Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 15 Nov 2008 09:03:56 +0100 (CET)
From:      Wojciech Puchar <wojtek@wojtek.tensor.gdynia.pl>
To:        Lisa Casey <lisa@mail.jellico.com>
Cc:        freebsd-questions@freebsd.org
Subject:   Re: Question about entry in auth.log
Message-ID:  <20081115090330.U19870@wojtek.tensor.gdynia.pl>
In-Reply-To: <20081114215444.C8966@mail.jellico.com>
References:  <B8B09B39A8884900970CF2434D40F6C4@CaseyHome> <BAY122-DAV1214B45821956EB1D7B782BA110@phx.gbl> <692726B5-52B5-46AC-9C79-41553179AF36@comcast.net> <20081114215444.C8966@mail.jellico.com>

next in thread | previous in thread | raw e-mail | index | archive | help
> Very odd. Sigh, Michael is not vacationing in Romania. Doubt he's ever been 
> there. I got rid of the michael account (it wasn't used anyway), and 
> downloaded a new copy of chkrootkit, installed it and ran it along with 
> chklastlog and chkwtmp. Nothing was found. Pehaps this was a harmless enough 
> prank? Anything else I ought to look at? Fortunately the michael account did 
> not have te ability to su to root.
it doesn't matter if he/she had, if he/she don't know root password.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20081115090330.U19870>