Re: suspicious cron log entry



Sylvain Robitaille <syl@xxxxxxxxxxxxxxxxxx> writes:

Randy Yates wrote:

Aug 25 22:55:39 localhost /usr/bin/crontab[1763]: (root) LIST (nobody)

Is this normal? If so, can someone please explain who/what is
doing this? If not, any suggestions on a course of action?

I should say that "doing this" means "crontab -l". Or am I
wrong?

Yes, it looks like someone, acting as root typed "crontab -l nobody".
Whether that's "normal" in your situation is not something others can
determine for you (are you the only one with legitimate "root" access
on this system?), but it certainly would be "normal" on systems I
manage, especially for "software accounts" that do have cron jobs, where
I might want to check details.

I hope that helps ...

Hi Sylvain,

Thanks for your response. I don't mean to be thick, but I still don't
really see what the bottom line is. I am the only human that should
have root access to my computer. Are there programs or cron jobs that
might do this sort of thing automatically? If so, how do you check?

If not, then please clarify that this is indeed an indication of a
break-in.
--
% Randy Yates % "So now it's getting late,
%% Fuquay-Varina, NC % and those who hesitate
%%% 919-577-9882 % got no one..."
%%%% <yates@xxxxxxxx> % 'Waterfall', *Face The Music*, ELO
http://home.earthlink.net/~yatescr
.



Relevant Pages

  • Re: root | su
    ... him why what he's doing is improper or foolish, or simply pull his root ... If this is a work-related incident, talk to your boss ... complete tool -- imagine Dilbert's boss with basic UNIX CLI and "how to ... didn't have root access to determine what the problem was, ...
    (freebsd-questions)
  • Re: Emergency! please help with file system access issue
    ... My friend was a security expert so I am sure ... > you now have root access and can change the password. ... Some systems are configured to ask for root password if you type "linux 1". ...
    (comp.os.linux.security)
  • Re: Choosing a distribution
    ... 'sudo bash' where I haven't had a proper root account to work with. ... cracked and hence give the intruder root access. ...
    (Ubuntu)
  • RE: [SLE] root access to user
    ... Can I pick on one thing about giving root access to users. ... the user will be prompted for the root password. ... You can do all this in Samba, but unless you are using at least one of ...
    (SuSE)
  • Re: Insidious Spam/swen/Garbage
    ... > Monique Y. Hermanis reported to have said: ... >> you are the only person with root access, ... anyone with root access could view your password. ... Well, I don't use dialup, so it's not a problem. ...
    (Debian-User)