From owner-freebsd-security@FreeBSD.ORG Thu Jun 16 13:24:33 2005 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 76A6416A41C for ; Thu, 16 Jun 2005 13:24:33 +0000 (GMT) (envelope-from root@Neo-Vortex.net) Received: from Neo-Vortex.net (203-206-17-78.dyn.iinet.net.au [203.206.17.78]) by mx1.FreeBSD.org (Postfix) with ESMTP id CC98E43D55 for ; Thu, 16 Jun 2005 13:24:32 +0000 (GMT) (envelope-from root@Neo-Vortex.net) Received: from localhost.Neo-Vortex.net (Neo-Vortex@localhost.Neo-Vortex.net [127.0.0.1]) by Neo-Vortex.net (8.13.1/8.12.10) with ESMTP id j5GDOUIn026897; Thu, 16 Jun 2005 23:24:30 +1000 (EST) (envelope-from root@Neo-Vortex.net) Date: Thu, 16 Jun 2005 23:24:30 +1000 (EST) From: Neo-Vortex To: Saurabh Bhasin In-Reply-To: Message-ID: <20050616232236.A26561@Neo-Vortex.net> References: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=ISO-8859-1 Content-Transfer-Encoding: QUOTED-PRINTABLE Cc: freebsd-security@freebsd.org Subject: Re: last command - strange entries? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 16 Jun 2005 13:24:33 -0000 On Wed, 15 Jun 2005, Saurabh Bhasin wrote: > Greetings, > > I am seeing strange entries when i perform "last -20" for example. > Here's a sample output becuase I can not seem to make any sense out of > this in the last two days and can't find any information online. Any > help is appreciated. > > 0 F=3D=B0Bttyp Wed Dec 31 16:00 still l= ogged in > 0 6=DB=AFBttyp Wed Dec 31 16:00 still l= ogged in > 0 m=DA=AFBttyp Wed Dec 31 16:00 still l= ogged in > 7 m=DA=AFBttyv Wed Dec 31 16:00 still l= ogged in > 0 =AFBttyp Wed Dec 31 16:00 still logge= d in > 0 (o=AFBttyp Wed Dec 31 16:00 still log= ged in > 2 =EBg=AFBttyp Wed Dec 31 16:00 still l= ogged in > . > > and it keeps going for 20 lines. The last command uses /var/log/wtmp and /var/log/utmp (mabe even /var/log/lastlog) - anyway, the point is, it uses those files to get the information, now, it appears as if they have become corrupt, mabe by userland/kernel land desynch? bad upgrade? tried a reboot? Else, can you give us more details about the system, past upgrades, intrusions? ~NVX