Security log
Posted: Fri Mar 26, 2010 10:50 am
I have been carefully monitoring my security log after having installed the server just to be sure that I don't have some error in my LAN setup that allows someone else in. For example, I have installed "denyhosts" so that attackers are automatically added to the "hosts.deny" file. I have periodically looked at the \var\log\secure file to be sure of who is attempting to log in.
Here's what I found yesterday:
Here's what I found yesterday:
- Mar 23 01:45:45 fedora12 groupadd[27988]: group added to /etc/group: name=saslauth, GID=47 8
Mar 23 01:45:45 fedora12 groupadd[27988]: group added to /etc/gshadow: name=saslauth
Mar 23 01:45:45 fedora12 groupadd[27988]: new group: name=saslauth, GID=478
Mar 23 01:45:45 fedora12 useradd[27993]: new user: name=saslauth, UID=491, GID=478, home=/ var/empty/saslauth, shell=/sbin/nologin
Mar 23 01:45:58 fedora12 userdel[28016]: delete user 'saslauth'
Mar 23 01:45:58 fedora12 userdel[28016]: removed group 'saslauth' owned by 'saslauth'