Re: Possible compromise ?

From: Patrick Muldoon (doon_at_inoc.net)
Date: 01/27/04

  • Next message: Eric Anderson: "Re: Possible compromise ?"
    To: "Peter Rosa" <prosa@pro.sk>, <freebsd-security@freebsd.org>
    Date: Tue, 27 Jan 2004 11:50:40 -0500
    
    

    On Tuesday 27 January 2004 11:44 am, Peter Rosa wrote:
    > Hello,

    > please, is there some way to list ALL users, who connect remotely to my
    > machine ? It is our gateway, so it should be one-user machine, but if I
    > list /var/log/lastlog binary file, there are some lines showing usage of
    > ttyp0. That console I have disabled in ttys, so why there are that lines ?
    > How could I make FreeBSD to show that file in readable way ?

    man last

     last -- indicate last logins of users and ttys

    >
    > Was my machine compromised ?

    Not enough information to make a educated guess here, sorry.

    -Patrick

    -- 
    Patrick Muldoon
    Network/Software Engineer
    INOC (http://www.inoc.net)
    PGPKEY (http://www.inoc.net/~doon)
    Key ID: 0x370D752C
    The computer is mightier than the pen, the sword, and usually, the programmer.
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Eric Anderson: "Re: Possible compromise ?"

    Relevant Pages

    • Possible compromise ?
      ... It is our gateway, so it should be one-user machine, but if I list ... /var/log/lastlog binary file, there are some lines showing usage of ttyp0. ... Peter Rosa ...
      (FreeBSD-Security)
    • Re: Possible compromise ?
      ... Peter Rosa wrote: ... It is our gateway, so it should be one-user machine, but if I list ... More information and a more clearly worded question would help. ... Eric Anderson Sr. ...
      (FreeBSD-Security)