ub newb
August 31st, 2008, 09:04 AM
Hi,
I tried to get help on the absolute beginners forum, so if this is a beginner question, I apologize. I haven't got an answer over there yet.
Please point me to an area that can help me decipher these auth log entries? xyzzz is my user name masked, and I was wondering why there would be any root activity on my account when I wasn't doin it around 2AM in the morning?
Aug 25 02:16:55 MDdesktop sudo: root : TTY=unknown ; PWD=/ ; USER=xyzzz ; COMMAND=/usr/bin/gconftool --get /system/http_proxy/use_http_proxy
Aug 25 02:16:55 MDdesktop sudo: pam_unix(sudo:session): session opened for user xyzzz by (uid=0)
Aug 25 02:16:55 MDdesktop sudo: pam_unix(sudo:session): session closed for user xyzzz
Aug 25 02:16:56 MDdesktop sudo: root : TTY=unknown ; PWD=/ ; USER=xyzzz ; COMMAND=/usr/bin/gconftool --get /system/http_proxy/host
Aug 25 02:16:56 MDdesktop sudo: pam_unix(sudo:session): session opened for user xyzzz by (uid=0)
Aug 25 02:16:56 MDdesktop sudo: pam_unix(sudo:session): session closed for user xyzzz
Aug 25 02:16:57 MDdesktop sudo: root : TTY=unknown ; PWD=/ ; USER=xyzzz ; COMMAND=/usr/bin/gconftool --get /system/http_proxy/port
Aug 25 02:16:57 MDdesktop sudo: pam_unix(sudo:session): session opened for user xyzzz by (uid=0)
Aug 25 02:16:57 MDdesktop sudo: pam_unix(sudo:session): session closed for user xyzzz
Thanks
I tried to get help on the absolute beginners forum, so if this is a beginner question, I apologize. I haven't got an answer over there yet.
Please point me to an area that can help me decipher these auth log entries? xyzzz is my user name masked, and I was wondering why there would be any root activity on my account when I wasn't doin it around 2AM in the morning?
Aug 25 02:16:55 MDdesktop sudo: root : TTY=unknown ; PWD=/ ; USER=xyzzz ; COMMAND=/usr/bin/gconftool --get /system/http_proxy/use_http_proxy
Aug 25 02:16:55 MDdesktop sudo: pam_unix(sudo:session): session opened for user xyzzz by (uid=0)
Aug 25 02:16:55 MDdesktop sudo: pam_unix(sudo:session): session closed for user xyzzz
Aug 25 02:16:56 MDdesktop sudo: root : TTY=unknown ; PWD=/ ; USER=xyzzz ; COMMAND=/usr/bin/gconftool --get /system/http_proxy/host
Aug 25 02:16:56 MDdesktop sudo: pam_unix(sudo:session): session opened for user xyzzz by (uid=0)
Aug 25 02:16:56 MDdesktop sudo: pam_unix(sudo:session): session closed for user xyzzz
Aug 25 02:16:57 MDdesktop sudo: root : TTY=unknown ; PWD=/ ; USER=xyzzz ; COMMAND=/usr/bin/gconftool --get /system/http_proxy/port
Aug 25 02:16:57 MDdesktop sudo: pam_unix(sudo:session): session opened for user xyzzz by (uid=0)
Aug 25 02:16:57 MDdesktop sudo: pam_unix(sudo:session): session closed for user xyzzz
Thanks