Re: who added the new user pcap?

From: Bill Unruh (unruh_at_string.physics.ubc.ca)
Date: 06/14/04


Date: Mon, 14 Jun 2004 15:23:32 +0000 (UTC)

lsun91125@yahoo.com (Lu) writes:

]Hi,

]I have a redhat 9 box. Logwatch reported the following:

] --------------------- Connections (secure-log) Begin
]------------------------
]New Users:
] pcap(77)

]**Unmatched Entries**
]groupadd[2380]: new group: name=pcap, gid=77
]usermod[2964]: change user `gdm' shell from `/sbin/nologin' to
]`/sbin/nologin'
] ---------------------- Connections (secure-log) End

]I don't know the exact time it happened. But prior to this, within 24
]hours, I also got something from my yum.cron:
]Stopping sshd:[ OK ]
]Starting sshd:[ OK ]
]warning: /etc/mail/sendmail.cf created as /etc/mail/sendmail.cf.rpmnew
]warning: /etc/mail/submit.cf created as /etc/mail/submit.cf.rpmnew

]I also noticed that the machine was rebooted before these two reports.

]Do these mean a security comprimise? What should I do to track it down
]and prevent it?

]Thanks a lot!

It looks like ssh, sendmail were updated with rpm. Were they? Did you do
it?

If you did not do it, find out what or who did.



Relevant Pages

  • Re: xinetd high cpu usage
    ... Does anyone have any idea why xinetd would take 98% on a Redhat 8, ... with only sshd and sendmail installed on it.It is a PIII 800 Mhz, ...
    (linux.redhat)
  • Re: how to install rpm form installation disk
    ... On Wed, 2003-12-31 at 18:00, Jianping Zhu wrote: ... > I have redhat 9.0. ... i found sshd is not working properly. ... > reinstall it from the original installation disk? ...
    (RedHat)
  • Re: OpenSSH upgrade
    ... > I just upgraded OpenSSH to my Redhat 6.2 system and as a result, ... > when I restarted ssh: ... > Shutting down sshd: ...
    (comp.os.linux.security)
  • Re: OpenSSH upgrade
    ... > I just upgraded OpenSSH to my Redhat 6.2 system and as a result, ... > Shutting down sshd: ... > Privilege separation user sshd does not exist ... > I read somewhere that I need to create the user sshd so I did. ...
    (comp.os.linux.security)
  • Re: IP Firewalling by DNS name
    ... How safe is it? ... As I understand it, sshd actually accepts connections ... prior to checking hosts.allow? ... there's an example for sshd but it contains: ...
    (freebsd-stable)

Quantcast