Re: Daily security report oddity...

2009-09-02 Thread Kurt Buff
On Wed, Sep 2, 2009 at 10:03, Dan Nelson wrote: > In the last episode (Sep 02), Kurt Buff said: >> Heh. Well, for me a very long time is more than a year, because >> security patches for the OS will at some point mandate a reboot - and >> usually in less than a year. >> >> I suppose there's a way

Re: Daily security report oddity...

2009-09-02 Thread Dan Nelson
In the last episode (Sep 02), Kurt Buff said: > On Wed, Sep 2, 2009 at 00:23, Mark Stapper wrote: > > Kurt Buff wrote: > >> I traced it down, and found out that he had not logged in on Sunday. > >> The auth.log is, as you can see from the listing below, quite old. The > >> entries referenced above

Re: Daily security report oddity...

2009-09-02 Thread Kurt Buff
On Wed, Sep 2, 2009 at 00:23, Mark Stapper wrote: > Kurt Buff wrote: >> I got a daily security run email from one of my machines on Monday >> morning, with the following entry: >> >>      zmx1.zetron.com login failures: >>      Aug 30 06:57:17 zmx1 su: BAD SU mlee to root on /dev/ttyp2 >>      Aug

Re: Daily security report oddity...

2009-09-02 Thread Mark Stapper
Kurt Buff wrote: > I got a daily security run email from one of my machines on Monday > morning, with the following entry: > > zmx1.zetron.com login failures: > Aug 30 06:57:17 zmx1 su: BAD SU mlee to root on /dev/ttyp2 > Aug 30 09:42:17 zmx1 su: BAD SU mlee to root on /dev/ttyp0 > >

Daily security report oddity...

2009-09-01 Thread Kurt Buff
I got a daily security run email from one of my machines on Monday morning, with the following entry: zmx1.zetron.com login failures: Aug 30 06:57:17 zmx1 su: BAD SU mlee to root on /dev/ttyp2 Aug 30 09:42:17 zmx1 su: BAD SU mlee to root on /dev/ttyp0 What's puzzling is that this a