Originally Posted by
cariboo907
btmp a log file that contains all the last bad login attempts. More info is available by running man lastb.
Code:
logan@logan-laptop:~$ lastb
UNKNOWN tty1 Fri Nov 27 02:50 - 02:50 (00:00)
btmp begins Fri Nov 27 02:50:33 2009
logan@logan-laptop:~$
firewall + messages
http://img513.imageshack.us/img513/8...eenshot2tv.png
These are all the logins from nov. 21st to now.
Code:
logan@logan-laptop:~$ last
logan pts/1 :0.0 Fri Nov 27 18:15 still logged in
logan pts/0 :0.0 Fri Nov 27 18:12 still logged in
logan pts/0 :0.0 Fri Nov 27 17:10 - 17:50 (00:40)
logan pts/0 :0.0 Fri Nov 27 05:45 - 06:48 (01:02)
logan pts/0 :0.0 Fri Nov 27 04:23 - 04:23 (00:00)
logan pts/0 :0.0 Fri Nov 27 04:12 - 04:20 (00:08)
logan pts/0 :0.0 Fri Nov 27 04:09 - 04:09 (00:00)
logan pts/0 :0.0 Fri Nov 27 02:58 - 02:58 (00:00)
logan tty7 :0 Fri Nov 27 02:53 still logged in
reboot system boot 2.6.31-15-generi Fri Nov 27 02:53 - 18:21 (15:28)
logan tty1 Fri Nov 27 02:50 - down (00:01)
logan tty1 Fri Nov 27 02:50 - 02:50 (00:00)
logan pts/0 :0.0 Fri Nov 27 02:43 - down (00:08)
logan pts/2 :0.0 Fri Nov 27 02:35 - 02:40 (00:05)
logan tty7 :0 Fri Nov 27 02:18 - down (00:33)
reboot system boot 2.6.31-15-generi Fri Nov 27 02:18 - 02:51 (00:33)
logan pts/0 :0.0 Fri Nov 27 02:08 - 02:15 (00:07)
logan pts/0 :0.0 Fri Nov 27 00:53 - 00:57 (00:04)
logan pts/0 :0.0 Thu Nov 26 22:17 - 22:19 (00:01)
logan pts/0 :0.0 Thu Nov 26 20:34 - 20:36 (00:01)
logan pts/0 :0.0 Thu Nov 26 20:28 - 20:33 (00:04)
logan pts/0 :0.0 Thu Nov 26 20:20 - 20:26 (00:05)
logan tty7 :0 Thu Nov 26 19:56 - down (06:21)
reboot system boot 2.6.31-15-generi Thu Nov 26 19:56 - 02:17 (06:21)
logan pts/0 :0.0 Thu Nov 26 19:10 - 19:12 (00:01)
logan tty7 :0 Thu Nov 26 18:55 - 19:24 (00:29)
reboot system boot 2.6.31-15-generi Thu Nov 26 18:55 - 19:24 (00:29)
logan tty7 :0 Thu Nov 26 14:49 - crash (04:05)
reboot system boot 2.6.31-15-generi Thu Nov 26 14:49 - 19:24 (04:35)
logan tty7 :0 Wed Nov 25 19:05 - 14:22 (19:16)
reboot system boot 2.6.31-15-generi Wed Nov 25 19:05 - 14:22 (19:17)
logan pts/0 :0.0 Tue Nov 24 19:18 - 19:19 (00:01)
logan pts/1 :0.0 Tue Nov 24 19:01 - 19:02 (00:01)
logan pts/0 :0.0 Tue Nov 24 18:58 - 19:01 (00:02)
logan tty7 :0 Tue Nov 24 18:52 - down (14:54)
reboot system boot 2.6.31-15-generi Tue Nov 24 18:52 - 09:46 (14:54)
logan pts/0 :0.0 Tue Nov 24 03:00 - 03:00 (00:00)
logan tty7 :0 Tue Nov 24 02:54 - down (05:38)
reboot system boot 2.6.31-15-generi Tue Nov 24 02:54 - 08:33 (05:38)
logan tty7 :0 Tue Nov 24 02:45 - down (00:07)
reboot system boot 2.6.31-15-generi Tue Nov 24 02:45 - 02:53 (00:07)
logan pts/0 :0.0 Tue Nov 24 01:41 - 01:41 (00:00)
logan tty7 :0 Mon Nov 23 21:03 - down (05:41)
reboot system boot 2.6.31-15-generi Mon Nov 23 21:02 - 02:44 (05:41)
logan tty7 :0 Mon Nov 23 06:10 - down (00:03)
reboot system boot 2.6.31-15-generi Mon Nov 23 06:10 - 06:13 (00:03)
logan tty7 :0 Mon Nov 23 05:30 - 05:36 (00:05)
reboot system boot 2.6.31-15-generi Mon Nov 23 05:30 - 05:36 (00:05)
logan pts/0 :0.0 Mon Nov 23 02:04 - 02:07 (00:02)
logan tty7 :0 Mon Nov 23 01:25 - down (01:49)
reboot system boot 2.6.31-15-generi Mon Nov 23 01:25 - 03:15 (01:49)
logan tty7 :0 Mon Nov 23 00:39 - crash (00:45)
reboot system boot 2.6.31-15-generi Mon Nov 23 00:39 - 03:15 (02:35)
logan pts/0 :0.0 Mon Nov 23 00:37 - crash (00:01)
logan tty7 :0 Mon Nov 23 00:05 - crash (00:33)
reboot system boot 2.6.31-15-generi Mon Nov 23 00:05 - 03:15 (03:09)
logan tty7 :0 Sun Nov 22 22:52 - down (01:12)
reboot system boot 2.6.31-15-generi Sun Nov 22 22:52 - 00:05 (01:12)
logan pts/1 :0.0 Sun Nov 22 22:45 - 22:48 (00:02)
logan pts/0 :0.0 Sun Nov 22 22:25 - 22:51 (00:25)
logan pts/0 :0.0 Sun Nov 22 22:24 - 22:24 (00:00)
logan pts/0 :0.0 Sun Nov 22 17:37 - 18:29 (00:51)
logan pts/0 :0.0 Sun Nov 22 17:26 - 17:27 (00:00)
logan tty7 :0 Sun Nov 22 17:25 - down (05:25)
reboot system boot 2.6.31-15-generi Sun Nov 22 17:25 - 22:51 (05:25)
logan pts/0 :0.0 Sun Nov 22 17:22 - 17:23 (00:01)
logan pts/0 :0.0 Sun Nov 22 16:51 - 16:51 (00:00)
logan tty7 :0 Sun Nov 22 16:09 - down (01:15)
reboot system boot 2.6.31-15-generi Sun Nov 22 16:08 - 17:24 (01:16)
logan pts/2 :0.0 Sun Nov 22 15:51 - 15:51 (00:00)
logan pts/0 :0.0 Sun Nov 22 15:51 - down (00:16)
logan pts/0 :0.0 Sat Nov 21 18:03 - 18:39 (00:35)
logan tty7 :0 Sat Nov 21 17:59 - down (22:07)
reboot system boot 2.6.31-15-generi Sat Nov 21 17:59 - 16:07 (22:08)
logan tty7 :0 Sat Nov 21 17:07 - down (00:51)
reboot system boot 2.6.31-14-generi Sat Nov 21 17:07 - 17:58 (00:51)
logan tty7 :0 Sat Nov 21 12:11 - crash (04:56)
reboot system boot 2.6.31-14-generi Sat Nov 21 12:11 - 17:58 (05:47)
logan tty7 :0 Sat Nov 21 01:20 - down (02:39)
reboot system boot 2.6.31-14-generi Sat Nov 21 01:20 - 04:00 (02:40)
I'm also beginning to get red messages in the firewall from blocked connections. Service is Telnet. ??
http://img522.imageshack.us/img522/7...eenshot3rq.png
and im getting these in my auth:
Code:
Nov 27 11:17:01 logan-laptop CRON[5542]: pam_unix(cron:session): session opened for user root by (uid=0)
Nov 27 11:17:01 logan-laptop CRON[5542]: pam_unix(cron:session): session closed for user root
Nov 27 12:17:01 logan-laptop CRON[5553]: pam_unix(cron:session): session opened for user root by (uid=0)
Nov 27 12:17:01 logan-laptop CRON[5553]: pam_unix(cron:session): session closed for user root
Nov 27 13:17:01 logan-laptop CRON[5570]: pam_unix(cron:session): session opened for user root by (uid=0)
Nov 27 13:17:01 logan-laptop CRON[5570]: pam_unix(cron:session): session closed for user root
Nov 27 14:17:01 logan-laptop CRON[5583]: pam_unix(cron:session): session opened for user root by (uid=0)
Nov 27 14:17:01 logan-laptop CRON[5583]: pam_unix(cron:session): session closed for user root
Nov 27 15:17:01 logan-laptop CRON[5602]: pam_unix(cron:session): session opened for user root by (uid=0)
Nov 27 15:17:01 logan-laptop CRON[5602]: pam_unix(cron:session): session closed for user root
Nov 27 16:17:01 logan-laptop CRON[5624]: pam_unix(cron:session): session opened for user root by (uid=0)
Nov 27 16:17:01 logan-laptop CRON[5624]: pam_unix(cron:session): session closed for user root
Nov 27 17:05:40 logan-laptop sudo: logan : TTY=unknown ; PWD=/home/logan ; USER=root ; COMMAND=/usr/sbin/synaptic --hide-main-window --non-interactive --parent-window-id 60817411 --update-at-startup
Nov 27 17:08:00 logan-laptop sudo: logan : TTY=unknown ; PWD=/home/logan ; USER=root ; COMMAND=/usr/sbin/synaptic --hide-main-window --non-interactive --parent-window-id 60817411 --update-at-startup
Nov 27 17:09:51 logan-laptop sudo: logan : TTY=unknown ; PWD=/home/logan ; USER=root ; COMMAND=/usr/bin/software-properties-gtk
Nov 27 17:10:39 logan-laptop sudo: logan : TTY=pts/0 ; PWD=/home/logan ; USER=root ; COMMAND=/usr/bin/apt-key add -
Nov 27 17:10:59 logan-laptop sudo: logan : TTY=unknown ; PWD=/home/logan ; USER=root ; COMMAND=/usr/bin/software-properties-gtk
Nov 27 17:11:17 logan-laptop sudo: logan : TTY=unknown ; PWD=/home/logan ; USER=root ; COMMAND=/usr/sbin/synaptic --hide-main-window --non-interactive --parent-window-id 60817445 --update-at-startup
Nov 27 17:11:43 logan-laptop sudo: logan : TTY=unknown ; PWD=/home/logan ; USER=root ; COMMAND=/usr/sbin/synaptic --hide-main-window --non-interactive --parent-window-id 60817411 --update-at-startup
Nov 27 17:11:53 logan-laptop sudo: logan : TTY=unknown ; PWD=/home/logan ; USER=root ; COMMAND=/usr/sbin/synaptic --hide-main-window --non-interactive --parent-window-id 60817411 --set-selections-file /tmp/tmp0J4dWG
Nov 27 17:17:01 logan-laptop CRON[6087]: pam_unix(cron:session): session opened for user root by (uid=0)
Nov 27 17:17:01 logan-laptop CRON[6087]: pam_unix(cron:session): session closed for user root
Nov 27 18:09:13 logan-laptop sudo: logan : TTY=unknown ; PWD=/home/logan ; USER=root ; COMMAND=/usr/sbin/firestarter
Nov 27 18:17:01 logan-laptop CRON[7341]: pam_unix(cron:session): session opened for user root by (uid=0)
Nov 27 18:17:01 logan-laptop CRON[7341]: pam_unix(cron:session): session closed for user root
Bookmarks