LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 03-14-2007, 11:54 AM   #1
ille.pugil42
Member
 
Registered: Dec 2005
Distribution: Slackware
Posts: 151

Rep: Reputation: 30
My Logfiles have inconsistent times and dates!


So, at first I thought the box was comprimised, but nothing has been changed. Looking at the logs I found the following:

Code:
Mar 13 19:02:46 mail2 sshd[1942]: Accepted publickey for root from XXX.XXX.XXX.XXX port 48404 ssh2
Mar 13 17:09:36 mail2 sshd[3519]: Accepted password for root from XXX.XXX.XXX.XXX port 61894 ssh2
Mar 14 00:09:36 mail2 sshd[3520]: Accepted password for root from XXX.XXX.XXX.XXX port 61894 ssh2
Mar 14 00:10:45 mail2 sshd[3554]: Accepted password for root from XXX.XXX.XXX.XXX port 54004 ssh2
Mar 13 17:10:45 mail2 sshd[3553]: Accepted password for root from XXX.XXX.XXX.XXX port 54004 ssh2
Having that many SSH's isn't abnormal, and the IP's are all internal and completely valid, but why does it go back and forth from Mar 13 to 14 and back? Its only on this system. I checked the time, date and DST settings, they're all nominal. The systems that we're logging in from remotely are also ok.

As I said prior, this caused me to think we'd been compromised, but I can't find any changes, rootkits, extra users, etc. Any ideas?
 
Old 03-14-2007, 12:00 PM   #2
b0uncer
LQ Guru
 
Registered: Aug 2003
Distribution: CentOS, OS X
Posts: 5,131

Rep: Reputation: Disabled
For a start I would make the wise thing: configure the ssh to prevent any root login attempts. There simply is no use or sane reason to accept root login trough SSH; one can use a regular account to log in and then use su or sudo to do the needed tasks, but it's definitely not wise to let root log in directly.

Can you repeat the date inconsistensy, or has it happened before, or is it just this one time?
 
Old 03-14-2007, 12:10 PM   #3
ille.pugil42
Member
 
Registered: Dec 2005
Distribution: Slackware
Posts: 151

Original Poster
Rep: Reputation: 30
Only since yesterday, so I'm thinking at this point its some sort of anomoly.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
packages by apt installed times and dates fakie_flip Linux - Software 2 10-05-2006 09:24 AM
Alter Times & Dates in Korganizer?? little_penguin Linux - Software 1 08-20-2006 09:29 PM
System hangs; Atheros Madwifi-ping times out every 15/16 times james 456 Linux - Networking 0 01-12-2006 06:55 PM
Logfiles wonderpun Linux - General 3 09-01-2002 03:27 AM
Dates and Times in MySQL oulevon General 2 09-13-2001 03:27 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 11:19 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration