'su by nobody' - should I be worried?
From: Matthijs (vanaalten_at_hotmail.com)
Date: 03/30/04
- Previous message: Albert Dengg: "Re: "EMU10K1/Audigy soundcard not found or device busy""
- Next in thread: Martin Dickopp: "Re: 'su by nobody' - should I be worried?"
- Reply: Martin Dickopp: "Re: 'su by nobody' - should I be worried?"
- Reply: p: "Re: 'su by nobody' - should I be worried?"
- Reply: Bill Thompson: "Re: 'su by nobody' - should I be worried?"
- Reply: p: "Re: 'su by nobody' - should I be worried?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Date: Tue, 30 Mar 2004 22:55:29 +0200 To: debian-user@lists.debian.org
Since a few days, Logcheck reports a lot of messages like this:
---------------------------------------------------------------------
Security Violations for su
=-=-=-=-=-=-=-=-=-=-=-=-=-
Mar 30 06:25:02 MyMail su[13083]: (pam_unix) session opened for user
nobody by (uid=0)
---------------------------------------------------------------------
I've had similar messages for various users for cron and sshd.
Should I be worried? The only way I can read this messages is that
user 'nobody' has done a 'su' - become root. I don't know what the
'pam_unix' part means.
So: does this mean my server has been compromised?
If not, what does it mean?
If so, how? How can I find the hole - or should I re-install
everything?
Thanks,
-- Matthijs vanaalten@hotmail.com -- To UNSUBSCRIBE, email to debian-user-request@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
- Previous message: Albert Dengg: "Re: "EMU10K1/Audigy soundcard not found or device busy""
- Next in thread: Martin Dickopp: "Re: 'su by nobody' - should I be worried?"
- Reply: Martin Dickopp: "Re: 'su by nobody' - should I be worried?"
- Reply: p: "Re: 'su by nobody' - should I be worried?"
- Reply: Bill Thompson: "Re: 'su by nobody' - should I be worried?"
- Reply: p: "Re: 'su by nobody' - should I be worried?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]