Has anything strange been happening in testing/woody's logging facilities lately?
In the last week, one of my machines has two days where the archived syslog is completely empty (not even a "--MARK--") and this morning I found a warning that auth.log was smaller than it had been the last time it was checked. I'm inclined to think that someone managed to break into this system, but first I want to check on whether there are any alternate explanations which won't require me to wipe the drive and reinstall. -- Linux will do for applications what the Internet did for networks. - IBM, "Peace, Love, and Linux" Geek Code 3.1: GCS d? s+: a- C++ UL++$ P++>+++ L+++>++++ E- W--(++) N+ o+ !K w---$ O M- V? PS+ PE Y+ PGP t 5++ X+ R++ tv b+ DI++++ D G e* h+ r y+