Hi,

On Fri, Aug 21, 2009 at 6:54 AM, Uwe Dippel<udip...@uniten.edu.my> wrote:
> Yes. Like
> Accepted password for isuser from XXX.XX.XX.XX port 61802 ssh2
>
> To be clear, the user exists, and logged on the last time three days ago as
> far as 'last' is concerned.

This sounds very fishy. I would start backing up if I were you.

You said first that last says the user had not logged on, but now that
it has 3 days ago? Is the user covering up his/her traces or was that
a typo?

See what the user is doing and what is in his/her home directory. Try
to find information about the machine which it is coming from.

Change the root password and re-mount important partitions read-only
until you find what this is all about?

Good luck. And report back what it was. I would be interested to know.

-- 
Best Regards

Edd Barrett
(Freelance software developer / technical writer / open-source developer)

http://students.dec.bournemouth.ac.uk/ebarrett

Reply via email to