LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-07-2012, 07:43 PM   #1
urandom23242
LQ Newbie
 
Registered: Sep 2012
Posts: 3

Rep: Reputation: Disabled
su - not working, worked after reboot


Hello,


Usually login via user, and 'su -' to root, cut and past password via ssh in terminal.

Login via user worked ok. I then typed su - and got password failure. I can't remember changing anything since about 30 minutes earlier when I su and password accepted.

auth log:



Sep time xxx sshd[18993]: Accepted publickey for xxx from X.X.X.X port xxx ssh2
Sep time xxx sshd[18993]: pam_unix(sshd:session): session opened for user xxx by (uid=0)
Sep time xxx su[19027]: pam_unix(su:auth): authentication failure; logname=xxx uid=1000 euid=0 tty=/dev/pts/0 ruser=xxx rhost= user=root
Sep time xxx su[19027]: pam_authenticate: Authentication failure
Sep time xxx su[19027]: FAILED su for root by xxx
Sep time xxx su[19027]: - /dev/pts/0 xxx:root
Sep time xxx su[19029]: pam_unix(su:auth): authentication failure; logname=xxx uid=1000 euid=0 tty=/dev/pts/0 ruser=xxx rhost= user=root
Sep time xxx su[19029]: pam_authenticate: Authentication failure
Sep time xxx su[19029]: FAILED su for root by xxx
Sep time xxx su[19029]: - /dev/pts/0 xxx:root
Sep time xxx su[19033]: pam_unix(su:auth): authentication failure; logname=xxx uid=1000 euid=0 tty=/dev/pts/0 ruser=xxx rhost= user=root
Sep time xxx su[19033]: pam_authenticate: Authentication failure

Attempting root login via ssh password:

Sep time xxx sshd[19038]: SSH: Server;Ltype: Version;Remote: X.X.X.X-xxx;Protocol: 2.0;Client: OpenSSH_5.9p1 Debian-3
Sep time xxx sshd[19038]: SSH: Server;Ltype: Kex;Remote: X.X.X.X-xxx;Enc: aes128-ctr;MAC: hmac-md5;Comp: none [preauth]
Sep time xxx sshd[19038]: SSH: Server;Ltype: Authname;Remote: X.X.X.X-xxx;Name: root [preauth]
Sep time xxx sshd[19038]: Postponed keyboard-interactive for root from X.X.X.X port xxx ssh2 [preauth]
Sep time xxx sshd[19040]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=X.X.X.X user=root
Sep time xxx sshd[19038]: error: PAM: Authentication failure for root from X.X.X.X.
Sep time xxx sshd[19038]: Postponed keyboard-interactive for root from X.X.X.X port xxx ssh2 [preauth]
Sep time xxx sshd[19041]: pam_unix(sshd:auth): conversation failed
Sep time xxx sshd[19041]: pam_unix(sshd:auth): auth could not identify password for [root]
Sep time xxx sshd[19041]: error: ssh_msg_send: write


Then, I rebooted, and I then did ssh again, and su password was accepted as normal.
------------
/etc/pam.d/su
#%PAM-1.0

auth sufficient pam_rootok.so
suauth.allow

suauth.nopass


auth required pam_wheel.so use_uid

auth include system-auth

account include system-auth

password include system-auth

session include system-auth
session required pam_env.so
session optional pam_xauth.so
------------

I also have someone nonestop hitting my port 8118 eventhough it is set to deny in firewall...blowing my kern log to 600MB and counting...
Sep 8 00:38:19 xxx kernel: [ 1580.964432] RULE 9 -- DENY IN=eth0 OUT= MAC=xxx SRC=99.58.56.225 DST=X.X.X.X LEN=380 TOS=0x00 PREC=0x00 TTL=43 ID=0 DF PROTO=UDP SPT=2643 DPT=8118 LEN=360
SRC=173.254.197.26
SRC=50.93.203.216
SRC=50.93.200.96
SRC=173.254.197.248
It is coming from numerous other ips
All the ips hitting my port 8118.

spoofed ips?

Only thing I can think of is someone changed the password, and changed it back right before or right after I rebooted? Unless I have a momentary fluck with my clipboard on the client machine?

So the question basically is, is there any reason why su would apparently stop working, and then start working again after a reboot and not changing anything?

My other question is I just noticed,"aes128-ctr", shouldn't I be using at least aes256?

Reinstall?

Thanks.

Last edited by urandom23242; 09-07-2012 at 07:50 PM.
 
Old 09-07-2012, 09:22 PM   #2
urandom23242
LQ Newbie
 
Registered: Sep 2012
Posts: 3

Original Poster
Rep: Reputation: Disabled
still happening

I just logged in again and experiencing the same problem. I cannot su to root.
 
Old 09-07-2012, 11:18 PM   #3
urandom23242
LQ Newbie
 
Registered: Sep 2012
Posts: 3

Original Poster
Rep: Reputation: Disabled
Red face

Hey. I think this issues is closed as a root level access...it happened again and I had to change the password from CD, nogo on console or ssh. server back up and running fine...

What would have been the motive of the attacker? The server is all public content...therefore, why not just hide in the background, why obvious and change the password? I am stumped.

Last edited by urandom23242; 09-08-2012 at 12:53 AM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Errors at login, always worked fine macking Linux - Newbie 7 10-28-2010 04:07 PM
serial console - working, then "stuck" output and can't login srfeo Linux - General 0 03-29-2007 04:45 AM
Only 1 of my ip's are working. It worked before the server went down. What can I do?! CrewXp Linux - Networking 3 02-06-2006 06:20 PM
kybd input suddenly not working after login; OK if 'startx' from console OpenMacNews SUSE / openSUSE 7 02-10-2005 12:41 PM
Mouse not working (worked during installation) Dark-Light Linux - Newbie 7 06-17-2002 05:07 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:13 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration