Gentoo Forums
Gentoo Forums
Quick Search: in
keep getting hacked (Solved) and yes it's true
View unanswered posts
View posts from last 24 hours

Goto page 1, 2, 3, 4, 5  Next  
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
Snappi
Tux's lil' helper
Tux's lil' helper


Joined: 20 Oct 2003
Posts: 113

PostPosted: Sat Nov 18, 2006 1:23 pm    Post subject: keep getting hacked (Solved) and yes it's true Reply with quote

Hi, I've been hacked >3 times now by the same guy.

I have iptables set up and chkrootkit and rkhunter doesn't detect anything.

ps -ef
Code:
UID        PID  PPID  C STIME TTY          TIME CMD
root         1     0  0 13:31 ?        00:00:00 init [3]
root         2     1  0 13:31 ?        00:00:00 [ksoftirqd/0]
root         3     1  0 13:31 ?        00:00:00 [watchdog/0]
root         4     1  0 13:31 ?        00:00:00 [events/0]
root         5     1  0 13:31 ?        00:00:00 [khelper]
root         6     1  0 13:31 ?        00:00:00 [kthread]
root         8     6  0 13:31 ?        00:00:00 [kblockd/0]
root         9     6  0 13:31 ?        00:00:00 [kacpid]
root       130     6  0 13:31 ?        00:00:00 [kseriod]
root       133     6  0 13:31 ?        00:00:00 [khubd]
root       224     6  0 13:31 ?        00:00:00 [pdflush]
root       225     6  0 13:31 ?        00:00:00 [pdflush]
root       226     1  0 13:31 ?        00:00:00 [kswapd0]
root       227     6  0 13:31 ?        00:00:00 [aio/0]
root       839     6  0 13:31 ?        00:00:00 [kpsmoused]
root       887     6  0 13:31 ?        00:00:00 [ata/0]
root       893     6  0 13:31 ?        00:00:00 [scsi_eh_0]
root       894     6  0 13:31 ?        00:00:00 [scsi_eh_1]
root       899     6  0 13:31 ?        00:00:00 [scsi_eh_2]
root       900     6  0 13:31 ?        00:00:00 [scsi_eh_3]
root       913     1  0 13:31 ?        00:00:00 [khpsbpkt]
root       917     1  0 13:31 ?        00:00:00 [knodemgrd_0]
root      1139     1  0 13:32 ?        00:00:01 /sbin/udevd --daemon
root      5093     1  0 13:32 ?        00:00:00 /usr/sbin/syslog-ng
root      5661     1  0 13:32 ?        00:00:00 /usr/kde/3.5/bin/kdm
root      5664  5661  0 13:32 tty7     00:00:12 /usr/bin/X -br -nolisten tcp :0 vt7 -auth /var/run/xauth/A:0-isnE
root      5665  5661  0 13:32 ?        00:00:00 -:0
root      6087     1  0 13:32 ?        00:00:00 /usr/sbin/cron
root      6178     1  0 13:32 tty1     00:00:00 /sbin/agetty 38400 tty1 linux
root      6179     1  0 13:32 tty2     00:00:00 /sbin/agetty 38400 tty2 linux
root      6180     1  0 13:32 tty3     00:00:00 /sbin/agetty 38400 tty3 linux
root      6181     1  0 13:32 tty4     00:00:00 /sbin/agetty 38400 tty4 linux
root      6182     1  0 13:32 tty5     00:00:00 /sbin/agetty 38400 tty5 linux
root      6183     1  0 13:32 tty6     00:00:00 /sbin/agetty 38400 tty6 linux
sim       6203  5665  0 13:32 ?        00:00:00 /bin/sh /usr/kde/3.5/bin/startkde
sim       6231     1  0 13:32 ?        00:00:00 /usr/bin/dbus-launch --sh-syntax --exit-with-session
sim       6232     1  0 13:32 ?        00:00:00 dbus-daemon --fork --print-pid 8 --print-address 6 --session
root      6250     1  0 13:32 ?        00:00:00 start_kdeinit --new-startup +kcminit_startup
sim       6251     1  0 13:32 ?        00:00:00 kdeinit Running...
sim       6254     1  0 13:32 ?        00:00:00 dcopserver [kdeinit] --nosid
sim       6256  6251  0 13:32 ?        00:00:00 klauncher [kdeinit] --new-startup
sim       6258     1  0 13:32 ?        00:00:00 kded [kdeinit] --new-startup
sim       6263  6203  0 13:32 ?        00:00:00 kwrapper ksmserver
sim       6265     1  0 13:32 ?        00:00:00 ksmserver [kdeinit]
sim       6266  6251  0 13:32 ?        00:00:00 kwin [kdeinit] -session 1014cd7d2d4000116302868900000054200000_11
sim       6268     1  0 13:32 ?        00:00:00 knotify [kdeinit]
sim       6270     1  0 13:32 ?        00:00:00 kdesktop [kdeinit]
sim       6272     1  0 13:32 ?        00:00:01 kicker [kdeinit]
sim       6273  6251  0 13:32 ?        00:00:00 kio_file [kdeinit] file /tmp/ksocket-sim/klauncherizfGjc.slave-so
sim       6279     1  0 13:32 ?        00:00:00 kaccess [kdeinit]
sim       6282     1  0 13:32 ?        00:00:00 kxkb [kdeinit]
sim       6286     1  0 13:32 ?        00:00:00 klipper [kdeinit]
sim       6298  6251  0 13:32 ?        00:00:00 konsole [kdeinit]
sim       6299  6298  0 13:32 pts/1    00:00:00 /bin/bash
sim       6594  6298  0 13:55 pts/2    00:00:00 /bin/bash
root      6598  6594  0 13:55 pts/2    00:00:00 su -
root      6601  6598  0 13:55 pts/2    00:00:00 -su
root      6604  6601  0 13:55 pts/2    00:00:04 firestarter
root      6606     1  0 13:55 pts/2    00:00:00 /usr/libexec/gconfd-2 11
sim       6810  6270  0 13:56 ?        00:00:00 /bin/bash /usr/libexec/mozilla-launcher
sim       6819  6810  1 13:56 ?        00:00:16 /usr/lib64/mozilla-firefox/firefox-bin
sim       6824     1  0 13:56 ?        00:00:00 /usr/libexec/gconfd-2 12
sim       6831  6819  0 13:56 ?        00:00:00 [netstat] <defunct>
root      7109  6299  0 14:02 pts/1    00:00:00 su -
root      7112  7109  0 14:02 pts/1    00:00:00 -su
root      8262  7112  0 14:22 pts/1    00:00:00 ps -ef


I don't know what logs I should post, but pls tell me what you want to see and I reply with that.


Last edited by Snappi on Tue Dec 05, 2006 8:20 pm; edited 1 time in total
Back to top
View user's profile Send private message
PaulBredbury
Watchman
Watchman


Joined: 14 Jul 2005
Posts: 6506

PostPosted: Sat Nov 18, 2006 1:29 pm    Post subject: Re: keep getting hacked Reply with quote

Snappi wrote:
I've been hacked

What has the guy done? Gained root privileges?
Back to top
View user's profile Send private message
NeddySeagoon
Administrator
Administrator


Joined: 05 Jul 2003
Posts: 27168
Location: 56N 3W

PostPosted: Sat Nov 18, 2006 1:31 pm    Post subject: Reply with quote

Snappi,

How does the hacker get in ?
What makes you think you have been hacked ?
_________________
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Back to top
View user's profile Send private message
Snappi
Tux's lil' helper
Tux's lil' helper


Joined: 20 Oct 2003
Posts: 113

PostPosted: Sat Nov 18, 2006 1:47 pm    Post subject: Reply with quote

I don't know how he gets in, but he writes to me in both X and in the terminal. I assume he has root privileges.
Back to top
View user's profile Send private message
albright
Veteran
Veteran


Joined: 16 Nov 2003
Posts: 1705
Location: Near Toronto

PostPosted: Sat Nov 18, 2006 1:55 pm    Post subject: Reply with quote

probably best to wipe off the drive and reinstall ...
but if you can talk to the guy you could offer him
money to go away after explaining how s/he did it
Back to top
View user's profile Send private message
Snappi
Tux's lil' helper
Tux's lil' helper


Joined: 20 Oct 2003
Posts: 113

PostPosted: Sat Nov 18, 2006 2:00 pm    Post subject: Reply with quote

I have reinstalled the box 3 times in this order windows, gentoo, gentoo

He keps getting in everytime, I change passwords and usernames
Back to top
View user's profile Send private message
NeddySeagoon
Administrator
Administrator


Joined: 05 Jul 2003
Posts: 27168
Location: 56N 3W

PostPosted: Sat Nov 18, 2006 2:03 pm    Post subject: Reply with quote

Snappi,

That may not mean you are hacked. Do you accept messages?
I forget the proper name for them but its like network broadcast messages that sysadmins use to tell users to log off while servers are being restarted. Your hacker may just be using that mechanism to set messages to your IP.

However, its a one way message. Are you able to write back ?
If so, thats more worrying.

The only way to clean up a compromised system is to reinstall from the beginning.
You should not even restore from backups unless you can date the compromise and use backups from before that date.
_________________
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Back to top
View user's profile Send private message
PaulBredbury
Watchman
Watchman


Joined: 14 Jul 2005
Posts: 6506

PostPosted: Sat Nov 18, 2006 2:05 pm    Post subject: Reply with quote

Money? Yeah right, hackers have such strong morals that the guy will probably give a 10% discount if asked nicely.

More detail is needed here. "Writes to me" is far too vague.

I block ports 6000:6255 and 177 for Xorg, and 22 for SSH.
Back to top
View user's profile Send private message
Snappi
Tux's lil' helper
Tux's lil' helper


Joined: 20 Oct 2003
Posts: 113

PostPosted: Sat Nov 18, 2006 2:21 pm    Post subject: Reply with quote

he writes to me and I can write back. he is watching this!ttt
Back to top
View user's profile Send private message
NeddySeagoon
Administrator
Administrator


Joined: 05 Jul 2003
Posts: 27168
Location: 56N 3W

PostPosted: Sat Nov 18, 2006 2:27 pm    Post subject: Reply with quote

Snappi,

Thats not messages then. There is no point in doing more installs until you find out who he is getting in.
You say you have Windows and Gentoo installed. Does ths happen under Windows and Gentoo, or only with one OS ?
Which one ?
_________________
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Back to top
View user's profile Send private message
Snappi
Tux's lil' helper
Tux's lil' helper


Joined: 20 Oct 2003
Posts: 113

PostPosted: Sat Nov 18, 2006 2:33 pm    Post subject: Reply with quote

I don't know how he is getting in, I had windows and switch to gentoo so only installed OS is gentoo, but I he was able to get in trough both gentoo and windows.
how do I find out how he got in???
Back to top
View user's profile Send private message
NeddySeagoon
Administrator
Administrator


Joined: 05 Jul 2003
Posts: 27168
Location: 56N 3W

PostPosted: Sat Nov 18, 2006 6:16 pm    Post subject: Reply with quote

Snappi,

Start by looking at your log files in /var/log exactly where you need to look depends on your logger.

You are looking for connection attempts
_________________
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Back to top
View user's profile Send private message
bodhaami
n00b
n00b


Joined: 18 Nov 2006
Posts: 5

PostPosted: Sat Nov 18, 2006 6:56 pm    Post subject: track him down Reply with quote

System logs are one source of information.

You can also always try to ask the standart linux tools. The most relevant are
Code:
users
and
Code:
last
.
users should give you everybody logged into the system. The linux version reports every single instance when given no arguments (BSD vesion prints only the names of the users once).
That means that you should usually see your username several times if you have some xterms open because they are mostly bash -l bashes with a bit of graphics around :).
Now count them and see if they match. If you have logged into your system and have two xterms then you should see three times your username. And NO root!

Far more useful should be last. run something like
Code:
last | grep pty
or
Code:
last | grep "still logged in"
Whatch out for usernames you don't know or for sessions you never did. And of course for occurances of root logins. You should also read the manpages.

read the manpages of both to get more information out of them. What does the misterious guy tell you? What means: he's writing messages to you? By what means? Where do they appear?
Back to top
View user's profile Send private message
dev-urandom
Apprentice
Apprentice


Joined: 24 Jun 2005
Posts: 260
Location: Huh?

PostPosted: Sat Nov 18, 2006 8:33 pm    Post subject: Re: track him down Reply with quote

I would suggest a couple of more things.

Code:
netstat -nlp


This as root will give you the list of all running servers, along with the process names and pid. Shut down all those that you don't want. Also, go through /etc/password - delete unwanted users and change the shell from /bin/bash to /sbin/nologin or /bin/false for all the users that don't need to login.

Run
Code:
w
to see the list of people logged in and from where they did it. See if this is an ssh session, and if so kill them. Disable root ssh access and shut it down unless you absolutely need it. And please explain what you mean by you can write messages to each other? If these are wall/broadcast messages then you have a true problem. I assume that they are not IM messages from gaim/kopete.
_________________
/earth: file system full.
Back to top
View user's profile Send private message
Snappi
Tux's lil' helper
Tux's lil' helper


Joined: 20 Oct 2003
Posts: 113

PostPosted: Sat Nov 18, 2006 9:30 pm    Post subject: Reply with quote

/var/log files
Code:
localhost log # ls -ls
total 3980
  28 -rw-r--r-- 1 root    root      28231 Nov 18 14:09 Xorg.0.log
  28 -rw-r--r-- 1 root    root      28208 Nov 18 11:12 Xorg.0.log.old
  28 -rw-r--r-- 1 root    root      28012 Nov  8 20:34 Xorg.8.log
  28 -rw-r--r-- 1 root    root      27910 Nov  8 20:31 Xorg.8.log.old
  20 -rw-r----- 1 root    root      18179 Nov 18 13:32 dmesg
 360 -rw-rw---- 1 portage portage  360735 Nov 18 16:54 emerge.log
   8 -rw------- 1 root    root      32032 Nov 17 18:28 faillog
  28 -rw-r--r-- 1 root    root      28523 Nov 18 13:32 kdm.log
  20 -rw-r--r-- 1 root    root     292292 Nov 18 13:32 lastlog
3092 -rw------- 1 root    root    3160813 Nov 18 21:57 messages
   4 drwxr-xr-x 2 root    root       4096 Aug  3 11:22 news
   4 drwxrwx--- 2 root    portage    4096 Nov 12 16:00 sandbox
 332 -rw-rw-r-- 1 root    utmp     332160 Nov 18 13:32 wtmp


They only one I think is relevant is messages but I don't know, pls correct me if it's so. the problem is it contains 19000 lines. but I post todays log when I think he had access,

Code:
Nov 18 13:32:11 localhost syslog-ng[5093]: syslog-ng version 1.6.11 starting
Nov 18 13:32:11 localhost syslog-ng[5093]: Changing permissions on special file /dev/tty12
Nov 18 13:32:11 localhost Bootdata ok (command line is root=/dev/sda7)
Nov 18 13:32:11 localhost Linux version 2.6.17-gentoo-r8 (root@localhost) (gcc version 4.1.1 (Gentoo 4.1.1-r2)) #7 Fri Nov 17 23:26:10 CET 2006
Nov 18 13:32:11 localhost BIOS-provided physical RAM map:
Nov 18 13:32:11 localhost BIOS-e820: 0000000000000000 - 000000000009f800 (usable)
Nov 18 13:32:11 localhost BIOS-e820: 000000000009f800 - 00000000000a0000 (reserved)
Nov 18 13:32:11 localhost BIOS-e820: 00000000000f0000 - 0000000000100000 (reserved)
Nov 18 13:32:11 localhost BIOS-e820: 0000000000100000 - 000000003fff0000 (usable)
Nov 18 13:32:11 localhost BIOS-e820: 000000003fff0000 - 000000003fff3000 (ACPI NVS)
Nov 18 13:32:11 localhost BIOS-e820: 000000003fff3000 - 0000000040000000 (ACPI data)
Nov 18 13:32:11 localhost BIOS-e820: 00000000e0000000 - 00000000f0000000 (reserved)
Nov 18 13:32:11 localhost BIOS-e820: 00000000fec00000 - 0000000100000000 (reserved)
Nov 18 13:32:11 localhost DMI 2.3 present.
Nov 18 13:32:11 localhost ACPI: RSDP (v000 Nvidia                                ) @ 0x00000000000f9240
Nov 18 13:32:11 localhost ACPI: RSDT (v001 Nvidia AWRDACPI 0x42302e31 AWRD 0x00000000) @ 0x000000003fff3040
Nov 18 13:32:11 localhost ACPI: FADT (v001 Nvidia AWRDACPI 0x42302e31 AWRD 0x00000000) @ 0x000000003fff30c0
Nov 18 13:32:11 localhost ACPI: SSDT (v001 PTLTD  POWERNOW 0x00000001  LTP 0x00000001) @ 0x000000003fff9700
Nov 18 13:32:11 localhost ACPI: SRAT (v001 AMD    HAMMER   0x00000001 AMD  0x00000001) @ 0x000000003fff9840
Nov 18 13:32:11 localhost ACPI: MCFG (v001 Nvidia AWRDACPI 0x42302e31 AWRD 0x00000000) @ 0x000000003fff9940
Nov 18 13:32:11 localhost ACPI: MADT (v001 Nvidia AWRDACPI 0x42302e31 AWRD 0x00000000) @ 0x000000003fff9600
Nov 18 13:32:11 localhost ACPI: DSDT (v001 NVIDIA AWRDACPI 0x00001000 MSFT 0x0100000e) @ 0x0000000000000000
Nov 18 13:32:11 localhost On node 0 totalpages: 256918
Nov 18 13:32:11 localhost DMA zone: 2413 pages, LIFO batch:0
Nov 18 13:32:11 localhost DMA32 zone: 254505 pages, LIFO batch:31
Nov 18 13:32:11 localhost Nvidia board detected. Ignoring ACPI timer override.
Nov 18 13:32:11 localhost ACPI: PM-Timer IO Port: 0x4008
Nov 18 13:32:11 localhost ACPI: Local APIC address 0xfee00000
Nov 18 13:32:11 localhost ACPI: LAPIC (acpi_id[0x00] lapic_id[0x00] enabled)
Nov 18 13:32:11 localhost Processor #0 15:7 APIC version 16
Nov 18 13:32:11 localhost ACPI: LAPIC (acpi_id[0x01] lapic_id[0x01] disabled)
Nov 18 13:32:11 localhost ACPI: LAPIC (acpi_id[0x02] lapic_id[0x02] disabled)
Nov 18 13:32:11 localhost ACPI: LAPIC (acpi_id[0x03] lapic_id[0x03] disabled)
Nov 18 13:32:11 localhost ACPI: LAPIC_NMI (acpi_id[0x00] high edge lint[0x1])
Nov 18 13:32:11 localhost ACPI: LAPIC_NMI (acpi_id[0x01] high edge lint[0x1])
Nov 18 13:32:11 localhost ACPI: LAPIC_NMI (acpi_id[0x02] high edge lint[0x1])
Nov 18 13:32:11 localhost ACPI: LAPIC_NMI (acpi_id[0x03] high edge lint[0x1])
Nov 18 13:32:11 localhost ACPI: IOAPIC (id[0x04] address[0xfec00000] gsi_base[0])
Nov 18 13:32:11 localhost IOAPIC[0]: apic_id 4, version 17, address 0xfec00000, GSI 0-23
Nov 18 13:32:11 localhost ACPI: INT_SRC_OVR (bus 0 bus_irq 9 global_irq 9 high level)
Nov 18 13:32:11 localhost ACPI: INT_SRC_OVR (bus 0 bus_irq 14 global_irq 14 high edge)
Nov 18 13:32:11 localhost ACPI: INT_SRC_OVR (bus 0 bus_irq 15 global_irq 15 high edge)
Nov 18 13:32:11 localhost ACPI: IRQ9 used by override.
Nov 18 13:32:11 localhost ACPI: IRQ14 used by override.
Nov 18 13:32:11 localhost ACPI: IRQ15 used by override.
Nov 18 13:32:11 localhost Setting APIC routing to flat
Nov 18 13:32:11 localhost Using ACPI (MADT) for SMP configuration information
Nov 18 13:32:11 localhost Allocating PCI resources starting at 50000000 (gap: 40000000:a0000000)
Nov 18 13:32:11 localhost Checking aperture...
Nov 18 13:32:11 localhost CPU 0: aperture @ 203a000000 size 32 MB
Nov 18 13:32:11 localhost Aperture from northbridge cpu 0 too small (32 MB)
Nov 18 13:32:11 localhost No AGP bridge found
Nov 18 13:32:11 localhost Built 1 zonelists
Nov 18 13:32:11 localhost Kernel command line: root=/dev/sda7
Nov 18 13:32:11 localhost Initializing CPU#0
Nov 18 13:32:11 localhost PID hash table entries: 4096 (order: 12, 32768 bytes)
Nov 18 13:32:11 localhost time.c: Using 3.579545 MHz WALL PM GTOD PIT/TSC timer.
Nov 18 13:32:11 localhost time.c: Detected 2211.351 MHz processor.
Nov 18 13:32:11 localhost Console: colour VGA+ 80x25
Nov 18 13:32:11 localhost Dentry cache hash table entries: 131072 (order: 8, 1048576 bytes)
Nov 18 13:32:11 localhost Inode-cache hash table entries: 65536 (order: 7, 524288 bytes)
Nov 18 13:32:11 localhost Memory: 1025432k/1048512k available (2794k kernel code, 22312k reserved, 1492k data, 188k init)
Nov 18 13:32:11 localhost Calibrating delay using timer specific routine.. 4425.34 BogoMIPS (lpj=8850684)
Nov 18 13:32:11 localhost Mount-cache hash table entries: 256
Nov 18 13:32:11 localhost CPU: L1 I Cache: 64K (64 bytes/line), D cache 64K (64 bytes/line)
Nov 18 13:32:11 localhost CPU: L2 Cache: 1024K (64 bytes/line)
Nov 18 13:32:11 localhost CPU: AMD Athlon(tm) 64 Processor 3700+ stepping 01
Nov 18 13:32:11 localhost Using local APIC timer interrupts.
Nov 18 13:32:11 localhost result 12564516
Nov 18 13:32:11 localhost Detected 12.564 MHz APIC timer.
Nov 18 13:32:11 localhost testing NMI watchdog ... OK.
Nov 18 13:32:11 localhost NET: Registered protocol family 16
Nov 18 13:32:11 localhost ACPI: bus type pci registered
Nov 18 13:32:11 localhost PCI: Using MMCONFIG at e0000000
Nov 18 13:32:11 localhost PCI: No mmconfig possible on device 0:18
Nov 18 13:32:11 localhost ACPI: Subsystem revision 20060127
Nov 18 13:32:11 localhost ACPI: Interpreter enabled
Nov 18 13:32:11 localhost ACPI: Using IOAPIC for interrupt routing
Nov 18 13:32:11 localhost ACPI: PCI Root Bridge [PCI0] (0000:00)
Nov 18 13:32:11 localhost PCI: Probing PCI hardware (bus 00)
Nov 18 13:32:11 localhost PCI: Transparent bridge - 0000:00:09.0
Nov 18 13:32:11 localhost Boot video device is 0000:05:00.0
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Routing Table [\_SB_.PCI0._PRT]
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Routing Table [\_SB_.PCI0.HUB0._PRT]
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LNK1] (IRQs 3 4 5 7 9 10 11 12 14 15) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LNK2] (IRQs 3 4 5 7 9 10 11 12 14 15) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LNK3] (IRQs 3 4 *5 7 9 10 11 12 14 15)
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LNK4] (IRQs 3 4 *5 7 9 10 11 12 14 15)
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LNK5] (IRQs 3 4 5 7 9 10 11 12 14 15) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LUBA] (IRQs 3 4 5 7 9 10 *11 12 14 15)
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LUBB] (IRQs 3 4 5 7 9 10 11 12 14 15) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LMAC] (IRQs 3 4 5 7 9 10 *11 12 14 15)
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LACI] (IRQs *3 4 5 7 9 10 11 12 14 15)
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LMCI] (IRQs 3 4 5 7 9 *10 11 12 14 15)
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LSMB] (IRQs 3 4 5 7 9 *10 11 12 14 15)
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LUB2] (IRQs *3 4 5 7 9 10 11 12 14 15)
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LIDE] (IRQs 3 4 5 7 9 10 11 12 14 15) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LSID] (IRQs 3 4 5 7 9 *10 11 12 14 15)
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LFID] (IRQs 3 4 5 7 9 10 *11 12 14 15)
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [LPCA] (IRQs 3 4 5 7 9 10 11 12 14 15) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APC1] (IRQs 16) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APC2] (IRQs 17) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APC3] (IRQs 18) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APC4] (IRQs 19) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APC5] (IRQs *16), disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APCF] (IRQs 20 21 22 23) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APCG] (IRQs 20 21 22 23) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APCH] (IRQs 20 21 22 23) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APCJ] (IRQs 20 21 22 23) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APCK] (IRQs 20 21 22 23) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APCS] (IRQs 20 21 22 23) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APCL] (IRQs 20 21 22 23) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APCZ] (IRQs 20 21 22 23) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APSI] (IRQs 20 21 22 23) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APSJ] (IRQs 20 21 22 23) *0, disabled.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APCP] (IRQs 20 21 22 23) *0, disabled.
Nov 18 13:32:11 localhost SCSI subsystem initialized
Nov 18 13:32:11 localhost usbcore: registered new driver usbfs
Nov 18 13:32:11 localhost usbcore: registered new driver hub
Nov 18 13:32:11 localhost PCI: Using ACPI for IRQ routing
Nov 18 13:32:11 localhost PCI: If a device doesn't work, try "pci=routeirq".  If it helps, post a report
Nov 18 13:32:11 localhost PCI-DMA: Disabling IOMMU.
Nov 18 13:32:11 localhost PCI: Bridge: 0000:00:09.0
Nov 18 13:32:11 localhost IO window: a000-afff
Nov 18 13:32:11 localhost MEM window: fde00000-fdefffff
Nov 18 13:32:11 localhost PREFETCH window: fdf00000-fdffffff
Nov 18 13:32:11 localhost PCI: Bridge: 0000:00:0b.0
Nov 18 13:32:11 localhost IO window: 9000-9fff
Nov 18 13:32:11 localhost MEM window: fdd00000-fddfffff
Nov 18 13:32:11 localhost PREFETCH window: fdc00000-fdcfffff
Nov 18 13:32:11 localhost PCI: Bridge: 0000:00:0c.0
Nov 18 13:32:11 localhost IO window: 8000-8fff
Nov 18 13:32:11 localhost MEM window: fdb00000-fdbfffff
Nov 18 13:32:11 localhost PREFETCH window: fda00000-fdafffff
Nov 18 13:32:11 localhost PCI: Bridge: 0000:00:0d.0
Nov 18 13:32:11 localhost IO window: 7000-7fff
Nov 18 13:32:11 localhost MEM window: fd900000-fd9fffff
Nov 18 13:32:11 localhost PREFETCH window: fd800000-fd8fffff
Nov 18 13:32:11 localhost PCI: Bridge: 0000:00:0e.0
Nov 18 13:32:11 localhost IO window: 6000-6fff
Nov 18 13:32:11 localhost MEM window: fa000000-fcffffff
Nov 18 13:32:11 localhost PREFETCH window: d0000000-dfffffff
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:00:09.0 to 64
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:00:0b.0 to 64
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:00:0c.0 to 64
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:00:0d.0 to 64
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:00:0e.0 to 64
Nov 18 13:32:11 localhost NET: Registered protocol family 2
Nov 18 13:32:11 localhost IP route cache hash table entries: 32768 (order: 6, 262144 bytes)
Nov 18 13:32:11 localhost TCP established hash table entries: 131072 (order: 8, 1048576 bytes)
Nov 18 13:32:11 localhost TCP bind hash table entries: 65536 (order: 7, 524288 bytes)
Nov 18 13:32:11 localhost TCP: Hash tables configured (established 131072 bind 65536)
Nov 18 13:32:11 localhost TCP reno registered
Nov 18 13:32:11 localhost IA32 emulation $Id: sys_ia32.c,v 1.32 2002/03/24 13:02:28 ak Exp $
Nov 18 13:32:11 localhost Total HugeTLB memory allocated, 0
Nov 18 13:32:11 localhost Installing knfsd (copyright (C) 1996 okir@monad.swb.de).
Nov 18 13:32:11 localhost io scheduler noop registered
Nov 18 13:32:11 localhost io scheduler deadline registered
Nov 18 13:32:11 localhost io scheduler cfq registered (default)
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:00:0b.0 to 64
Nov 18 13:32:11 localhost pcie_portdrv_probe->Dev[005d:10de] has invalid IRQ. Check vendor BIOS
Nov 18 13:32:11 localhost assign_interrupt_mode Found MSI capability
Nov 18 13:32:11 localhost Allocate Port Service[0000:00:0b.0:pcie00]
Nov 18 13:32:11 localhost Allocate Port Service[0000:00:0b.0:pcie03]
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:00:0c.0 to 64
Nov 18 13:32:11 localhost pcie_portdrv_probe->Dev[005d:10de] has invalid IRQ. Check vendor BIOS
Nov 18 13:32:11 localhost assign_interrupt_mode Found MSI capability
Nov 18 13:32:11 localhost Allocate Port Service[0000:00:0c.0:pcie00]
Nov 18 13:32:11 localhost Allocate Port Service[0000:00:0c.0:pcie03]
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:00:0d.0 to 64
Nov 18 13:32:11 localhost pcie_portdrv_probe->Dev[005d:10de] has invalid IRQ. Check vendor BIOS
Nov 18 13:32:11 localhost assign_interrupt_mode Found MSI capability
Nov 18 13:32:11 localhost Allocate Port Service[0000:00:0d.0:pcie00]
Nov 18 13:32:11 localhost Allocate Port Service[0000:00:0d.0:pcie03]
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:00:0e.0 to 64
Nov 18 13:32:11 localhost pcie_portdrv_probe->Dev[005d:10de] has invalid IRQ. Check vendor BIOS
Nov 18 13:32:11 localhost assign_interrupt_mode Found MSI capability
Nov 18 13:32:11 localhost Allocate Port Service[0000:00:0e.0:pcie00]
Nov 18 13:32:11 localhost Allocate Port Service[0000:00:0e.0:pcie03]
Nov 18 13:32:11 localhost Real Time Clock Driver v1.12ac
Nov 18 13:32:11 localhost Software Watchdog Timer: 0.07 initialized. soft_noboot=0 soft_margin=60 sec (nowayout= 0)
Nov 18 13:32:11 localhost Linux agpgart interface v0.101 (c) Dave Jones
Nov 18 13:32:11 localhost ACPI: Power Button (FF) [PWRF]
Nov 18 13:32:11 localhost ACPI: Power Button (CM) [PWRB]
Nov 18 13:32:11 localhost ACPI: Fan [FAN] (on)
Nov 18 13:32:11 localhost ACPI: Thermal Zone [THRM] (22 C)
Nov 18 13:32:11 localhost Serial: 8250/16550 driver $Revision: 1.90 $ 4 ports, IRQ sharing disabled
Nov 18 13:32:11 localhost serial8250: ttyS0 at I/O 0x3f8 (irq = 4) is a 16550A
Nov 18 13:32:11 localhost serio: i8042 AUX port at 0x60,0x64 irq 12
Nov 18 13:32:11 localhost serio: i8042 KBD port at 0x60,0x64 irq 1
Nov 18 13:32:11 localhost mice: PS/2 mouse device common for all mice
Nov 18 13:32:11 localhost FDC 0 is a post-1991 82077
Nov 18 13:32:11 localhost RAMDISK driver initialized: 16 RAM disks of 4096K size 1024 blocksize
Nov 18 13:32:11 localhost loop: loaded (max 8 devices)
Nov 18 13:32:11 localhost Intel(R) PRO/1000 Network Driver - version 7.1.9-k4
Nov 18 13:32:11 localhost Copyright (c) 1999-2006 Intel Corporation.
Nov 18 13:32:11 localhost e100: Intel(R) PRO/100 Network Driver, 3.5.10-k2-NAPI
Nov 18 13:32:11 localhost e100: Copyright(c) 1999-2005 Intel Corporation
Nov 18 13:32:11 localhost forcedeth.c: Reverse Engineered nForce ethernet driver. Version 0.54.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APCH] enabled at IRQ 23
Nov 18 13:32:11 localhost GSI 16 sharing vector 0xD9 and IRQ 16
Nov 18 13:32:11 localhost ACPI: PCI Interrupt 0000:00:0a.0[A] -> Link [APCH] -> GSI 23 (level, low) -> IRQ 217
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:00:0a.0 to 64
Nov 18 13:32:11 localhost forcedeth: using HIGHDMA
Nov 18 13:32:11 localhost eth0: forcedeth.c: subsystem: 01462:7125 bound to 0000:00:0a.0
Nov 18 13:32:11 localhost tun: Universal TUN/TAP device driver, 1.6
Nov 18 13:32:11 localhost tun: (C) 1999-2004 Max Krasnyansky <maxk@qualcomm.com>
Nov 18 13:32:11 localhost netconsole: not configured, aborting
Nov 18 13:32:11 localhost Uniform Multi-Platform E-IDE driver Revision: 7.00alpha2
Nov 18 13:32:11 localhost ide: Assuming 33MHz system bus speed for PIO modes; override with idebus=xx
Nov 18 13:32:11 localhost NFORCE-CK804: IDE controller at PCI slot 0000:00:06.0
Nov 18 13:32:11 localhost NFORCE-CK804: chipset revision 242
Nov 18 13:32:11 localhost NFORCE-CK804: not 100% native mode: will probe irqs later
Nov 18 13:32:11 localhost NFORCE-CK804: 0000:00:06.0 (rev f2) UDMA133 controller
Nov 18 13:32:11 localhost ide0: BM-DMA at 0xe000-0xe007, BIOS settings: hda:DMA, hdb:DMA
Nov 18 13:32:11 localhost ide1: BM-DMA at 0xe008-0xe00f, BIOS settings: hdc:DMA, hdd:DMA
Nov 18 13:32:11 localhost Probing IDE interface ide0...
Nov 18 13:32:11 localhost Probing IDE interface ide1...
Nov 18 13:32:11 localhost hdc: HL-DT-STDVDRRW GWA-4164B, ATAPI CD/DVD-ROM drive
Nov 18 13:32:11 localhost ide1 at 0x170-0x177,0x376 on irq 15
Nov 18 13:32:11 localhost Probing IDE interface ide0...
Nov 18 13:32:11 localhost hdc: ATAPI 40X DVD-ROM DVD-R CD-R/RW drive, 2048kB Cache, UDMA(33)
Nov 18 13:32:11 localhost Uniform CD-ROM driver Revision: 3.20
Nov 18 13:32:11 localhost megaraid cmm: 2.20.2.6 (Release Date: Mon Mar 7 00:01:03 EST 2005)
Nov 18 13:32:11 localhost megaraid: 2.20.4.8 (Release Date: Mon Apr 11 12:27:22 EST 2006)
Nov 18 13:32:11 localhost megasas: 00.00.02.04 Fri Feb 03 14:31:44 PST 2006
Nov 18 13:32:11 localhost libata version 1.20 loaded.
Nov 18 13:32:11 localhost sata_nv 0000:00:07.0: version 0.8
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APSI] enabled at IRQ 22
Nov 18 13:32:11 localhost GSI 17 sharing vector 0xE1 and IRQ 17
Nov 18 13:32:11 localhost ACPI: PCI Interrupt 0000:00:07.0[A] -> Link [APSI] -> GSI 22 (level, low) -> IRQ 225
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:00:07.0 to 64
Nov 18 13:32:11 localhost ata1: SATA max UDMA/133 cmd 0x9F0 ctl 0xBF2 bmdma 0xCC00 irq 225
Nov 18 13:32:11 localhost ata2: SATA max UDMA/133 cmd 0x970 ctl 0xB72 bmdma 0xCC08 irq 225
Nov 18 13:32:11 localhost ata1: SATA link up 3.0 Gbps (SStatus 123)
Nov 18 13:32:11 localhost ata1: dev 0 cfg 49:2f00 82:746b 83:7f01 84:4023 85:7469 86:3c01 87:4023 88:40ff
Nov 18 13:32:11 localhost ata1: dev 0 ATA-7, max UDMA7, 488397168 sectors: LBA48
Nov 18 13:32:11 localhost nv_sata: Primary device added
Nov 18 13:32:11 localhost nv_sata: Primary device removed
Nov 18 13:32:11 localhost nv_sata: Secondary device added
Nov 18 13:32:11 localhost nv_sata: Secondary device removed
Nov 18 13:32:11 localhost ata1: dev 0 configured for UDMA/133
Nov 18 13:32:11 localhost scsi0 : sata_nv
Nov 18 13:32:11 localhost ata2: SATA link down (SStatus 0)
Nov 18 13:32:11 localhost scsi1 : sata_nv
Nov 18 13:32:11 localhost Vendor: ATA       Model: SAMSUNG SP2504C   Rev: VT10
Nov 18 13:32:11 localhost Type:   Direct-Access                      ANSI SCSI revision: 05
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APSJ] enabled at IRQ 21
Nov 18 13:32:11 localhost GSI 18 sharing vector 0xE9 and IRQ 18
Nov 18 13:32:11 localhost ACPI: PCI Interrupt 0000:00:08.0[A] -> Link [APSJ] -> GSI 21 (level, low) -> IRQ 233
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:00:08.0 to 64
Nov 18 13:32:11 localhost ata3: SATA max UDMA/133 cmd 0x9E0 ctl 0xBE2 bmdma 0xB800 irq 233
Nov 18 13:32:11 localhost ata4: SATA max UDMA/133 cmd 0x960 ctl 0xB62 bmdma 0xB808 irq 233
Nov 18 13:32:11 localhost ata3: SATA link down (SStatus 0)
Nov 18 13:32:11 localhost scsi2 : sata_nv
Nov 18 13:32:11 localhost ata4: SATA link down (SStatus 0)
Nov 18 13:32:11 localhost scsi3 : sata_nv
Nov 18 13:32:11 localhost SCSI device sda: 488397168 512-byte hdwr sectors (250059 MB)
Nov 18 13:32:11 localhost sda: Write Protect is off
Nov 18 13:32:11 localhost sda: Mode Sense: 00 3a 00 00
Nov 18 13:32:11 localhost SCSI device sda: drive cache: write back
Nov 18 13:32:11 localhost SCSI device sda: 488397168 512-byte hdwr sectors (250059 MB)
Nov 18 13:32:11 localhost sda: Write Protect is off
Nov 18 13:32:11 localhost sda: Mode Sense: 00 3a 00 00
Nov 18 13:32:11 localhost SCSI device sda: drive cache: write back
Nov 18 13:32:11 localhost sda: sda1 < sda5 sda6 sda7 > sda2 sda3
Nov 18 13:32:11 localhost sd 0:0:0:0: Attached scsi disk sda
Nov 18 13:32:11 localhost Fusion MPT base driver 3.03.09
Nov 18 13:32:11 localhost Copyright (c) 1999-2005 LSI Logic Corporation
Nov 18 13:32:11 localhost Fusion MPT SPI Host driver 3.03.09
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APC4] enabled at IRQ 19
Nov 18 13:32:11 localhost GSI 19 sharing vector 0x32 and IRQ 19
Nov 18 13:32:11 localhost ACPI: PCI Interrupt 0000:01:0c.0[A] -> Link [APC4] -> GSI 19 (level, low) -> IRQ 50
Nov 18 13:32:11 localhost PCI: VIA IRQ fixup for 0000:01:0c.0, from 5 to 2
Nov 18 13:32:11 localhost ohci1394: fw-host0: OHCI-1394 1.0 (PCI): IRQ=[50]  MMIO=[fdeff000-fdeff7ff]  Max Packet=[2048]  IR/IT contexts=[4/8]
Nov 18 13:32:11 localhost ieee1394: raw1394: /dev/raw1394 device initialized
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APCL] enabled at IRQ 20
Nov 18 13:32:11 localhost GSI 20 sharing vector 0x3A and IRQ 20
Nov 18 13:32:11 localhost ACPI: PCI Interrupt 0000:00:02.1[B] -> Link [APCL] -> GSI 20 (level, low) -> IRQ 58
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:00:02.1 to 64
Nov 18 13:32:11 localhost ehci_hcd 0000:00:02.1: EHCI Host Controller
Nov 18 13:32:11 localhost ehci_hcd 0000:00:02.1: new USB bus registered, assigned bus number 1
Nov 18 13:32:11 localhost ehci_hcd 0000:00:02.1: debug port 1
Nov 18 13:32:11 localhost PCI: cache line size of 64 is not supported by device 0000:00:02.1
Nov 18 13:32:11 localhost ehci_hcd 0000:00:02.1: irq 58, io mem 0xfeb00000
Nov 18 13:32:11 localhost ehci_hcd 0000:00:02.1: USB 2.0 started, EHCI 1.00, driver 10 Dec 2004
Nov 18 13:32:11 localhost usb usb1: configuration #1 chosen from 1 choice
Nov 18 13:32:11 localhost hub 1-0:1.0: USB hub found
Nov 18 13:32:11 localhost hub 1-0:1.0: 10 ports detected
Nov 18 13:32:11 localhost ohci_hcd: 2005 April 22 USB 1.1 'Open' Host Controller (OHCI) Driver (PCI)
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APCF] enabled at IRQ 23
Nov 18 13:32:11 localhost ACPI: PCI Interrupt 0000:00:02.0[A] -> Link [APCF] -> GSI 23 (level, low) -> IRQ 217
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:00:02.0 to 64
Nov 18 13:32:11 localhost ohci_hcd 0000:00:02.0: OHCI Host Controller
Nov 18 13:32:11 localhost ohci_hcd 0000:00:02.0: new USB bus registered, assigned bus number 2
Nov 18 13:32:11 localhost ohci_hcd 0000:00:02.0: irq 217, io mem 0xfe02f000
Nov 18 13:32:11 localhost usb usb2: configuration #1 chosen from 1 choice
Nov 18 13:32:11 localhost hub 2-0:1.0: USB hub found
Nov 18 13:32:11 localhost hub 2-0:1.0: 10 ports detected
Nov 18 13:32:11 localhost USB Universal Host Controller Interface driver v3.0
Nov 18 13:32:11 localhost Initializing USB Mass Storage driver...
Nov 18 13:32:11 localhost usb 1-3: new high speed USB device using ehci_hcd and address 3
Nov 18 13:32:11 localhost ieee1394: Host added: ID:BUS[0-00:1023]  GUID[0010dc0000cc4fa5]
Nov 18 13:32:11 localhost hub 1-0:1.0: Cannot enable port 3.  Maybe the USB cable is bad?
Nov 18 13:32:11 localhost hub 1-0:1.0: Cannot enable port 3.  Maybe the USB cable is bad?
Nov 18 13:32:11 localhost usb 1-3: new high speed USB device using ehci_hcd and address 5
Nov 18 13:32:11 localhost usb 1-3: device not accepting address 5, error -71
Nov 18 13:32:11 localhost usb 1-3: new high speed USB device using ehci_hcd and address 6
Nov 18 13:32:11 localhost usb 1-3: device not accepting address 6, error -71
Nov 18 13:32:11 localhost usb 2-2: new low speed USB device using ohci_hcd and address 2
Nov 18 13:32:11 localhost usb 2-2: configuration #1 chosen from 1 choice
Nov 18 13:32:11 localhost usb 2-9: new low speed USB device using ohci_hcd and address 3
Nov 18 13:32:11 localhost usb 2-9: configuration #1 chosen from 1 choice
Nov 18 13:32:11 localhost usbcore: registered new driver usb-storage
Nov 18 13:32:11 localhost USB Mass Storage support registered.
Nov 18 13:32:11 localhost input: G-Tech CHINA    USB Wireless Mouse & KeyBoard V1.01   as /class/input/input0
Nov 18 13:32:11 localhost input: USB HID v1.00 Keyboard [G-Tech CHINA    USB Wireless Mouse & KeyBoard V1.01  ] on usb-0000:00:02.0-2
Nov 18 13:32:11 localhost input: G-Tech CHINA    USB Wireless Mouse & KeyBoard V1.01   as /class/input/input1
Nov 18 13:32:11 localhost input: USB HID v1.00 Mouse [G-Tech CHINA    USB Wireless Mouse & KeyBoard V1.01  ] on usb-0000:00:02.0-2
Nov 18 13:32:11 localhost input: Microsoft Microsoft IntelliMouse® Optical as /class/input/input2
Nov 18 13:32:11 localhost input: USB HID v1.00 Mouse [Microsoft Microsoft IntelliMouse® Optical] on usb-0000:00:02.0-9
Nov 18 13:32:11 localhost usbcore: registered new driver usbhid
Nov 18 13:32:11 localhost drivers/usb/input/hid-core.c: v2.6:USB HID core driver
Nov 18 13:32:11 localhost device-mapper: 4.6.0-ioctl (2006-02-17) initialised: dm-devel@redhat.com
Nov 18 13:32:11 localhost Intel 810 + AC97 Audio, version 1.01, 23:24:46 Nov 17 2006
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APCJ] enabled at IRQ 22
Nov 18 13:32:11 localhost ACPI: PCI Interrupt 0000:00:04.0[A] -> Link [APCJ] -> GSI 22 (level, low) -> IRQ 225
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:00:04.0 to 64
Nov 18 13:32:11 localhost i810: NVIDIA nForce Audio found at IO 0xec00 and 0xf000, MEM 0x0000 and 0x0000, IRQ 225
Nov 18 13:32:11 localhost i810_audio: Audio Controller supports 6 channels.
Nov 18 13:32:11 localhost i810_audio: Defaulting to base 2 channel mode.
Nov 18 13:32:11 localhost i810_audio: Resetting connection 0
Nov 18 13:32:11 localhost ac97_codec: AC97  codec, id: ALG144 (Unknown)
Nov 18 13:32:11 localhost i810_audio: only 48Khz playback available.
Nov 18 13:32:11 localhost i810_audio: AC'97 codec 0 Unable to map surround DAC's (or DAC's not present), total channels = 2
Nov 18 13:32:11 localhost oprofile: using NMI interrupt.
Nov 18 13:32:11 localhost ip_conntrack version 2.4 (4095 buckets, 32760 max) - 280 bytes per conntrack
Nov 18 13:32:11 localhost TCP bic registered
Nov 18 13:32:11 localhost NET: Registered protocol family 1
Nov 18 13:32:11 localhost NET: Registered protocol family 10
Nov 18 13:32:11 localhost IPv6 over IPv4 tunneling driver
Nov 18 13:32:11 localhost NET: Registered protocol family 17
Nov 18 13:32:11 localhost powernow-k8: Found 1 AMD Athlon 64 / Opteron processors (version 1.60.2)
Nov 18 13:32:11 localhost powernow-k8:    0 : fid 0xe (2200 MHz), vid 0x6 (1400 mV)
Nov 18 13:32:11 localhost powernow-k8:    1 : fid 0xc (2000 MHz), vid 0x8 (1350 mV)
Nov 18 13:32:11 localhost powernow-k8:    2 : fid 0xa (1800 MHz), vid 0xa (1300 mV)
Nov 18 13:32:11 localhost powernow-k8:    3 : fid 0x2 (1000 MHz), vid 0x12 (1100 mV)
Nov 18 13:32:11 localhost cpu_init done, current fid 0xe, vid 0x6
Nov 18 13:32:11 localhost ACPI wakeup devices:
Nov 18 13:32:11 localhost HUB0 XVR0 XVR1 XVR2 XVR3 USB0 USB2 MMAC MMCI UAR1
Nov 18 13:32:11 localhost ACPI: (supports S0 S3 S4 S5)
Nov 18 13:32:11 localhost VFS: Mounted root (ext2 filesystem) readonly.
Nov 18 13:32:11 localhost Freeing unused kernel memory: 188k freed
Nov 18 13:32:11 localhost nvidia: module license 'NVIDIA' taints kernel.
Nov 18 13:32:11 localhost ACPI: PCI Interrupt Link [APC3] enabled at IRQ 18
Nov 18 13:32:11 localhost GSI 21 sharing vector 0x42 and IRQ 21
Nov 18 13:32:11 localhost ACPI: PCI Interrupt 0000:05:00.0[A] -> Link [APC3] -> GSI 18 (level, low) -> IRQ 66
Nov 18 13:32:11 localhost PCI: Setting latency timer of device 0000:05:00.0 to 64
Nov 18 13:32:11 localhost NVRM: loading NVIDIA Linux x86_64 Kernel Module  1.0-9629  Wed Nov  1 19:27:33 PST 2006
Nov 18 13:32:11 localhost ip_tables: (C) 2000-2006 Netfilter Core Team
Nov 18 13:32:11 localhost Adding 506008k swap on /dev/sda6.  Priority:-1 extents:1 across:506008k
Nov 18 13:32:18 localhost cron[6087]: (CRON) STARTUP (V5.0)
Nov 18 13:32:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9846 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:32:22 localhost eth0: no IPv6 routers present
Nov 18 13:32:26 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=24.87.27.75 DST=192.168.0.99 LEN=40 TOS=0x00 PREC=0x00 TTL=238 ID=17678 PROTO=TCP SPT=1379 DPT=54070 WINDOW=0 RES=0x00 RST URGP=0
Nov 18 13:32:29 localhost kdm: :0[5665]: pam_unix(kde:session): session opened for user sim by (uid=0)
Nov 18 13:32:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9847 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:32:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9848 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:33:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9849 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:33:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9850 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:33:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9851 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:33:35 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=82.237.132.209 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=60778 DF PROTO=TCP SPT=3059 DPT=54070 WINDOW=64240 RES=0x00 SYN URGP=0
Nov 18 13:33:38 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=82.237.132.209 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=60875 DF PROTO=TCP SPT=3059 DPT=54070 WINDOW=64240 RES=0x00 SYN URGP=0
Nov 18 13:33:44 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=82.237.132.209 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=61094 DF PROTO=TCP SPT=3059 DPT=54070 WINDOW=64240 RES=0x00 SYN URGP=0
Nov 18 13:33:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9852 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:34:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9853 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:34:19 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=82.237.132.209 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=63117 DF PROTO=TCP SPT=3167 DPT=54070 WINDOW=64240 RES=0x00 SYN URGP=0
Nov 18 13:34:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9854 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:34:22 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=82.237.132.209 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=63194 DF PROTO=TCP SPT=3167 DPT=54070 WINDOW=64240 RES=0x00 SYN URGP=0
Nov 18 13:34:27 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=82.237.132.209 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=63402 DF PROTO=TCP SPT=3167 DPT=54070 WINDOW=64240 RES=0x00 SYN URGP=0
Nov 18 13:34:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9855 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:34:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9856 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:35:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9857 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:35:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9858 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:35:33 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=201.51.107.72 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=43113 DF PROTO=TCP SPT=2261 DPT=54070 WINDOW=64512 RES=0x00 SYN URGP=0
Nov 18 13:35:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9859 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:35:36 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=201.51.107.72 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=43184 DF PROTO=TCP SPT=2261 DPT=54070 WINDOW=64512 RES=0x00 SYN URGP=0
Nov 18 13:35:42 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=201.51.107.72 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=43332 DF PROTO=TCP SPT=2261 DPT=54070 WINDOW=64512 RES=0x00 SYN URGP=0
Nov 18 13:35:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9860 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:36:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9861 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:36:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9862 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:36:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9863 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:36:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9864 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:37:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9865 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:37:13 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=195.0.171.138 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=50774 DF PROTO=TCP SPT=33469 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:37:16 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=195.0.171.138 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=50864 DF PROTO=TCP SPT=33469 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:37:19 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=213.213.139.178 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=107 ID=7083 DF PROTO=TCP SPT=49174 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:37:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9866 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:37:21 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=213.213.139.178 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=107 ID=7139 DF PROTO=TCP SPT=49174 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:37:22 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=195.0.171.138 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=51066 DF PROTO=TCP SPT=33469 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:37:27 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=213.213.139.178 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=107 ID=7272 DF PROTO=TCP SPT=49174 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:37:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9867 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:37:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9868 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:38:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9869 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:38:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9870 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:38:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9871 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:38:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9872 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:39:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9873 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:39:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9874 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:39:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9875 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:39:38 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=195.0.171.138 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=55449 DF PROTO=TCP SPT=32792 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:39:41 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=195.0.171.138 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=55543 DF PROTO=TCP SPT=32792 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:39:47 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=195.0.171.138 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=55728 DF PROTO=TCP SPT=32792 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:39:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9876 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:39:59 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=154.20.50.177 DST=192.168.0.99 LEN=70 TOS=0x00 PREC=0x00 TTL=109 ID=6079 PROTO=UDP SPT=60032 DPT=54070 LEN=50
Nov 18 13:40:01 localhost cron[6305]: (root) CMD (test -x /usr/sbin/run-crons && /usr/sbin/run-crons )
Nov 18 13:40:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9877 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:40:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9878 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:40:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9879 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:40:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9880 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:41:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9881 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:41:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9882 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:41:31 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=41.223.244.245 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=112 ID=20388 DF PROTO=TCP SPT=2172 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:41:34 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=41.223.244.245 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=112 ID=20505 DF PROTO=TCP SPT=2172 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:41:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9883 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:41:40 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=41.223.244.245 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=112 ID=20716 DF PROTO=TCP SPT=2172 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:41:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9884 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:42:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9885 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:42:10 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=201.51.107.72 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=52930 DF PROTO=TCP SPT=2558 DPT=54070 WINDOW=64512 RES=0x00 SYN URGP=0
Nov 18 13:42:13 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=201.51.107.72 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=53002 DF PROTO=TCP SPT=2558 DPT=54070 WINDOW=64512 RES=0x00 SYN URGP=0
Nov 18 13:42:19 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=201.51.107.72 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=53149 DF PROTO=TCP SPT=2558 DPT=54070 WINDOW=64512 RES=0x00 SYN URGP=0
Nov 18 13:42:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9886 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:42:28 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=85.24.219.213 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=118 ID=41340 DF PROTO=TCP SPT=4629 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:42:31 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=85.24.219.213 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=118 ID=42058 DF PROTO=TCP SPT=4629 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:42:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9887 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:42:37 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=85.24.219.213 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=118 ID=43560 DF PROTO=TCP SPT=4629 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:42:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9888 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:43:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9889 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:43:14 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=24.87.27.75 DST=192.168.0.99 LEN=40 TOS=0x00 PREC=0x00 TTL=238 ID=1222 PROTO=TCP SPT=1648 DPT=54070 WINDOW=0 RES=0x00 RST URGP=0
Nov 18 13:43:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9890 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:43:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9891 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:43:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9892 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:44:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9893 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:44:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9894 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:44:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9895 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:44:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9896 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:44:53 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=82.72.156.147 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=50214 DF PROTO=TCP SPT=6881 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:44:56 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=82.72.156.147 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=50463 DF PROTO=TCP SPT=6881 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:45:02 localhost KMF: IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=82.72.156.147 DST=192.168.0.99 LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=51032 DF PROTO=TCP SPT=6881 DPT=54070 WINDOW=65535 RES=0x00 SYN URGP=0
Nov 18 13:45:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9897 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:45:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9898 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:45:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9899 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:45:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9900 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:46:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9901 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:46:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9902 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:46:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9903 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:46:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9904 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:47:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9905 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:47:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9906 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:47:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9907 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:47:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9908 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:48:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9909 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:48:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9910 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:48:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9911 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:48:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9912 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:49:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9913 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:49:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9914 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:49:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9915 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:49:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9916 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Back to top
View user's profile Send private message
Snappi
Tux's lil' helper
Tux's lil' helper


Joined: 20 Oct 2003
Posts: 113

PostPosted: Sat Nov 18, 2006 9:33 pm    Post subject: Reply with quote

Code:
Nov 18 13:50:01 localhost cron[6582]: (root) CMD (test -x /usr/sbin/run-crons && /usr/sbin/run-crons )
Nov 18 13:50:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9917 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:50:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9918 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:50:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9919 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:50:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9920 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:51:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9921 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:51:19 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9922 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:51:34 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9923 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:51:49 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9924 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:52:04 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9925 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:52:20 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9926 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:52:35 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9927 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:52:50 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9928 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:53:05 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9929 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:53:20 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9930 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:53:35 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9931 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:53:50 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9932 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:54:05 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9933 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:54:20 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9934 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:54:35 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9935 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:54:50 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9936 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:55:05 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9937 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:55:20 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9938 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:55:35 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9939 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:55:47 localhost su[6598]: Successful su for root by sim
Nov 18 13:55:47 localhost su[6598]: + pts/2 sim:root
Nov 18 13:55:47 localhost su[6598]: pam_unix(su:session): session opened for user root by (uid=1000)
Nov 18 13:55:50 localhost KMF: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:c0:71:36:86:5d:bd:08:00 SRC=192.168.0.63 DST=192.168.0.255 LEN=36 TOS=0x00 PREC=0x00 TTL=64 ID=9940 PROTO=UDP SPT=7335 DPT=7335 LEN=16
Nov 18 13:55:54 localhost (root-6606): starting (version 2.14.0), pid 6606 user 'root'
Nov 18 13:55:54 localhost (root-6606): Resolved address "xml:readonly:/etc/gconf/gconf.xml.mandatory" to a read-only configuration source at position 0
Nov 18 13:55:54 localhost (root-6606): Resolved address "xml:readwrite:/root/.gconf" to a writable configuration source at position 1
Nov 18 13:55:54 localhost (root-6606): Resolved address "xml:readonly:/etc/gconf/gconf.xml.defaults" to a read-only configuration source at position 2
Nov 18 13:56:44 localhost (sim-6824): starting (version 2.14.0), pid 6824 user 'sim'
Nov 18 13:56:44 localhost (sim-6824): Resolved address "xml:readonly:/etc/gconf/gconf.xml.mandatory" to a read-only configuration source at position 0
Nov 18 13:56:44 localhost (sim-6824): Resolved address "xml:readwrite:/home/sim/.gconf" to a writable configuration source at position 1
Nov 18 13:56:44 localhost (sim-6824): Resolved address "xml:readonly:/etc/gconf/gconf.xml.defaults" to a read-only configuration source at position 2
Nov 18 14:00:01 localhost cron[7084]: (root) CMD (test -x /usr/sbin/run-crons && /usr/sbin/run-crons )
Nov 18 14:00:01 localhost cron[7086]: (root) CMD (rm -f /var/spool/cron/lastrun/cron.hourly)
Nov 18 14:02:48 localhost su[7109]: Successful su for root by sim
Nov 18 14:02:48 localhost su[7109]: + pts/1 sim:root
Nov 18 14:02:48 localhost su[7109]: pam_unix(su:session): session opened for user root by (uid=1000)
Nov 18 14:10:01 localhost cron[7152]: (root) CMD (test -x /usr/sbin/run-crons && /usr/sbin/run-crons )
Nov 18 14:13:07 localhost eth0: link down.
Nov 18 14:14:17 localhost eth0: link up.
Nov 18 14:16:27 localhost eth0: link down.
Nov 18 14:20:01 localhost cron[8246]: (root) CMD (test -x /usr/sbin/run-crons && /usr/sbin/run-crons )
Nov 18 14:24:34 localhost eth0: link up.
Nov 18 14:30:01 localhost cron[8291]: (root) CMD (test -x /usr/sbin/run-crons && /usr/sbin/run-crons )
Nov 18 14:40:01 localhost cron[8314]: (root) CMD (test -x /usr/sbin/run-crons && /usr/sbin/run-crons )
Nov 18 14:50:01 localhost cron[8356]: (root) CMD (test -x /usr/sbin/run-crons && /usr/sbin/run-crons )
Nov 18 14:52:40 localhost Inbound IN=eth0 OUT= MAC= SRC=192.168.0.99 DST=239.255.255.250 LEN=129 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=UDP SPT=8008 DPT=1900 LEN=109
Nov 18 14:52:40 localhost Inbound IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=192.168.0.99 LEN=295 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=1900 DPT=8008 LEN=275
Nov 18 14:52:41 localhost Inbound IN=eth0 OUT= MAC= SRC=192.168.0.99 DST=239.255.67.250 LEN=197 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=UDP SPT=32876 DPT=16680 LEN=177
Nov 18 14:52:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=304 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=284
Nov 18 14:52:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 14:52:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=376 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=356
Nov 18 14:52:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=368 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=348
Nov 18 14:53:40 localhost Inbound IN=eth0 OUT= MAC= SRC=192.168.0.99 DST=239.255.255.250 LEN=129 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=UDP SPT=8008 DPT=1900 LEN=109
Nov 18 14:53:40 localhost Inbound IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=192.168.0.99 LEN=295 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=1900 DPT=8008 LEN=275
Nov 18 14:53:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=304 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=284
Nov 18 14:53:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 14:53:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=376 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=356
Nov 18 14:53:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=368 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=348
Nov 18 14:53:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 14:54:40 localhost Inbound IN=eth0 OUT= MAC= SRC=192.168.0.99 DST=239.255.255.250 LEN=129 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=UDP SPT=8008 DPT=1900 LEN=109
Nov 18 14:54:40 localhost Inbound IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=192.168.0.99 LEN=295 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=1900 DPT=8008 LEN=275
Nov 18 14:54:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=304 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=284
Nov 18 14:54:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 14:54:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=376 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=356
Nov 18 14:54:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=368 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=348
Nov 18 14:54:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 14:55:40 localhost Inbound IN=eth0 OUT= MAC= SRC=192.168.0.99 DST=239.255.255.250 LEN=129 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=UDP SPT=8008 DPT=1900 LEN=109
Nov 18 14:55:40 localhost Inbound IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=192.168.0.99 LEN=295 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=1900 DPT=8008 LEN=275
Nov 18 14:55:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=304 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=284
Nov 18 14:55:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 14:55:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=376 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=356
Nov 18 14:55:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=368 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=348
Nov 18 14:55:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 14:56:40 localhost Inbound IN=eth0 OUT= MAC= SRC=192.168.0.99 DST=239.255.255.250 LEN=129 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=UDP SPT=8008 DPT=1900 LEN=109
Nov 18 14:56:40 localhost Inbound IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=192.168.0.99 LEN=295 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=1900 DPT=8008 LEN=275
Nov 18 14:56:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=304 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=284
Nov 18 14:56:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 14:56:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=376 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=356
Nov 18 14:56:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=368 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=348
Nov 18 14:56:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 14:57:40 localhost Inbound IN=eth0 OUT= MAC= SRC=192.168.0.99 DST=239.255.255.250 LEN=129 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=UDP SPT=8008 DPT=1900 LEN=109
Nov 18 14:57:40 localhost Inbound IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=192.168.0.99 LEN=295 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=1900 DPT=8008 LEN=275
Nov 18 14:57:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=304 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=284
Nov 18 14:57:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 14:57:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=376 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=356
Nov 18 14:57:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=368 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=348
Nov 18 14:57:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 14:58:40 localhost Inbound IN=eth0 OUT= MAC= SRC=192.168.0.99 DST=239.255.255.250 LEN=129 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=UDP SPT=8008 DPT=1900 LEN=109
Nov 18 14:58:40 localhost Inbound IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=192.168.0.99 LEN=295 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=1900 DPT=8008 LEN=275
Nov 18 14:58:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=304 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=284
Nov 18 14:58:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 14:58:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=376 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=356
Nov 18 14:58:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=368 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=348
Nov 18 14:58:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 14:59:40 localhost Inbound IN=eth0 OUT= MAC= SRC=192.168.0.99 DST=239.255.255.250 LEN=129 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=UDP SPT=8008 DPT=1900 LEN=109
Nov 18 14:59:40 localhost Inbound IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=192.168.0.99 LEN=295 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=1900 DPT=8008 LEN=275
Nov 18 14:59:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=304 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=284
Nov 18 14:59:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 14:59:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=376 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=356
Nov 18 14:59:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=368 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=348
Nov 18 14:59:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 15:00:01 localhost cron[8586]: (root) CMD (test -x /usr/sbin/run-crons && /usr/sbin/run-crons )
Nov 18 15:00:01 localhost cron[8588]: (root) CMD (rm -f /var/spool/cron/lastrun/cron.hourly)
Nov 18 15:00:40 localhost Inbound IN=eth0 OUT= MAC= SRC=192.168.0.99 DST=239.255.255.250 LEN=129 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=UDP SPT=8008 DPT=1900 LEN=109
Nov 18 15:00:40 localhost Inbound IN=eth0 OUT= MAC=00:13:d3:a4:b5:f7:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=192.168.0.99 LEN=295 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=1900 DPT=8008 LEN=275
Nov 18 15:00:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=304 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=284
Nov 18 15:00:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Nov 18 15:00:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=376 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=356
Nov 18 15:00:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=368 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=348
Nov 18 15:00:41 localhost Inbound IN=eth0 OUT= MAC=01:00:5e:7f:ff:fa:00:14:bf:b2:2d:be:08:00 SRC=192.168.0.1 DST=239.255.255.250 LEN=299 TOS=0x00 PREC=0x00 TTL=4 ID=0 DF PROTO=UDP SPT=1900 DPT=1900 LEN=279
Back to top
View user's profile Send private message
Snappi
Tux's lil' helper
Tux's lil' helper


Joined: 20 Oct 2003
Posts: 113

PostPosted: Sat Nov 18, 2006 9:33 pm    Post subject: Reply with quote

users
Code:
sim

wichs seems fine

last
Code:
sim      :0                            Sat Nov 18 13:32   still logged in
reboot   system boot  2.6.17-gentoo-r8 Sat Nov 18 13:32          (08:42)
sim      :0                            Sat Nov 18 11:11 - 11:12  (00:00)
reboot   system boot  2.6.17-gentoo-r8 Sat Nov 18 11:11          (00:01)
sim      :0                            Sat Nov 18 02:44 - 02:45  (00:01)
sim      :0                            Sat Nov 18 01:29 - 02:44  (01:14)
sim      :0                            Fri Nov 17 23:32 - 01:29  (01:57)
reboot   system boot  2.6.17-gentoo-r8 Fri Nov 17 23:31          (03:13)
sim      :0                            Fri Nov 17 21:24 - 23:31  (02:07)
reboot   system boot  2.6.17-gentoo-r8 Fri Nov 17 21:23          (02:07)
root     tty2                          Fri Nov 17 18:28 - down   (02:55)
root     tty2                          Fri Nov 17 18:28 - 18:28  (00:00)
root     tty1                          Fri Nov 17 18:18 - 18:34  (00:15)
root     tty1                          Fri Nov 17 18:18 - 18:18  (00:00)
sim      :0                            Fri Nov 17 18:16 - 18:18  (00:01)
reboot   system boot  2.6.17-gentoo-r8 Fri Nov 17 18:16          (03:06)
sim      :0                            Thu Nov 16 19:55 - 01:18  (05:23)
reboot   system boot  2.6.17-gentoo-r8 Thu Nov 16 19:54          (05:24)
root     pts/1        :0.0             Thu Nov 16 19:53 - 19:53  (00:00)
root     pts/2        :0.0             Thu Nov 16 19:53 - 19:53  (00:00)
root     pts/0        :0.0             Thu Nov 16 19:53 - 19:53  (00:00)
root     pts/1        :0.0             Thu Nov 16 19:53 - 19:53  (00:00)
root     pts/2        :0.0             Thu Nov 16 19:53 - 19:53  (00:00)
root     pts/0        :0.0             Thu Nov 16 19:53 - 19:53  (00:00)
root     pts/2        :0.0             Thu Nov 16 19:49 - 19:49  (00:00)
root     pts/1        :0.0             Thu Nov 16 19:49 - 19:49  (00:00)
root     pts/0        :0.0             Thu Nov 16 19:49 - 19:49  (00:00)
root     pts/1        :0.0             Thu Nov 16 19:48 - 19:48  (00:00)
root     pts/2        :0.0             Thu Nov 16 19:48 - 19:48  (00:00)
root     pts/0        :0.0             Thu Nov 16 19:48 - 19:48  (00:00)
root     pts/1        :0.0             Thu Nov 16 19:47 - 19:47  (00:00)
root     pts/2        :0.0             Thu Nov 16 19:47 - 19:47  (00:00)
root     pts/0        :0.0             Thu Nov 16 19:47 - 19:47  (00:00)
root     pts/2        :0.0             Thu Nov 16 19:47 - 19:47  (00:00)
root     pts/1        :0.0             Thu Nov 16 19:47 - 19:47  (00:00)
root     pts/0        :0.0             Thu Nov 16 19:47 - 19:47  (00:00)
root     pts/1        :0.0             Thu Nov 16 19:47 - 19:47  (00:00)
root     pts/2        :0.0             Thu Nov 16 19:47 - 19:47  (00:00)
root     pts/0        :0.0             Thu Nov 16 19:47 - 19:47  (00:00)
root     pts/2        :0.0             Thu Nov 16 19:46 - 19:46  (00:00)
root     pts/1        :0.0             Thu Nov 16 19:46 - 19:46  (00:00)
root     pts/0        :0.0             Thu Nov 16 19:46 - 19:46  (00:00)
root     pts/0        :0.0             Thu Nov 16 19:44 - 19:44  (00:00)
root     pts/1        :0.0             Thu Nov 16 19:44 - 19:44  (00:00)
root     pts/2        :0.0             Thu Nov 16 19:44 - 19:44  (00:00)
root     pts/0        :0.0             Thu Nov 16 19:44 - 19:44  (00:00)
root     pts/2        :0.0             Thu Nov 16 19:42 - 19:42  (00:00)
root     pts/1        :0.0             Thu Nov 16 19:42 - 19:42  (00:00)
root     pts/0        :0.0             Thu Nov 16 19:42 - 19:42  (00:00)
root     pts/2        :0.0             Thu Nov 16 19:40 - 19:40  (00:00)
root     pts/0        :0.0             Thu Nov 16 19:40 - 19:40  (00:00)
root     pts/1        :0.0             Thu Nov 16 19:40 - 19:40  (00:00)
root     tty2                          Thu Nov 16 19:39 - down   (00:14)
root     tty2                          Thu Nov 16 19:39 - 19:39  (00:00)
root     tty1                          Thu Nov 16 19:39 - down   (00:14)
root     tty1                          Thu Nov 16 19:39 - 19:39  (00:00)
reboot   system boot  2.6.17-gentoo-r8 Thu Nov 16 19:39          (00:14)
root     tty1                          Thu Nov 16 19:38 - down   (00:00)
root     tty1                          Thu Nov 16 19:38 - 19:38  (00:00)
sim      :0                            Thu Nov 16 17:08 - 19:37  (02:29)
reboot   system boot  2.6.17-gentoo-r8 Thu Nov 16 17:07          (02:30)
sim      :0                            Tue Nov 14 23:31 - 15:51  (16:20)
reboot   system boot  2.6.17-gentoo-r8 Tue Nov 14 23:30          (16:20)
sim      :0                            Mon Nov 13 18:44 - 17:41  (22:57)
reboot   system boot  2.6.17-gentoo-r8 Mon Nov 13 18:42          (22:58)
sim      :0                            Mon Nov 13 00:57 - 02:52  (01:55)
reboot   system boot  2.6.17-gentoo-r8 Mon Nov 13 00:56          (01:56)
sim      tty3                          Sun Nov 12 22:15 - 22:19  (00:03)
sim      tty3                          Sun Nov 12 22:15 - 22:15  (00:00)
root     tty2                          Sun Nov 12 18:35 - 00:52  (06:17)
root     tty2                          Sun Nov 12 18:35 - 18:35  (00:00)
root     tty2                          Sun Nov 12 17:04 - 17:07  (00:02)
root     tty2                          Sun Nov 12 17:04 - 17:04  (00:00)
sim      tty2                          Sun Nov 12 17:02 - 17:04  (00:01)
sim      tty2                          Sun Nov 12 17:02 - 17:02  (00:00)
root     tty2                          Sun Nov 12 17:01 - 17:02  (00:01)
root     tty2                          Sun Nov 12 17:01 - 17:01  (00:00)
root     tty1                          Sun Nov 12 15:41 - down   (09:11)
root     tty1                          Sun Nov 12 15:41 - 15:41  (00:00)
sim      :0                            Thu Nov  9 02:05 - 15:40 (3+13:35)
reboot   system boot  2.6.17-gentoo-r8 Thu Nov  9 02:04         (3+22:48)
sim      :0                            Thu Nov  9 01:43 - 02:04  (00:20)
reboot   system boot  2.6.17-gentoo-r8 Thu Nov  9 01:43          (00:20)
sim      :0                            Thu Nov  9 00:30 - 01:42  (01:11)
reboot   system boot  2.6.17-gentoo-r8 Thu Nov  9 00:29          (01:12)
root     tty1                          Thu Nov  9 00:22 - down   (00:06)
root     tty1                          Thu Nov  9 00:22 - 00:22  (00:00)
reboot   system boot  2.6.17-gentoo-r8 Thu Nov  9 00:22          (00:07)
root     tty1                          Thu Nov  9 01:04 - down   (00:16)
root     tty1                          Thu Nov  9 01:04 - 01:04  (00:00)
reboot   system boot  2.6.17-gentoo-r8 Thu Nov  9 00:58          (00:23)
root     pts/1        :0.0             Wed Nov  8 20:35 - 20:40  (00:05)
root     pts/2        :0.0             Wed Nov  8 20:35 - 20:40  (00:05)
root     pts/0        :0.0             Wed Nov  8 20:35 - 20:40  (00:05)
root     pts/2        :0.0             Wed Nov  8 20:27 - 20:30  (00:03)
root     pts/1        :0.0             Wed Nov  8 20:27 - 20:30  (00:03)
root     pts/0        :0.0             Wed Nov  8 20:27 - 20:30  (00:03)
root     pts/2        :0.0             Wed Nov  8 20:03 - 20:04  (00:00)
root     pts/1        :0.0             Wed Nov  8 20:03 - 20:04  (00:00)
root     pts/0        :0.0             Wed Nov  8 20:03 - 20:04  (00:00)
root     tty2                          Wed Nov  8 20:00 - down   (01:16)
root     tty2                          Wed Nov  8 20:00 - 20:00  (00:00)
root     pts/2        :0.0             Wed Nov  8 19:53 - 19:53  (00:00)
root     pts/0        :0.0             Wed Nov  8 19:53 - 19:53  (00:00)
root     pts/1        :0.0             Wed Nov  8 19:53 - 19:53  (00:00)
root     tty1                          Wed Nov  8 19:41 - down   (01:35)
root     tty1                          Wed Nov  8 19:41 - 19:41  (00:00)
reboot   system boot  2.6.17-gentoo-r8 Wed Nov  8 19:31          (01:44)
root     tty2                          Wed Nov  8 13:16 - down   (02:13)
root     tty2                          Wed Nov  8 13:16 - 13:16  (00:00)
root     pts/2        :0.0             Wed Nov  8 13:14 - 13:24  (00:09)
root     pts/0        :0.0             Wed Nov  8 13:14 - 13:24  (00:09)
root     pts/1        :0.0             Wed Nov  8 13:14 - 13:24  (00:09)
root     tty1                          Wed Nov  8 12:49 - down   (02:40)
root     tty1                          Wed Nov  8 12:49 - 12:49  (00:00)
reboot   system boot  2.6.17-gentoo-r8 Wed Nov  8 12:35          (02:54)
root     tty2                          Wed Nov  8 04:24 - down   (00:40)
root     tty2                          Wed Nov  8 04:24 - 04:24  (00:00)
root     tty1                          Wed Nov  8 04:20 - down   (00:44)
root     tty1                          Wed Nov  8 04:20 - 04:20  (00:00)
reboot   system boot  2.6.17-gentoo-r8 Wed Nov  8 04:20          (00:44)
root     tty2                          Wed Nov  8 03:19 - down   (00:00)
root     tty2                          Wed Nov  8 03:19 - 03:19  (00:00)
root     tty1                          Wed Nov  8 01:23 - down   (01:56)
root     tty1                          Wed Nov  8 01:23 - 01:23  (00:00)
reboot   system boot  2.6.17-gentoo-r8 Wed Nov  8 01:22          (01:56)

wtmp begins Wed Nov  8 01:22:57 2006


only user I have created is sim

netstat -nlp
Code:
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name
tcp        0      0 ::ffff:127.0.0.1:6880   :::*                    LISTEN      8376/java
tcp        0      0 ::ffff:127.0.0.1:45100  :::*                    LISTEN      8376/java
tcp        0      0 :::54070                :::*                    LISTEN      8376/java
udp        0      0 :::16680                :::*                                8376/java
udp        0      0 :::54070                :::*                                8376/java
udp        0      0 ::ffff:192.168.0.9:8008 :::*                                8376/java
udp        0      0 :::1900                 :::*                                8376/java
udp        0      0 ::ffff:192.168.0.:32876 :::*                                8376/java
Active UNIX domain sockets (only servers)
Proto RefCnt Flags       Type       State         I-Node PID/Program name    Path
unix  2      [ ACC ]     STREAM     LISTENING     75377  14138/gconfd-2      /tmp/orbit-sim/linc-373a-0-756ab4fc43457
unix  2      [ ACC ]     STREAM     LISTENING     75386  14133/firefox-bin   /tmp/orbit-sim/linc-3735-0-478cdaad4962f
unix  2      [ ACC ]     STREAM     LISTENING     11459  6232/dbus-daemon    @/tmp/dbus-9b76ybTl1t
unix  2      [ ACC ]     STREAM     LISTENING     10731  5664/X              /tmp/.X11-unix/X0
unix  2      [ ACC ]     STREAM     LISTENING     10102  5093/syslog-ng      /dev/log
unix  2      [ ACC ]     STREAM     LISTENING     10726  5661/kdm            /var/run/xdmctl/dmctl/socket
unix  2      [ ACC ]     STREAM     LISTENING     10735  5661/kdm            /var/run/xdmctl/dmctl-:0/socket
unix  2      [ ACC ]     STREAM     LISTENING     11497  6251/kdeinit Runnin /tmp/ksocket-sim/kdeinit__0
unix  2      [ ACC ]     STREAM     LISTENING     11499  6251/kdeinit Runnin /tmp/ksocket-sim/kdeinit-:0
unix  2      [ ACC ]     STREAM     LISTENING     11506  6254/dcopserver [kd /tmp/.ICE-unix/dcop6254-1163853150
unix  2      [ ACC ]     STREAM     LISTENING     11596  6265/ksmserver [kde /tmp/.ICE-unix/6265
unix  2      [ ACC ]     STREAM     LISTENING     11527  6256/klauncher [kde /tmp/ksocket-sim/klauncherizfGjc.slave-socket
unix  2      [ ACC ]     STREAM     LISTENING     12363  6606/gconfd-2       /tmp/orbit-root/linc-19ce-0-2a91f05cc0779
unix  2      [ ACC ]     STREAM     LISTENING     12369  6604/firestarter    /tmp/orbit-root/linc-19cc-0-2b61e47cce01a


/etc/passwd
Code:
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/bin/false
daemon:x:2:2:daemon:/sbin:/bin/false
adm:x:3:4:adm:/var/adm:/bin/false
lp:x:4:7:lp:/var/spool/lpd:/bin/false
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:/bin/false
news:x:9:13:news:/usr/lib/news:/bin/false
uucp:x:10:14:uucp:/var/spool/uucppublic:/bin/false
operator:x:11:0:operator:/root:/bin/bash
man:x:13:15:man:/usr/share/man:/bin/false
postmaster:x:14:12:postmaster:/var/spool/mail:/bin/false
smmsp:x:209:209:smmsp:/var/spool/mqueue:/bin/false
portage:x:250:250:portage:/var/tmp/portage:/bin/false
nobody:x:65534:65534:nobody:/:/bin/false
sshd:x:22:22:added by portage for openssh:/var/empty:/usr/sbin/nologin
cron:x:16:16:added by portage for cronbase:/var/spool/cron:/usr/sbin/nologin
sim:x:1000:1000::/home/sim:/bin/bash
messagebus:x:101:1001:added by portage for dbus:/dev/null:/usr/sbin/nologin
haldaemon:x:102:1002:added by portage for hal:/dev/null:/usr/sbin/nologin


"operator:x:11:0:operator:/root:/bin/bash" what is that???

w
Code:
22:28:45 up  8:56,  1 user,  load average: 0.03, 0.07, 0.05
USER     TTY        LOGIN@   IDLE   JCPU   PCPU WHAT
sim      :0        13:32   ?xdm?   3:41   0.00s /bin/sh /usr/kde/3.5/bin/startkde


he can write every where, like in the first post the 3 ttt is his. (firefox, kwrite, xterm,.....)
Back to top
View user's profile Send private message
NeddySeagoon
Administrator
Administrator


Joined: 05 Jul 2003
Posts: 27168
Location: 56N 3W

PostPosted: Sat Nov 18, 2006 10:16 pm    Post subject: Reply with quote

Snappi

Code:
operator:x:11:0:operator:/root:/bin/bash
Operator is an account that can be logged into user name operator but with membershup of the root group.

Its intended to do some of the things that root can but not everything. e.g. run backups.
If it has a password, it will be in /etc/shadow DO NOT post that here, its all your passwd hashes.
Disable the account if you don't use it.

Theres a lot of root logins in last, can you account for them all ?
You should never log in as root, log in as your normal user and use sudo for odd commands as root, or su if you need a longer root session.
_________________
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Back to top
View user's profile Send private message
Snappi
Tux's lil' helper
Tux's lil' helper


Joined: 20 Oct 2003
Posts: 113

PostPosted: Sat Nov 18, 2006 11:02 pm    Post subject: Reply with quote

only time I use root is with "su -", I suppose might be some more time, I am not sure if I can confirm these logins.
Back to top
View user's profile Send private message
NeddySeagoon
Administrator
Administrator


Joined: 05 Jul 2003
Posts: 27168
Location: 56N 3W

PostPosted: Sun Nov 19, 2006 11:00 am    Post subject: Reply with quote

Snappi,

Ask the question the other way round ...

Are there root logins on days you know you did not use root ?

I'm beginning to suspect this is a practical joke rather than a hack. Lets recap.
1. It happens in both Linux and Windows.
2. It happens when you are using your PC. Most hackers prefer to keep their existence unknown.
3. There is only sim and root in last

I suspect that someone close to you has been able to guess your passwd(s) because you choose a poor one or you wrote it down.

Change the root and sim passwds to strong passwds (mix of upper and lower case letters, with a few numbers and special symbols).
Do not write them down and don't tell anyone. That prevents users gaining access by 'social engineering'.
_________________
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Back to top
View user's profile Send private message
Snappi
Tux's lil' helper
Tux's lil' helper


Joined: 20 Oct 2003
Posts: 113

PostPosted: Sun Nov 19, 2006 11:03 am    Post subject: Reply with quote

no one I know knows my ip, and no one knows the pass. I am sure of that.
Back to top
View user's profile Send private message
NeddySeagoon
Administrator
Administrator


Joined: 05 Jul 2003
Posts: 27168
Location: 56N 3W

PostPosted: Sun Nov 19, 2006 11:12 am    Post subject: Reply with quote

Snappi,

Everyone you connect to on the internet knows your IP. If they didn't, they could send you any replies.
Every Ethernet packet you send contains your IP. It doesn't matter - hackers often don't care about the target and work on guessed IPs.

You already have strong passwords of eight symbols or more?
Passwords based on your sports teams, pets names, keyboard patterns, or relatives names are particularly useless.
_________________
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Back to top
View user's profile Send private message
Snappi
Tux's lil' helper
Tux's lil' helper


Joined: 20 Oct 2003
Posts: 113

PostPosted: Sun Nov 19, 2006 1:08 pm    Post subject: Reply with quote

yeah I know that, I meant my friends doesn't know my ip.

my root password contains more than 8 symbols. and it's a completly random password, it's not a word.
Back to top
View user's profile Send private message
NeddySeagoon
Administrator
Administrator


Joined: 05 Jul 2003
Posts: 27168
Location: 56N 3W

PostPosted: Sun Nov 19, 2006 1:19 pm    Post subject: Reply with quote

Snappi,

Look in /root/.bash_history and /home/<user>/.bash_history. They contain the last 300 or so commands executed by the user.
Anything odd ?

e.g. commands you never use, truncated files, indicating that someone has been trying to cover their tracks.
_________________
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Back to top
View user's profile Send private message
Snappi
Tux's lil' helper
Tux's lil' helper


Joined: 20 Oct 2003
Posts: 113

PostPosted: Sun Nov 19, 2006 2:22 pm    Post subject: Reply with quote

nothing there. I think this guy is good at what he do.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Goto page 1, 2, 3, 4, 5  Next
Page 1 of 5

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum