From owner-freebsd-stable@FreeBSD.ORG Tue Jul 1 11:56:34 2003 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 0CD8B37B401 for ; Tue, 1 Jul 2003 11:56:34 -0700 (PDT) Received: from blue.icn.pl (blue.icn.pl [212.182.96.243]) by mx1.FreeBSD.org (Postfix) with SMTP id 0146744053 for ; Tue, 1 Jul 2003 11:56:32 -0700 (PDT) (envelope-from n0n4m3@icn.pl) Received: (qmail 17183 invoked by uid 66); 1 Jul 2003 18:56:31 -0000 Received: from blue.icn.pl(212.182.96.243) via SMTP by blue.icn.pl, id smtpd2y7oiw; Tue Jul 1 20:56:30 2003 Date: Tue, 1 Jul 2003 20:56:30 +0200 (CEST) From: n0n4m3 To: Sergei Vyshenski In-Reply-To: <5.1.1.6.2.20030701150100.00a74aa0@vivaldi.pn.sinp.msu.ru> Message-ID: <20030701205618.Y16933@blue.icn.pl> References: <5.1.1.6.2.20030701150100.00a74aa0@vivaldi.pn.sinp.msu.ru> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII cc: freebsd-stable@freebsd.org Subject: Re: possible intrusion? X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 01 Jul 2003 18:56:34 -0000 whats this ? On Tue, 1 Jul 2003, Sergei Vyshenski wrote: > Today discovered the following in /var/log: > > -rw-r--r-- 1 root wheel 176 Jul 1 14:37 wtmp > -rw-r--r-- 1 root wheel 0 Jul 1 05:20 wtmp.0 > -rw-r--r-- 1 root wheel 0 Jul 1 05:00 wtmp.1 > -rw-r--r-- 1 root wheel 20460 Jul 1 00:19 wtmp.2 > -rw-r--r-- 1 root wheel 0 Jun 1 05:20 wtmp.3 > > While file /etc/newsyslog says: > > /var/log/wtmp root.wheel 644 3 * @01T05 B > > The system is 4.8-STABLE FreeBSD 4.8-STABLE #0: Tue Jun 17 22:09:23 MSD 2003 > > Could this mean the sign of intrusion? > > Thank you very much for any comment ahead of time, > Sergei > > _______________________________________________ > freebsd-stable@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-stable > To unsubscribe, send any mail to "freebsd-stable-unsubscribe@freebsd.org" >