From owner-freebsd-security@FreeBSD.ORG Tue Jan 27 08:59:18 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id DC93716A4CE for ; Tue, 27 Jan 2004 08:59:18 -0800 (PST) Received: from corb.mc.mpls.visi.com (corb.mc.mpls.visi.com [208.42.156.1]) by mx1.FreeBSD.org (Postfix) with ESMTP id 998FA43D46 for ; Tue, 27 Jan 2004 08:58:57 -0800 (PST) (envelope-from hawkeyd@visi.com) Received: from sheol.localdomain (hawkeyd-fw.dsl.visi.com [208.42.101.193]) by corb.mc.mpls.visi.com (Postfix) with ESMTP id 714988990; Tue, 27 Jan 2004 10:57:42 -0600 (CST) Received: (from hawkeyd@localhost) by sheol.localdomain (8.11.6p2/8.11.6) id i0RGvfq01806; Tue, 27 Jan 2004 10:57:41 -0600 (CST) (envelope-from hawkeyd) X-Spam-Policy: http://www.visi.com/~hawkeyd/index.html#mail Date: Tue, 27 Jan 2004 10:57:41 -0600 From: D J Hawkey Jr To: Peter Rosa Message-ID: <20040127165741.GA1700@sheol.localdomain> References: <01a901c3e294$8ea8a500$3501a8c0@peter> <1653155537.20040126121155@b-o.ru> <003001c3e4f4$dbba7910$3501a8c0@peter> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <003001c3e4f4$dbba7910$3501a8c0@peter> User-Agent: Mutt/1.4.1i cc: security at FreeBSD Subject: Re: Possible compromise ? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: hawkeyd@visi.com List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 27 Jan 2004 16:59:19 -0000 On Jan 27, at 05:44 PM, Peter Rosa wrote: > > Hello, > > please, is there some way to list ALL users, who connect remotely to my > machine ? It is our gateway, so it should be one-user machine, but if I list > /var/log/lastlog binary file, there are some lines showing usage of ttyp0. `man lastlog` explains that file (and others), and the "SEE ALSO" section lists pertinent commands. > That console I have disabled in ttys, so why there are that lines ? How > could I make FreeBSD to show that file in readable way ? `man last`. > Was my machine compromised ? Not enough info to go on. `last` just may show the last time the admin was on tty0, disabling tty0. Dave -- ______________________ ______________________ \__________________ \ D. J. HAWKEY JR. / __________________/ \________________/\ hawkeyd@visi.com /\________________/ http://www.visi.com/~hawkeyd/