From owner-freebsd-bugs@FreeBSD.ORG Sun May 16 23:00:42 2004 Return-Path: Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 0512516A4CF for ; Sun, 16 May 2004 23:00:42 -0700 (PDT) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 3A9C543D62 for ; Sun, 16 May 2004 23:00:40 -0700 (PDT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) i4H60evE015187 for ; Sun, 16 May 2004 23:00:40 -0700 (PDT) (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.12.11/8.12.11/Submit) id i4H60eCm015182; Sun, 16 May 2004 23:00:40 -0700 (PDT) (envelope-from gnats) Resent-Date: Sun, 16 May 2004 23:00:40 -0700 (PDT) Resent-Message-Id: <200405170600.i4H60eCm015182@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Mark Steven Baker Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 62FC516A4CE for ; Sun, 16 May 2004 22:53:47 -0700 (PDT) Received: from www.freebsd.org (www.freebsd.org [216.136.204.117]) by mx1.FreeBSD.org (Postfix) with ESMTP id E495843D2D for ; Sun, 16 May 2004 22:53:46 -0700 (PDT) (envelope-from nobody@FreeBSD.org) Received: from www.freebsd.org (localhost [127.0.0.1]) by www.freebsd.org (8.12.11/8.12.11) with ESMTP id i4H5rkTO066523 for ; Sun, 16 May 2004 22:53:46 -0700 (PDT) (envelope-from nobody@www.freebsd.org) Received: (from nobody@localhost) by www.freebsd.org (8.12.11/8.12.11/Submit) id i4H5rkCV066522; Sun, 16 May 2004 22:53:46 -0700 (PDT) (envelope-from nobody) Message-Id: <200405170553.i4H5rkCV066522@www.freebsd.org> Date: Sun, 16 May 2004 22:53:46 -0700 (PDT) From: Mark Steven Baker To: freebsd-gnats-submit@FreeBSD.org X-Send-Pr-Version: www-2.3 Subject: misc/66726: /etc/periodic/security/ 800.loginfail script reports failed logins from previous year X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 17 May 2004 06:00:42 -0000 >Number: 66726 >Category: misc >Synopsis: /etc/periodic/security/ 800.loginfail script reports failed logins from previous year >Confidential: no >Severity: non-critical >Priority: low >Responsible: freebsd-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Sun May 16 23:00:39 PDT 2004 >Closed-Date: >Last-Modified: >Originator: Mark Steven Baker >Release: 4.8 Release >Organization: >Environment: FreeBSD xxxxx 4.8-RELEASE FreeBSD 4.8-RELEASE >Description: The 800.loginfail script in /etc/periodic/security that normally runs via cron every night is supposed to report login failures from /var/log/auth.log for the previous day and email this to root as part of the daily security report. If a single auth.log file exists on a system with a year of syslog data, the current script will report failed login errors from the previous date one year earlier as well. >How-To-Repeat: Edit the /var/log/auth.log file, creating some bogus login failures for one year earlier than the previous day. Then manually run the /etc/periodic/security/800.loginfail script and see that these year-old login failures are reported. >Fix: I had some trouble understanding the catmsg function in 800.loginfail, so I can't suggest a fix. >Release-Note: >Audit-Trail: >Unformatted: