were logged 3 time(s) from:
with 3 IPs

A total of 3 sites probed the server
with 3 ips

!!!! 3 possible successful probes
With link paths/querys with http errors at the end of them
http response 200

Just wondering what logwatch means when it says 3 possible successful probes - Does this mean their hacking my servers?

*Heads up*
There are more logwatch reports that I question but i want to start with these ones first. If anyone can help in explaining that would be great.

Thanks,
lastcall79
 
Old 10-26-2008, 05:42 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
All the report lines you posted should be accompanied by the IP addresses involved and clues in the sense of filters/paths Logwatch checks for (which you didn't post). "3 possible successful probes" means just that: a HTTP request for an existing (code 200) entity. The context, as in cracking or not, depends on what actually was requested (which you didn't post).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ssh connection; explanations, please? b0uncer Linux - Networking 7 05-12-2004 03:24 PM
Explanations for Networking and users permissions in Red Hat 9 marinovedder Linux - Networking 1 01-08-2004 06:44 PM
logwatch GraemeK Linux - Software 2 12-18-2003 08:32 PM
Possible explanations for error code 43 with efax jpfox Linux - Software 0 10-29-2003 09:13 AM
Sourceforge ranking explanations. liguorir Linux - Software 0 07-21-2003 09:32 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:06 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration