Hi,

ich schau grade in /var/log/auth.log

Und sehe da nur von gestern und heute 4MB Eintäge in unten zu sehender
Art. Gehe ich da recht in der Annahme das da versucht wurde mein
RootPasswort zu "erraten"?

Anfang des Logs:
Feb 20 06:29:01 vs2801 CRON[25586]: pam_unix(cron:session): session
closed for user root
Feb 20 06:39:03 vs2801 CRON[7151]: pam_unix(cron:session): session
opened for user root by (uid=0)
Feb 20 06:39:05 vs2801 CRON[7151]: pam_unix(cron:session): session
closed for user root
Feb 20 06:47:01 vs2801 CRON[30980]: pam_unix(cron:session): session
opened for user root by (uid=0)
Feb 20 06:48:46 vs2801 CRON[30980]: pam_unix(cron:session): session
closed for user root
Feb 20 06:51:38 vs2801 saslauthd[11067]: do_request      : NULL password
received
Feb 20 06:51:43 vs2801 saslauthd[11066]: do_request      : NULL password
received
Feb 20 06:51:49 vs2801 saslauthd[11068]: pam_unix(smtp:auth): check
pass; user unknown
Feb 20 06:51:49 vs2801 saslauthd[11068]: pam_unix(smtp:auth):
authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=
Feb 20 06:51:51 vs2801 saslauthd[11068]: DEBUG: auth_pam:
pam_authenticate failed: User not known to the underlying authentication
module
Feb 20 06:51:51 vs2801 saslauthd[11068]: do_auth         : auth failure:
[user=inna] [service=smtp] [realm=] [mech=pam] [reason=PAM auth error]
Feb 20 06:51:55 vs2801 saslauthd[11066]: pam_unix(smtp:auth): check
pass; user unknown
Feb 20 06:51:55 vs2801 saslauthd[11066]: pam_unix(smtp:auth):
authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=
Feb 20 06:51:57 vs2801 saslauthd[11066]: DEBUG: auth_pam:
pam_authenticate failed: User not known to the underlying authentication
module


Ende des Logs:
Feb 20 21:11:12 vs2801 saslauthd[11066]: pam_unix(smtp:auth): check
pass; user unknown
Feb 20 21:11:12 vs2801 saslauthd[11066]: pam_unix(smtp:auth):
authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=
Feb 20 21:11:14 vs2801 saslauthd[11066]: DEBUG: auth_pam:
pam_authenticate failed: User not known to the underlying authentication
module
Feb 20 21:11:14 vs2801 saslauthd[11066]: do_auth         : auth failure:
[user=1234] [service=smtp] [realm=] [mech=pam] [reason=PAM auth error]
Feb 20 21:11:16 vs2801 saslauthd[11064]: pam_unix(smtp:auth): check
pass; user unknown
Feb 20 21:11:16 vs2801 saslauthd[11064]: pam_unix(smtp:auth):
authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=
Feb 20 21:11:18 vs2801 saslauthd[11064]: DEBUG: auth_pam:
pam_authenticate failed: User not known to the underlying authentication
module
Feb 20 21:11:18 vs2801 saslauthd[11064]: do_auth         : auth failure:
[user=1234] [service=smtp] [realm=] [mech=pam] [reason=PAM auth error]
Feb 20 21:17:01 vs2801 CRON[14556]: pam_unix(cron:session): session
opened for user root by (uid=0)
Feb 20 21:17:01 vs2801 CRON[14556]: pam_unix(cron:session): session
closed for user root
Feb 20 21:39:01 vs2801 CRON[11345]: pam_unix(cron:session): session
opened for user root by (uid=0)
Feb 20 21:39:01 vs2801 CRON[11345]: pam_unix(cron:session): session
closed for user root
Feb 20 22:09:01 vs2801 CRON[10759]: pam_unix(cron:session): session
opened for user root by (uid=0)
Feb 20 22:09:01 vs2801 CRON[10759]: pam_unix(cron:session): session
closed for user root

Viele Grüße und schönen Wochenstart,
Rob

_______________________________________________
Lug-dd maillist  -  Lug-dd@mailman.schlittermann.de
https://ssl.schlittermann.de/mailman/listinfo/lug-dd

Antwort per Email an