I donāt know if there is something unusual in the logs as i did never watch themā¦ Iām not a professionnal you know
So i ran logwatch and here is the output file:
[root@h10-10 root]# logwatch --detail high --save /root/logwatchperso.log
[root@h10-10 root]# cat /root/logwatchperso.log
################### LogWatch 5.1 (02/03/04) ####################
Processing Initiated: Tue May 10 14:01:21 2005
Date Range Processed: yesterday
Detail Level of Output: 10
Logfiles for Host: h10-10
################################################################
--------------------- Cron Begin ------------------------
Commands Run:
User iworx:
cd /home/interworx/cron ; ./iworx.pex --daily: 1 Time(s)
cd /home/interworx/cron ; ./iworx.pex --fifteenly: 96 Time(s)
cd /home/interworx/cron ; ./iworx.pex --fively: 288 Time(s)
cd /home/interworx/cron ; ./iworx.pex --hourly: 24 Time(s)
cd /home/interworx/cron ; ./iworx.pex --quad_daily: 4 Time(s)
personal crontab listed: 2 Time(s)
User root:
/home/vpopmail/bin/clearopensmtp > /dev/null 2>&1: 24 Time(s)
/usr/bin/mrtg /etc/mrtg/mrtg.cfg: 288 Time(s)
run-parts /etc/cron.daily: 1 Time(s)
run-parts /etc/cron.hourly: 24 Time(s)
---------------------- Cron End -------------------------
--------------------- httpd Begin ------------------------
0.00 MB transfered in 289 responses (1xx 289, 2xx 0, 3xx 0, 4xx 0, 5xx 0)
0 Images (0 bytes),
0 Documents (0 bytes),
0 Archives (0 bytes),
0 Sound files (0 bytes),
0 Movies files (0 bytes),
0 Windows executable files (0 bytes),
0 Content pages (0 bytes),
0 Redirects (0 bytes),
0 Proxy Configuration Files (0 bytes),
0 Program source files (0 bytes),
0 CD Images (0 bytes),
289 Other (0 bytes)
A total of 1 unidentified āotherā records logged
with response code(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Invalid Users:
Unknown Account: 9 Time(s)
Sessions Opened:
root: 5 Time(s)
Unknown Entries:
authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=secondavenue.plus.com : 6 Time(s)
authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=211.234.100.218 : 2 Time(s)
authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=host-58-in-132.etcbaltimore.net : 1 Time(s)
---------------------- pam_unix End -------------------------
--------------------- proftpd-messages Begin ------------------------
Unmatched Entries
h10-10 (217.44.95.110[217.44.95.110]) - FTP session idle timeout, disconnected.
h10-10 (217.44.95.110[217.44.95.110]) - FTP session idle timeout, disconnected.
h10-10 (217.44.95.110[217.44.95.110]) - FTP session idle timeout, disconnected.
h10-10 (217.44.95.110[217.44.95.110]) - FTP session idle timeout, disconnected.
---------------------- proftpd-messages End -------------------------
--------------------- Connections (secure-log) Begin ------------------------
New Users:
useradd (publidev)
useradd (miniblog)
useradd (dnsbz)
useradd (miniblog)
Deleted Users:
publidev
miniblog
New Groups:
useradd (publidev)
useradd (miniblog)
useradd (dnsbz)
useradd (miniblog)
Deleted Groups:
publidev
miniblog
---------------------- Connections (secure-log) End -------------------------
--------------------- sendmail Begin ------------------------
ERROR: Could not open /etc/mail/local-host-names
ERROR: Could not open /etc/mail/access
Message Size Distribution:
Range # Msgs KBytes
0 - 10k 0 0
10k - 20k 0 0
20k - 50k 0 0
50k - 100k 0 0
100k - 500k 0 0
500k - 1Mb 0 0
1Mb - 2Mb 0 0
2Mb - 5Mb 0 0
5Mb - 10Mb 0 0
10Mb+ 0 0
TOTAL 0 0
---------------------- sendmail End -------------------------
--------------------- SSHD Begin ------------------------
Didnāt receive an ident from these IPs:
211.234.100.218: 2 Time(s)
host-58-in-132.etcbaltimore.net (12.167.132.58): 2 Time(s)
secondavenue.plus.com (81.174.235.30): 2 Time(s)
Failed logins from these:
anonymous/password from ::ffff:81.174.235.30: 2 Time(s)
chuck/password from ::ffff:81.174.235.30: 1 Time(s)
darkman/password from ::ffff:81.174.235.30: 1 Time(s)
hostmaster/password from ::ffff:81.174.235.30: 1 Time(s)
passwd/password from ::ffff:81.174.235.30: 1 Time(s)
temp/password from ::ffff:12.167.132.58: 1 Time(s)
thomas/password from ::ffff:211.234.100.218: 2 Time(s)
Illegal users from these:
anonymous/none from ::ffff:81.174.235.30: 2 Time(s)
anonymous/password from ::ffff:81.174.235.30: 2 Time(s)
chuck/none from ::ffff:81.174.235.30: 1 Time(s)
chuck/password from ::ffff:81.174.235.30: 1 Time(s)
darkman/none from ::ffff:81.174.235.30: 1 Time(s)
darkman/password from ::ffff:81.174.235.30: 1 Time(s)
hostmaster/none from ::ffff:81.174.235.30: 1 Time(s)
hostmaster/password from ::ffff:81.174.235.30: 1 Time(s)
passwd/none from ::ffff:81.174.235.30: 1 Time(s)
passwd/password from ::ffff:81.174.235.30: 1 Time(s)
temp/none from ::ffff:12.167.132.58: 1 Time(s)
temp/password from ::ffff:12.167.132.58: 1 Time(s)
thomas/none from ::ffff:211.234.100.218: 2 Time(s)
thomas/password from ::ffff:211.234.100.218: 2 Time(s)
Users logging in through sshd:
root:
host217-44-95-110.range217-44.btcentralplus.com (217.44.95.110): 5 times
SFTP subsystem requests: 4 Time(s)
---------------------- SSHD End -------------------------
--------------------- vpopmail Begin ------------------------
No Such User Found:
bbastide - 1 Time(s)
---------------------- vpopmail End -------------------------
------------------ Disk Space --------------------
Filesystem Size Used Avail Use% Mounted on
/dev/hda1 75G 46G 25G 65% /
none 236M 0 236M 0% /dev/shm
###################### LogWatch End #########################
And about my server load here are the 3 pics i got from nodeworx:
CPU Utilization
Localhost - Load Average
Localhost Processes
Concerning the backups, i never did any backup!!
As everything on my server is the same than on my computer!!
I took a look at all these stats and logs, nothing seems wrong, doesnāt it?
Thanks very much for your help !!!