Logfile Output

ServerDateServiceMessage
bhodisoft.com Sent:From: root@mailSunday, July 30, 20 3:10 AM
odisoft.com Subject:To: [email protected]Contents of message1
Jul 23 04:02:0roto-router syslogd.3-3: restart.
roto-routerJul 23 04:02:02syslogd 1.3-3restart.
roto-routerJul 23 04:02:03syslogd 1.3-3restart.
roto-routerJul 23 04:02:03syslogd 1.3-3restart.
roto-routerJul 23 04:02:04syslogd 1.3-3restart.
roto-routerJul 23 04:54:21sshd[619]connection from "10.0.0.3"
roto-routerJul 23 04:54:32sshd[23948]User bswopes's local password accepted.
roto-routerJul 23 04:54:32sshd[23948]Password authentication for user bswopes accepted.
roto-routerJul 23 04:54:32sshd[23948]User bswopes, coming from hume.the-well.lan, authenticated.
roto-routerJul 23 05:02:55sshd[23948]Remote host disconnected: Connection closed.
roto-routerJul 23 05:02:55sshd[23948]connection lost: 'Connection closed.'
roto-routerJul 23 14:54:06ftpd[24422]FTP LOGIN FROM hume.the-well.lan [10.0.0.3], bswopes
roto-routerJul 23 14:54:11ftpd[24422]FTP session closed
roto-routerJul 24 18:06:56sshd[20125]Remote host disconnected: Connection closed.
roto-routerJul 24 18:06:56sshd[20125]connection lost: 'Connection closed.'
roto-routerJul 24 18:07:10sshd[619]connection from "10.0.0.3"
roto-routerJul 24 18:07:18sshd[25823]User tailmon's local password accepted.
roto-routerJul 24 18:07:18sshd[25823]Password authentication for user tailmon accepted.
roto-routerJul 24 18:07:18sshd[25823]User tailmon, coming from hume.the-well.lan, authenticated.
roto-routerJul 24 20:08:09sshd[25823]Remote host disconnected: Connection closed.
roto-routerJul 24 20:08:09sshd[25823]connection lost: 'Connection closed.'
roto-routerJul 25 01:32:15sshd[619]connection from "209.247.53.208"
roto-routerJul 25 01:33:01sshd[26215]User paramitaom's local password accepted.
roto-routerJul 25 01:33:01sshd[26215]Password authentication for user paramitaom accepted.
roto-routerJul 25 01:33:01sshd[26215]User paramitaom, coming from dialup-209.247.53.208.SanFrancisco1.Level3.net, authenticated.
roto-routerJul 25 01:34:13sshd[619]connection from "10.0.0.3"
roto-routerJul 25 01:34:20sshd[26231]User tailmon's local password accepted.
roto-routerJul 25 01:34:20sshd[26231]Password authentication for user tailmon accepted.
roto-routerJul 25 01:34:20sshd[26231]User tailmon, coming from hume.the-well.lan, authenticated.
roto-routerJul 25 01:37:24sshd[26215]Remote host disconnected: Connection closed.
roto-routerJul 25 01:37:24sshd[26215]connection lost: 'Connection closed.'
roto-routerJul 25 02:21:29sshd[619]connection from "10.0.0.2"
roto-routerJul 25 02:22:02sshd[26288]User bswopes's local password accepted.
roto-routerJul 25 02:22:02sshd[26288]Password authentication for user bswopes accepted.
roto-routerJul 25 02:22:02sshd[26288]User bswopes, coming from shiva.the-well.lan, authenticated.
roto-routerJul 25 02:22:10PAM_pwdb[26304](su) session opened for user root by bswopes(uid=500)
roto-routerJul 25 02:22:55PAM_pwdb[26304](su) session closed for user root
roto-routerJul 25 02:22:56sshd[26288]Remote host disconnected: Connection closed.
roto-routerJul 25 02:22:56sshd[26288]connection lost: 'Connection closed.'
roto-routerJul 25 02:28:44sshd[619]connection from "10.0.0.3"
roto-routerJul 25 02:28:54sshd[26342]User bswopes's local password accepted.
roto-routerJul 25 02:28:54sshd[26342]Password authentication for user bswopes accepted.
roto-routerJul 25 02:28:54sshd[26342]User bswopes, coming from hume.the-well.lan, authenticated.
roto-routerJul 25 02:29:47PAM_pwdb[26367]authentication failure; bswopes(uid=500) -> root for su service
roto-routerJul 25 02:29:54PAM_pwdb[26369](su) session opened for user root by bswopes(uid=500)
roto-routerJul 25 02:31:24PAM_pwdb[26369](su) session closed for user root
roto-routerJul 25 02:31:25sshd[26342]Remote host disconnected: Connection closed.
roto-routerJul 25 02:31:25sshd[26342]connection lost: 'Connection closed.'
roto-routerJul 25 03:05:13ftpd[26428]failed login from shiva.the-well.lan [10.0.0.2]
roto-routerJul 25 03:05:18ftpd[26428]FTP LOGIN FROM shiva.the-well.lan [10.0.0.2], bswopes
roto-routerJul 25 03:05:43ftpd[26428]FTP session closed
roto-routerJul 25 03:13:51sshd[619]connection from "10.0.0.2"
roto-routerJul 25 03:14:02sshd[26442]User bswopes's local password accepted.
roto-routerJul 25 03:14:02sshd[26442]Password authentication for user bswopes accepted.
roto-routerJul 25 03:14:02sshd[26442]User bswopes, coming from shiva.the-well.lan, authenticated.
roto-routerJul 25 03:14:17sshd[26442]Remote host disconnected: Connection closed.
roto-routerJul 25 03:14:17sshd[26442]connection lost: 'Connection closed.'
roto-routerJul 25 03:16:42sshd[619]connection from "10.0.0.3"
roto-routerJul 25 03:16:52sshd[26462]User bswopes's local password accepted.
roto-routerJul 25 03:16:52sshd[26462]Password authentication for user bswopes accepted.
roto-routerJul 25 03:16:52sshd[26462]User bswopes, coming from hume.the-well.lan, authenticated.
roto-routerJul 25 04:19:12PAM_pwdb[26696](su) session opened for user root by bswopes(uid=500)
roto-routerJul 25 04:27:31PAM_pwdb[26696](su) session closed for user root
roto-routerJul 25 04:27:32sshd[26462]Remote host disconnected: Connection closed.
roto-routerJul 25 04:27:32sshd[26462]connection lost: 'Connection closed.'
roto-routerJul 25 04:43:47sshd[619]connection from "10.0.0.3"
roto-routerJul 25 04:43:59sshd[26769]User bswopes's local password accepted.
roto-routerJul 25 04:43:59sshd[26769]Password authentication for user bswopes accepted.
roto-routerJul 25 04:43:59sshd[26769]User bswopes, coming from hume.the-well.lan, authenticated.
roto-routerJul 25 05:06:47sshd[26769]Remote host disconnected: Connection closed.
roto-routerJul 25 05:06:47sshd[26769]connection lost: 'Connection closed.'
roto-routerJul 25 12:10:23sshd[619]connection from "10.0.0.3"
roto-routerJul 25 12:10:33sshd[27132]User bswopes's local password accepted.
roto-routerJul 25 12:10:33sshd[27132]Password authentication for user bswopes accepted.
roto-routerJul 25 12:10:33sshd[27132]User bswopes, coming from hume.the-well.lan, authenticated.
roto-routerJul 25 12:11:11sshd[27132]Remote host disconnected: Connection closed.
roto-routerJul 25 12:11:11sshd[27132]connection lost: 'Connection closed.'
roto-routerJul 25 13:01:53sshd[619]connection from "10.0.0.3"
roto-routerJul 25 13:02:04sshd[27204]User bswopes's local password accepted.
roto-routerJul 25 13:02:04sshd[27204]Password authentication for user bswopes accepted.
roto-routerJul 25 13:02:04sshd[27204]User bswopes, coming from hume.the-well.lan, authenticated.
roto-routerJul 25 14:56:34ftpd[27378]FTP LOGIN FROM shiva.the-well.lan [10.0.0.2], bswopes
roto-routerJul 25 14:56:53ftpd[27378]FTP session closed
roto-routerJul 25 15:09:55PAM_pwdb[27397](su) session opened for user root by bswopes(uid=500)
roto-routerJul 25 15:10:19PAM_pwdb[27397](su) session closed for user root
roto-routerJul 25 15:13:07PAM_pwdb[27438](su) session opened for user root by bswopes(uid=500)
roto-routerJul 25 15:13:41PAM_pwdb[27438](su) session closed for user root
roto-routerJul 25 15:16:02PAM_pwdb[27465](su) session opened for user root by bswopes(uid=500)
roto-routerJul 25 15:16:10named[27483]starting. named 8.2.2-P5 Tue Mar 7 02:45:02 PST 2000 ^Iroot@roto-router:/root/tarball/bind/src/bin/named
roto-routerJul 25 15:16:10named[27483]/etc/named.conf:13: can't redefine channel 'default_syslog'
roto-routerJul 25 15:17:36named[27498]starting. named 8.2.2-P5 Tue Mar 7 02:45:02 PST 2000 ^Iroot@roto-router:/root/tarball/bind/src/bin/named
roto-routerJul 25 15:17:36named[27498]/etc/named.conf:13: can't redefine channel 'default_syslog'
roto-routerJul 25 15:18:23named[27508]starting. named 8.2.2-P5 Tue Mar 7 02:45:02 PST 2000 ^Iroot@roto-router:/root/tarball/bind/src/bin/named
roto-routerJul 25 15:18:23named[27508]/etc/named.conf:13: can't redefine channel 'default_syslog'
roto-routerJul 25 15:18:39PAM_pwdb[27465](su) session closed for user root
roto-routerJul 25 18:30:57sshd[27204]Remote host disconnected: Connection closed.
roto-routerJul 25 18:30:57sshd[27204]connection lost: 'Connection closed.'
roto-routerJul 25 19:29:34ftpd[27803]FTP LOGIN FROM shiva.the-well.lan [10.0.0.2], bswopes
roto-routerJul 25 19:29:50ftpd[27803]FTP session closed
roto-routerJul 25 19:35:02ftpd[27813]FTP LOGIN FROM shiva.the-well.lan [10.0.0.2], bswopes
roto-routerJul 25 19:35:12ftpd[27813]FTP session closed
roto-routerJul 25 19:38:03sshd[619]connection from "10.0.0.3"
roto-routerJul 25 19:38:23sshd[27817]User bswopes's local password accepted.
roto-routerJul 25 19:38:23sshd[27817]Password authentication for user bswopes accepted.
roto-routerJul 25 19:38:23sshd[27817]User bswopes, coming from hume.the-well.lan, authenticated.
roto-routerJul 25 19:53:02PAM_pwdb[27849](su) session opened for user root by bswopes(uid=500)
roto-routerJul 25 19:57:06ftpd[27870]FTP LOGIN FROM shiva.the-well.lan [10.0.0.2], bswopes
roto-routerJul 25 19:57:46ftpd[27870]FTP session closed
roto-routerJul 25 20:02:14PAM_pwdb[27849](su) session closed for user root
roto-routerJul 25 20:27:19ftpd[27962]FTP session closed
roto-routerJul 25 20:27:19sshd[619]connection from "10.0.0.2"
roto-routerJul 25 20:27:20sshd[27965]Remote host disconnected: Connection closed by remote host.
roto-routerJul 25 20:27:21sshd[27965]connection lost: 'Connection closed by remote host.'
roto-routerJul 25 21:53:35PAM_pwdb[28061](su) session opened for user root by bswopes(uid=500)
roto-routerJul 25 21:54:02PAM_pwdb[28061](su) session closed for user root
roto-routerJul 25 21:54:07sshd[27817]Remote host disconnected: Connection closed.
roto-routerJul 25 21:54:07sshd[27817]connection lost: 'Connection closed.'
roto-routerJul 25 22:21:23sshd[619]connection from "10.0.0.2"
roto-routerJul 25 22:21:41sshd[28110]User bswopes's local password accepted.
roto-routerJul 25 22:21:41sshd[28110]Password authentication for user bswopes accepted.
roto-routerJul 25 22:21:41sshd[28110]User bswopes, coming from shiva.the-well.lan, authenticated.
roto-routerJul 25 22:22:03sshd[28110]Remote host disconnected: Connection closed.
roto-routerJul 25 22:22:03sshd[28110]connection lost: 'Connection closed.'
roto-routerJul 25 22:40:06sshd[619]connection from "10.0.0.3"
roto-routerJul 25 22:40:17sshd[28145]User bswopes's local password accepted.
roto-routerJul 25 22:40:17sshd[28145]Password authentication for user bswopes accepted.
roto-routerJul 25 22:40:17sshd[28145]User bswopes, coming from hume.the-well.lan, authenticated.
roto-routerJul 25 22:40:27sshd[28145]Remote host disconnected: Connection closed.
roto-routerJul 25 22:40:27sshd[28145]connection lost: 'Connection closed.'
roto-routerJul 25 22:44:25sshd[619]connection from "10.0.0.3"
roto-routerJul 25 22:44:36sshd[28171]Remote host disconnected: Unable to authenticate using any of the configured authentication methods
roto-routerJul 25 22:44:36sshd[28171]disconnected by application: 'Unable to authenticate using any of the configured authentication methods'
roto-routerJul 26 14:04:09sshd[26231]Remote host disconnected: Connection closed.
roto-routerJul 26 14:04:09sshd[26231]connection lost: 'Connection closed.'
roto-routerJul 26 14:25:42sshd[619]connection from "10.0.0.3"
roto-routerJul 26 14:25:50sshd[29119]User tailmon's local password accepted.
roto-routerJul 26 14:25:50sshd[29119]Password authentication for user tailmon accepted.
roto-routerJul 26 14:25:50sshd[29119]User tailmon, coming from hume.the-well.lan, authenticated.
roto-routerJul 26 22:25:02sshd[619]connection from "10.0.0.5"
roto-routerJul 26 22:25:03sshd[29505]DNS lookup failed for "10.0.0.5".
roto-routerJul 26 22:25:08sshd[619]connection from "10.0.0.3"
roto-routerJul 26 22:25:17sshd[29505]Connection from 10.0.0.5 denied. Authentication as user james was attempted.
roto-routerJul 26 22:25:17sshd[29505]Remote host disconnected: No further authentication methods available.
roto-routerJul 26 22:25:17sshd[29505]disconnected by application: 'No further authentication methods available.'
roto-routerJul 26 22:25:24sshd[619]connection from "10.0.0.5"
roto-routerJul 26 22:25:24sshd[29513]DNS lookup failed for "10.0.0.5".
roto-routerJul 26 22:25:29sshd[29508]User bswopes's local password accepted.
roto-routerJul 26 22:25:29sshd[29508]Password authentication for user bswopes accepted.
roto-routerJul 26 22:25:29sshd[29508]User bswopes, coming from hume.the-well.lan, authenticated.
roto-routerJul 26 22:25:34sshd[29513]Connection from 10.0.0.5 denied. Authentication as user james was attempted.
roto-routerJul 26 22:25:34sshd[29513]Remote host disconnected: No further authentication methods available.
roto-routerJul 26 22:25:34sshd[29513]disconnected by application: 'No further authentication methods available.'
roto-routerJul 26 22:25:50sshd[619]connection from "10.0.0.5"
roto-routerJul 26 22:25:50sshd[29533]DNS lookup failed for "10.0.0.5".
roto-routerJul 26 22:25:58sshd[29533]Connection from 10.0.0.5 denied. Authentication as user james was attempted.
roto-routerJul 26 22:25:58sshd[29533]Remote host disconnected: No further authentication methods available.
roto-routerJul 26 22:25:58sshd[29533]disconnected by application: 'No further authentication methods available.'
roto-routerJul 26 22:26:32sshd[619]connection from "10.0.0.5"
roto-routerJul 26 22:26:33sshd[29539]DNS lookup failed for "10.0.0.5".
roto-routerJul 26 22:26:40sshd[29539]Connection from 10.0.0.5 denied. Authentication as user bswopes was attempted.
roto-routerJul 26 22:26:40sshd[29539]Remote host disconnected: No further authentication methods available.
roto-routerJul 26 22:26:40sshd[29539]disconnected by application: 'No further authentication methods available.'
roto-routerJul 26 22:34:43PAM_pwdb[29592]authentication failure; bswopes(uid=500) -> root for su service
roto-routerJul 26 22:34:52PAM_pwdb[29594](su) session opened for user root by bswopes(uid=500)
roto-routerJul 26 22:37:45PAM_pwdb[29594](su) session closed for user root
roto-routerJul 26 22:37:48sshd[29508]Remote host disconnected: Connection closed.
roto-routerJul 26 22:37:48sshd[29508]connection lost: 'Connection closed.'
roto-routerJul 26 23:08:58sshd[619]connection from "10.0.0.3"
roto-routerJul 26 23:08:58sshd[29119]Remote host disconnected: Connection closed.
roto-routerJul 26 23:08:58sshd[29119]connection lost: 'Connection closed.'
roto-routerJul 26 23:09:06sshd[29650]User tailmon's local password accepted.
roto-routerJul 26 23:09:06sshd[29650]Password authentication for user tailmon accepted.
roto-routerJul 26 23:09:06sshd[29650]User tailmon, coming from hume.the-well.lan, authenticated.
roto-routerJul 29 11:10:45portsentry[7083]attackalert: SYN/Normal scan from host: 211.169.82.130/211.169.82.130 to TCP port: 98
roto-routerJul 29 11:10:45portsentry[7083]attackalert: Host 211.169.82.130 has been blocked via wrappers with string: "ALL: 211.169.82.130"
roto-routerJul 29 11:10:45portsentry[7083]attackalert: Host 211.169.82.130 has been blocked via dropped route using command: "/sbin/ipchains -I input -s 211.169.82.130 -j DENY -l"