home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.unix.ultrix
- Path: sparky!uunet!munnari.oz.au!metro!usage!newt.phys.unsw.edu.au!mcba
- From: mcba@newt.phys.unsw.edu.au (Michael C. B. Ashley)
- Subject: SUMMARY (preliminary): There have been 243 unsuccessful login attempts on your account
- Message-ID: <1992Aug25.110645.16618@usage.csd.unsw.OZ.AU>
- Keywords: comp.unix.ultrix
- Sender: news@usage.csd.unsw.OZ.AU
- Nntp-Posting-Host: newt.phys.unsw.edu.au
- Organization: University of New South Wales
- Date: Tue, 25 Aug 1992 11:06:45 GMT
- Lines: 42
-
- Thank you to the many people who responded to my original message
- regarding tracking down unsuccessful root logins.
-
- I have done two things to try and locate the problem: (1) enabled the
- ULTRIX audit facility to audit success and failure of all logins, and
- (2) installed log_tcp (a wrapper for IP network services from Vol 30 of
- comp.sources.unix, written by Wietse Venema (wietse@wzv.win.tue.nl)).
- log_tcp writes a message to /var/spool/mqueue/syslog whenever someone
- tries to use any of the IP network services that you specify (I have
- enabled TELNETD, RLOGIND, RSHD, and FTPD).
-
- However, the problem remains! After leaving the system overnight I had
- "133 unsuccessful login attempts" on the root account, and the
- audit log didn't show anything (yes I did dump the auditd buffer with
- /etc/sec/auditd -d, and I have checked that a deliberate unsuccessful
- root login is recorded). Moreover, log_tcp recorded just the correct
- number of logind/rshd/telnetd/ftpd's expected from the output of "last".
- Also, a thorough check through "lastcomm" shows no commands being run
- that
- tally with the number and distribution of the phantom logins (I
- usually get between 50 and 100 of them a day; sometimes 25 an hour,
- sometimes only 1 or 2 per hour).
-
- So, before I go crazy and reload the operating system in a frenzy of
- paranoia, could someone please answer the following questions?
-
- (1) What possible events cause the "unsuccessful login attempt"
- counter to be incremented? Presumably this counter is the
- "fail_count" located in the auth file.
-
- (2) Are there any such events that would also fail to be noticed by
- the auditd daemon? Or is it possible that I have auditd set up
- incorrectly?
-
- (3) Are there any other ways of logging into a DECstation other than
- the logind/rshd/telnetd/ftpd daemons that I am monitoring with
- log_tcp? (I don't have DECNET support in the kernel, and don't
- have LAT as far as I know...).
-
- Thank you in advance for any help.
- Michael Ashley mcba@newt.phys.unsw.edu.au
- Astrophysics Dept. / Uni of NSW / Sydney Australia
-