Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 10 May 2008 23:00:41 +0200
From:      Mel <fbsd.questions@rachie.is-a-geek.net>
To:        freebsd-questions@freebsd.org, dennis_flynn@yahoo.com
Subject:   Re: root login stops working
Message-ID:  <200805102300.41775.fbsd.questions@rachie.is-a-geek.net>
In-Reply-To: <812883.11120.qm@web54010.mail.re2.yahoo.com>
References:  <812883.11120.qm@web54010.mail.re2.yahoo.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Saturday 10 May 2008 20:50:46 Dennis Flynn wrote:
> I'm running FreeBSD wx.dennis-flynn.net 7.0-RELEASE FreeBSD 7.0-RELEASE #0:
> Sun Feb 24 19:59:52 UTC 2008    
> root@logan.cse.buffalo.edu:/usr/obj/usr/src/sys/GENERIC  i386
>
> About a day after install root login no longer works - even on the console.
>
> I see the following in /var/log/auth.log:
> May 10 14:22:37 wx sshd[86223]: Accepted password for root from
> 10.11.12.104 port 1492 ssh2 May 10 14:22:37 wx sshd[86223]: Received
> disconnect from 10.11.12.104: 0:
>
> And in /var/log/messages:
> May 10 14:27:51 wx kernel: pid 86237 (csh), uid 0: exited on signal 11
> (core dumped)

Looks like you got hacked, the tell-tale being "ip port ####".
http://security.freebsd.org/advisories/FreeBSD-SA-08:05.openssh.asc

-- 
Mel

Problem with today's modular software: they start with the modules
    and never get to the software part.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200805102300.41775.fbsd.questions>