cogset
December 17th, 2012, 11:15 AM
I've seen this weird message in syslog:
Dec 16 13:28:46 ubuntu-desktop /usr/bin/crontab[20278]: (root) LIST (nobody)that (nobody) looked out of context,so I've examined other logs and found that it matches time-wise exactly this event:
Dec 16 13:28:46 ubuntu-desktop sudo: ubuntu : TTY=pts/10 ; PWD=/home/ubuntu ; USER=root ; COMMAND=/usr/sbin/chkrootkit
which I can attribute to myself launching (as root) the rkhunter --update command,if memory serves:so what was going on exactly ?
Both rkhunter and chrootkit report no issues and nmap doesn't find any unusual ports open,auth.log did not show other users logged and besides ssh is not installed as I don't need it.
So what does that (nobody) stand for ?
Dec 16 13:28:46 ubuntu-desktop /usr/bin/crontab[20278]: (root) LIST (nobody)that (nobody) looked out of context,so I've examined other logs and found that it matches time-wise exactly this event:
Dec 16 13:28:46 ubuntu-desktop sudo: ubuntu : TTY=pts/10 ; PWD=/home/ubuntu ; USER=root ; COMMAND=/usr/sbin/chkrootkit
which I can attribute to myself launching (as root) the rkhunter --update command,if memory serves:so what was going on exactly ?
Both rkhunter and chrootkit report no issues and nmap doesn't find any unusual ports open,auth.log did not show other users logged and besides ssh is not installed as I don't need it.
So what does that (nobody) stand for ?