logwatch and ssh, not recognizing entries correctly

From: B Wooster (bwooster47_at_gmail.com)
Date: 04/02/05

  • Next message: Craig White: "Re: console package manager for FC3 ?"
    Date: Sat, 2 Apr 2005 16:55:51 -0500
    To: For users of Fedora Core releases <fedora-list@redhat.com>
    
    

    So I get daily reports from logwatch, but am having trouble figuring
    out why logwatch reports all the sshd lines as "Unmatched Entries".
    So, I get thousands of lines in the email that are unrecognized. But
    related entries seem to be matched correctly by pam_unix.

    Is the logwatch sshd script out of date in Fedora FC3 and does not
    match the openssh output?

    Here are the unmatched entries examples:
    User nobody not allowed because not listed in AllowUsers
    Failed password for invalid user nobody from 216.17.211.26 port 53321 ssh2
    Invalid user patrick from 216.17.211.26
    Failed password for invalid user patrick from 216.17.211.26 port 53259 ssh2
    Invalid user patrick from 216.17.211.26
    Failed password for invalid user patrick from 216.17.211.26 port 60961 ssh2
    User root not allowed because not listed in AllowUsers
    .....

    sshd version is:
    OpenSSH_3.9p1, OpenSSL 0.9.7a Feb 19 2003
    .....
    Using latest Fedora: 2.6.10-1.770_FC3
    ....

    Looking at /etc/log.d/scripts/services/sshd, I notice that it is not
    looking for above lines, but is instead looking for "Failed ... login"
    instead of "Invalid user".
    Also: the pam_unix logwatch script is working - but seems to me all
    that info will be duplicate of what the sshd script would print out,
    not sure if this how the normal setup is.

    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: Craig White: "Re: console package manager for FC3 ?"

    Relevant Pages

    • Re: Securing my Linux-pc? Worried....hacked?
      ... Subject: LogWatch for localhost.localdomain ... Connections: ... Starting sshd: ... rejecting connections on daemon MTA: load average: 14 ...
      (comp.os.linux.security)
    • Re: logwatch - need latest version, remove from yum?
      ... Invalid user admin from 10.114.109.221 ... User mysql not allowed because not listed in AllowUsers ... All these lines went away when I upgraded to logwatch 7.1, ... > daily logwatch email in the sshd section. ...
      (Fedora)
    • Re: sshd activity .. what does it mean
      ... "Harry Putnam" wrote in message ... > I recieved this notice from an application called logwatch: ... You should only panic if your sshd is not the most recent version. ... use hotmail com for any email replies ...
      (comp.os.linux.security)