From owner-freebsd-security@FreeBSD.ORG Tue Jan 27 12:45:35 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E249C16A4CE for ; Tue, 27 Jan 2004 12:45:35 -0800 (PST) Received: from ns.pro.sk (proxy.pro.sk [212.55.244.46]) by mx1.FreeBSD.org (Postfix) with ESMTP id 2AB8543D6A for ; Tue, 27 Jan 2004 12:44:57 -0800 (PST) (envelope-from prosa@pro.sk) Received: from peter (Peter [192.168.1.53]) by ns.pro.sk (8.12.9/8.12.9) with SMTP id i0RKiBrp010245 for ; Tue, 27 Jan 2004 21:44:11 +0100 (CET) (envelope-from prosa@pro.sk) Message-ID: <00c401c3e516$4f1bf7a0$3501a8c0@peter> From: "Peter Rosa" To: "security at FreeBSD" References: <01a901c3e294$8ea8a500$3501a8c0@peter><1653155537.20040126121155@b-o.ru> <003001c3e4f4$dbba7910$3501a8c0@peter> <20040127165741.GA1700@sheol.localdomain> <002801c3e513$774a4040$3501a8c0@peter> <4016CAE5.6080808@centtech.com> Date: Tue, 27 Jan 2004 21:44:07 +0100 MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_NextPart_000_00C1_01C3E51E.B0D207C0" X-Priority: 1 X-MSMail-Priority: High X-Mailer: Microsoft Outlook Express 6.00.2800.1158 X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2800.1165 X-RAVMilter-Version: 8.4.3(snapshot 20030217) (ns.pro.sk) Subject: Re: Possible compromise ? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 27 Jan 2004 20:45:36 -0000 This is a multi-part message in MIME format. ------=_NextPart_000_00C1_01C3E51E.B0D207C0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit As Mr. Anderson wrote, I tried last -f /var/log/lastlog and get, what is in attachment. Unreadable chaos, bad dates. May be, lastlog has not exact structure for last, isn't it ? PR ------=_NextPart_000_00C1_01C3E51E.B0D207C0 Content-Type: text/plain; name="lastlog.txt" Content-Transfer-Encoding: quoted-printable Content-Disposition: attachment; filename="lastlog.txt" ttyp2 067.mbne Thu Jan 1 01:00 - 08:08 = (9012+06:08)=0A= =11m=15@ttyv0 Thu Jan 1 01:00 still = logged in=0A= 0 h=F6&=3Dttyp 160- Thu Jan 1 01:00 still = logged in=0A= 0 d=B6=D1?ttyv Thu Jan 1 01:00 still = logged in=0A= =0A= wtmp begins Thu Jan 1 01:00:00 CET 1970=0A= ------=_NextPart_000_00C1_01C3E51E.B0D207C0--