Hi, On Fri, Aug 21, 2009 at 6:54 AM, Uwe Dippel<udip...@uniten.edu.my> wrote: > Yes. Like > Accepted password for isuser from XXX.XX.XX.XX port 61802 ssh2 > > To be clear, the user exists, and logged on the last time three days ago as > far as 'last' is concerned.
This sounds very fishy. I would start backing up if I were you. You said first that last says the user had not logged on, but now that it has 3 days ago? Is the user covering up his/her traces or was that a typo? See what the user is doing and what is in his/her home directory. Try to find information about the machine which it is coming from. Change the root password and re-mount important partitions read-only until you find what this is all about? Good luck. And report back what it was. I would be interested to know. -- Best Regards Edd Barrett (Freelance software developer / technical writer / open-source developer) http://students.dec.bournemouth.ac.uk/ebarrett