From owner-freebsd-security@FreeBSD.ORG Tue Jan 27 08:52:08 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 6C81716A4CE for ; Tue, 27 Jan 2004 08:52:08 -0800 (PST) Received: from mx1-b.inoc.net (mx1-b.inoc.net [64.246.131.28]) by mx1.FreeBSD.org (Postfix) with ESMTP id 1317043D75 for ; Tue, 27 Jan 2004 08:52:07 -0800 (PST) (envelope-from doon@inoc.net) Received: from doon.ops.inoc.net (noc-gw0-fe.dc1-alb.inoc.net [64.246.129.30]) by mx1-b.inoc.net (build v4.0.9) with ESMTP id 5545211 for multiple; Tue, 27 Jan 2004 11:51:43 -0500 From: Patrick Muldoon Organization: INOC To: "Peter Rosa" , Date: Tue, 27 Jan 2004 11:50:40 -0500 User-Agent: KMail/1.5.4 References: <01a901c3e294$8ea8a500$3501a8c0@peter> <1653155537.20040126121155@b-o.ru> <003001c3e4f4$dbba7910$3501a8c0@peter> In-Reply-To: <003001c3e4f4$dbba7910$3501a8c0@peter> X-Powered-By: FreeBSD MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200401271150.40132.doon@inoc.net> Subject: Re: Possible compromise ? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 27 Jan 2004 16:52:08 -0000 On Tuesday 27 January 2004 11:44 am, Peter Rosa wrote: > Hello, > please, is there some way to list ALL users, who connect remotely to my > machine ? It is our gateway, so it should be one-user machine, but if I > list /var/log/lastlog binary file, there are some lines showing usage of > ttyp0. That console I have disabled in ttys, so why there are that lines ? > How could I make FreeBSD to show that file in readable way ? man last last -- indicate last logins of users and ttys > > Was my machine compromised ? Not enough information to make a educated guess here, sorry. -Patrick -- Patrick Muldoon Network/Software Engineer INOC (http://www.inoc.net) PGPKEY (http://www.inoc.net/~doon) Key ID: 0x370D752C The computer is mightier than the pen, the sword, and usually, the programmer.