BananaJoe
2005-02-13, 22:59:17
Guten Abend Forum,
hatten heute am Rechner das Problem das sich "Michael" nicht mehr einloggen konnte. (also über gdm). Hab dann das Passwort für ihn neu festgelegt und schon gings wieder.
Jetzt schau ich Spaßeshalber mal in den Logviewer und sehe folgendes:
Feb 13 17:06:32 localhost sshd[14658]: pam_succeed_if: requirement "uid < 100" not met by user "michael"
Feb 13 17:06:32 localhost sshd[14658]: Accepted password for michael from ::ffff:82.77.62.46 port 33822
Feb 13 19:19:04 localhost sshd[16659]: Did not receive identification string from ::ffff:213.186.61.81
Feb 13 19:22:12 localhost sshd[16701]: Illegal user jordan from ::ffff:213.186.61.81
Feb 13 19:22:15 localhost sshd[16701]: Failed password for illegal user jordan from ::ffff:213.186.61.81 port 4480 ssh2
Feb 13 19:22:18 localhost sshd[16704]: Failed password for michael from ::ffff:213.186.61.81 port 4604 ssh2
Feb 13 19:22:19 localhost sshd[16706]: Illegal user nicole from ::ffff:213.186.61.81
Feb 13 19:22:21 localhost sshd[16706]: Failed password for illegal user nicole from ::ffff:213.186.61.81 port 4747 ssh2
Feb 13 19:22:22 localhost sshd[16709]: Illegal user daniel from ::ffff:213.186.61.81
Feb 13 19:22:24 localhost sshd[16709]: Failed password for illegal user daniel from ::ffff:213.186.61.81 port 4873 ssh2
Feb 13 19:22:25 localhost sshd[16711]: Illegal user andrew from ::ffff:213.186.61.81
Feb 13 19:22:28 localhost sshd[16711]: Failed password for illegal user andrew from ::ffff:213.186.61.81 port 1131 ssh2
Feb 13 19:22:28 localhost sshd[16714]: Illegal user nathan from ::ffff:213.186.61.81
Feb 13 19:22:31 localhost sshd[16714]: Failed password for illegal user nathan from ::ffff:213.186.61.81 port 1274 ssh2
Feb 13 19:22:32 localhost sshd[16717]: Illegal user matthew from ::ffff:213.186.61.81
Feb 13 19:22:34 localhost sshd[16717]: Failed password for illegal user matthew from ::ffff:213.186.61.81 port 1410 ssh2
Feb 13 19:22:35 localhost sshd[16719]: Illegal user magic from ::ffff:213.186.61.81
Feb 13 19:22:37 localhost sshd[16719]: Failed password for illegal user magic from ::ffff:213.186.61.81 port 1568 ssh2
Feb 13 19:22:38 localhost sshd[16722]: Illegal user lion from ::ffff:213.186.61.81
Feb 13 19:22:40 localhost sshd[16722]: Failed password for illegal user lion from ::ffff:213.186.61.81 port 1708 s
etc..
Seh ich das richtig das da einer als Michael rein ist? PW war natürlich Michael :rolleyes:
Steh etwas aufn Schlauch, hab nen dicken Kopf. :D
Der 2. hatte ja weniger Glück wies scheint.
Wenn ja, was sollte ich alles auf veränderungen am Rechner prüfen? Verstecke Prozesse, etc?
Grüße
hatten heute am Rechner das Problem das sich "Michael" nicht mehr einloggen konnte. (also über gdm). Hab dann das Passwort für ihn neu festgelegt und schon gings wieder.
Jetzt schau ich Spaßeshalber mal in den Logviewer und sehe folgendes:
Feb 13 17:06:32 localhost sshd[14658]: pam_succeed_if: requirement "uid < 100" not met by user "michael"
Feb 13 17:06:32 localhost sshd[14658]: Accepted password for michael from ::ffff:82.77.62.46 port 33822
Feb 13 19:19:04 localhost sshd[16659]: Did not receive identification string from ::ffff:213.186.61.81
Feb 13 19:22:12 localhost sshd[16701]: Illegal user jordan from ::ffff:213.186.61.81
Feb 13 19:22:15 localhost sshd[16701]: Failed password for illegal user jordan from ::ffff:213.186.61.81 port 4480 ssh2
Feb 13 19:22:18 localhost sshd[16704]: Failed password for michael from ::ffff:213.186.61.81 port 4604 ssh2
Feb 13 19:22:19 localhost sshd[16706]: Illegal user nicole from ::ffff:213.186.61.81
Feb 13 19:22:21 localhost sshd[16706]: Failed password for illegal user nicole from ::ffff:213.186.61.81 port 4747 ssh2
Feb 13 19:22:22 localhost sshd[16709]: Illegal user daniel from ::ffff:213.186.61.81
Feb 13 19:22:24 localhost sshd[16709]: Failed password for illegal user daniel from ::ffff:213.186.61.81 port 4873 ssh2
Feb 13 19:22:25 localhost sshd[16711]: Illegal user andrew from ::ffff:213.186.61.81
Feb 13 19:22:28 localhost sshd[16711]: Failed password for illegal user andrew from ::ffff:213.186.61.81 port 1131 ssh2
Feb 13 19:22:28 localhost sshd[16714]: Illegal user nathan from ::ffff:213.186.61.81
Feb 13 19:22:31 localhost sshd[16714]: Failed password for illegal user nathan from ::ffff:213.186.61.81 port 1274 ssh2
Feb 13 19:22:32 localhost sshd[16717]: Illegal user matthew from ::ffff:213.186.61.81
Feb 13 19:22:34 localhost sshd[16717]: Failed password for illegal user matthew from ::ffff:213.186.61.81 port 1410 ssh2
Feb 13 19:22:35 localhost sshd[16719]: Illegal user magic from ::ffff:213.186.61.81
Feb 13 19:22:37 localhost sshd[16719]: Failed password for illegal user magic from ::ffff:213.186.61.81 port 1568 ssh2
Feb 13 19:22:38 localhost sshd[16722]: Illegal user lion from ::ffff:213.186.61.81
Feb 13 19:22:40 localhost sshd[16722]: Failed password for illegal user lion from ::ffff:213.186.61.81 port 1708 s
etc..
Seh ich das richtig das da einer als Michael rein ist? PW war natürlich Michael :rolleyes:
Steh etwas aufn Schlauch, hab nen dicken Kopf. :D
Der 2. hatte ja weniger Glück wies scheint.
Wenn ja, was sollte ich alles auf veränderungen am Rechner prüfen? Verstecke Prozesse, etc?
Grüße