From owner-freebsd-security@FreeBSD.ORG Sun Apr 18 19:12:13 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id F183E16A4CE for ; Sun, 18 Apr 2004 19:12:13 -0700 (PDT) Received: from rwcrmhc11.comcast.net (rwcrmhc11.comcast.net [204.127.198.35]) by mx1.FreeBSD.org (Postfix) with ESMTP id C0A8243D4C for ; Sun, 18 Apr 2004 19:12:13 -0700 (PDT) (envelope-from cristjc@comcast.net) Received: from blossom.cjclark.org (c-24-6-187-112.client.comcast.net[24.6.187.112]) by comcast.net (rwcrmhc11) with ESMTP id <2004041902121301300fddnde>; Mon, 19 Apr 2004 02:12:13 +0000 Received: from blossom.cjclark.org (localhost. [127.0.0.1]) by blossom.cjclark.org (8.12.9p2/8.12.8) with ESMTP id i3J2Ce8B067337; Sun, 18 Apr 2004 19:12:40 -0700 (PDT) (envelope-from cristjc@comcast.net) Received: (from cjc@localhost) by blossom.cjclark.org (8.12.9p2/8.12.9/Submit) id i3J2CdQi067336; Sun, 18 Apr 2004 19:12:39 -0700 (PDT) (envelope-from cristjc@comcast.net) X-Authentication-Warning: blossom.cjclark.org: cjc set sender to cristjc@comcast.net using -f Date: Sun, 18 Apr 2004 19:12:39 -0700 From: "Crist J. Clark" To: z3l3zt@hackunite.net Message-ID: <20040419021239.GA67288@blossom.cjclark.org> References: <1998.213.112.193.35.1082212115.squirrel@mail.hackunite.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1998.213.112.193.35.1082212115.squirrel@mail.hackunite.net> User-Agent: Mutt/1.4.2.1i X-URL: http://people.freebsd.org/~cjc/ cc: freebsd-security@freebsd.org Subject: Re: Is log_in_vain really good or really bad? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: "Crist J. Clark" List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 19 Apr 2004 02:12:14 -0000 On Sat, Apr 17, 2004 at 04:28:35PM +0200, z3l3zt@hackunite.net wrote: [snip] > My server box is a Intel Celeron 733Mhz, 384Mb of RAM.. yet it's slow from > time to time since I only run ATA66 due to the old motherboard. When this > "attack" occured yesterday, the box almost died and the box were working > 100%.. all users who were logged in got "spammed" since the default > *.emerg in /etc/syslog.conf is set to "*" .. Not sure what that has to do with anything. The log_in_vain messages get logged at "info" level. What messages were your users seeing? -- Crist J. Clark | cjclark@alum.mit.edu | cjclark@jhu.edu http://people.freebsd.org/~cjc/ | cjc@freebsd.org