Script started on Sun Nov 24 15:24:42 2002 ]0;barrie@magnolia:~/scripts [barrie@magnolia scripts]$ [barrie@magnolia scripts]$ [barrie@magnolia scripts]$ w [barrie@magnolia scripts]$ w [barrie@magnolia scripts]$ wh [barrie@magnolia scripts]$ wh [barrie@magnolia scripts]$ whi [barrie@magnolia scripts]$ whi [barrie@magnolia scripts]$ whic [barrie@magnolia scripts]$ whic [barrie@magnolia scripts]$ which [barrie@magnolia scripts]$ which [barrie@magnolia scripts]$ which [barrie@magnolia scripts]$ which [barrie@magnolia scripts]$ which l [barrie@magnolia scripts]$ which l [barrie@magnolia scripts]$ which lo [barrie@magnolia scripts]$ which lo [barrie@magnolia scripts]$ which log [barrie@magnolia scripts]$ which log [barrie@magnolia scripts]$ which logc [barrie@magnolia scripts]$ which logc [barrie@magnolia scripts]$ which logch [barrie@magnolia scripts]$ which logch [barrie@magnolia scripts]$ which logche [barrie@magnolia scripts]$ which logche [barrie@magnolia scripts]$ which logchec [barrie@magnolia scripts]$ which logchec [barrie@magnolia scripts]$ which logcheck [barrie@magnolia scripts]$ which logcheck /usr/bin/which: no logcheck in (/usr/local/bin:/bin:/usr/bin:/usr/X11R6/bin:/sbin:/usr/sbin:/usr/local/sbin:/home/barrie/bin:/usr/local/mysql/bin) ]0;barrie@magnolia:~/scripts [barrie@magnolia scripts]$ [barrie@magnolia scripts]$ [barrie@magnolia scripts]$ r [barrie@magnolia scripts]$ r [barrie@magnolia scripts]$ rp [barrie@magnolia scripts]$ rp [barrie@magnolia scripts]$ rpm [barrie@magnolia scripts]$ rpm [barrie@magnolia scripts]$ rpm [barrie@magnolia scripts]$ rpm [barrie@magnolia scripts]$ rpm - [barrie@magnolia scripts]$ rpm - [barrie@magnolia scripts]$ rpm -q [barrie@magnolia scripts]$ rpm -q [barrie@magnolia scripts]$ rpm -qi [barrie@magnolia scripts]$ rpm -qi [barrie@magnolia scripts]$ rpm -qi [barrie@magnolia scripts]$ rpm -qi [barrie@magnolia scripts]$ rpm -qi r [barrie@magnolia scripts]$ rpm -qi r [barrie@magnolia scripts]$ rpm -qi rp [barrie@magnolia scripts]$ rpm -qi rp [barrie@magnolia scripts]$ rpm -qi rpm [barrie@magnolia scripts]$ rpm -qi rpm [barrie@magnolia scripts]$ rpm -qi rp [barrie@magnolia scripts]$ rpm -qi rp [barrie@magnolia scripts]$ rpm -qi r [barrie@magnolia scripts]$ rpm -qi r [barrie@magnolia scripts]$ rpm -qi  [barrie@magnolia scripts]$ rpm -qi [barrie@magnolia scripts]$ rpm -qi l [barrie@magnolia scripts]$ rpm -qi l [barrie@magnolia scripts]$ rpm -qi  [barrie@magnolia scripts]$ rpm -qi [barrie@magnolia scripts]$ rpm -qi [barrie@magnolia scripts]$ rpm -qi [barrie@magnolia scripts]$ rpm -q [barrie@magnolia scripts]$ rpm -q [barrie@magnolia scripts]$ rpm -qp [barrie@magnolia scripts]$ rpm -qp [barrie@magnolia scripts]$ rpm -qpi [barrie@magnolia scripts]$ rpm -qpi [barrie@magnolia scripts]$ rpm -qpi [barrie@magnolia scripts]$ rpm -qpi [barrie@magnolia scripts]$ rpm -qpi l [barrie@magnolia scripts]$ rpm -qpi l [barrie@magnolia scripts]$ rpm -qpi lo [barrie@magnolia scripts]$ rpm -qpi lo [barrie@magnolia scripts]$ rpm -qpi log [barrie@magnolia scripts]$ rpm -qpi log [barrie@magnolia scripts]$ rpm -qpi logc [barrie@magnolia scripts]$ rpm -qpi logc [barrie@magnolia scripts]$ rpm -qpi logch [barrie@magnolia scripts]$ rpm -qpi logch [barrie@magnolia scripts]$ rpm -qpi logche [barrie@magnolia scripts]$ rpm -qpi logche [barrie@magnolia scripts]$ rpm -qpi logchec [barrie@magnolia scripts]$ rpm -qpi logchec [barrie@magnolia scripts]$ rpm -qpi logcheck [barrie@magnolia scripts]$ rpm -qpi logcheck error: open of logcheck failed: No such file or directory ]0;barrie@magnolia:~/scripts [barrie@magnolia scripts]$ [barrie@magnolia scripts]$ [barrie@magnolia scripts]$ r [barrie@magnolia scripts]$ r [barrie@magnolia scripts]$ rp [barrie@magnolia scripts]$ rp [barrie@magnolia scripts]$ rpm [barrie@magnolia scripts]$ rpm [barrie@magnolia scripts]$ rpm [barrie@magnolia scripts]$ rpm [barrie@magnolia scripts]$ rpm - [barrie@magnolia scripts]$ rpm - [barrie@magnolia scripts]$ rpm -q [barrie@magnolia scripts]$ rpm -q [barrie@magnolia scripts]$ rpm -qi [barrie@magnolia scripts]$ rpm -qi [barrie@magnolia scripts]$ rpm -qi [barrie@magnolia scripts]$ rpm -qi [barrie@magnolia scripts]$ rpm -qi l [barrie@magnolia scripts]$ rpm -qi l [barrie@magnolia scripts]$ rpm -qi lo [barrie@magnolia scripts]$ rpm -qi lo [barrie@magnolia scripts]$ rpm -qi log [barrie@magnolia scripts]$ rpm -qi log [barrie@magnolia scripts]$ rpm -qi lo [barrie@magnolia scripts]$ rpm -qi lo [barrie@magnolia scripts]$ rpm -qi l [barrie@magnolia scripts]$ rpm -qi l [barrie@magnolia scripts]$ rpm -qi  [barrie@magnolia scripts]$ rpm -qi [barrie@magnolia scripts]$ rpm -qi [barrie@magnolia scripts]$ rpm -qi [barrie@magnolia scripts]$ rpm -q [barrie@magnolia scripts]$ rpm -q [barrie@magnolia scripts]$ rpm -q [barrie@magnolia scripts]$ rpm -q [barrie@magnolia scripts]$ rpm -q l [barrie@magnolia scripts]$ rpm -q l [barrie@magnolia scripts]$ rpm -q lo [barrie@magnolia scripts]$ rpm -q lo [barrie@magnolia scripts]$ rpm -q log [barrie@magnolia scripts]$ rpm -q log [barrie@magnolia scripts]$ rpm -q logc [barrie@magnolia scripts]$ rpm -q logc [barrie@magnolia scripts]$ rpm -q logch [barrie@magnolia scripts]$ rpm -q logch [barrie@magnolia scripts]$ rpm -q logche [barrie@magnolia scripts]$ rpm -q logche [barrie@magnolia scripts]$ rpm -q logchec [barrie@magnolia scripts]$ rpm -q logchec [barrie@magnolia scripts]$ rpm -q logcheck [barrie@magnolia scripts]$ rpm -q logcheck package logcheck is not installed ]0;barrie@magnolia:~/scripts [barrie@magnolia scripts]$ [barrie@magnolia scripts]$ [barrie@magnolia scripts]$ l [barrie@magnolia scripts]$ l [barrie@magnolia scripts]$ lo [barrie@magnolia scripts]$ lo [barrie@magnolia scripts]$ loc [barrie@magnolia scripts]$ loc [barrie@magnolia scripts]$ loca [barrie@magnolia scripts]$ loca [barrie@magnolia scripts]$ locat [barrie@magnolia scripts]$ locat [barrie@magnolia scripts]$ locate [barrie@magnolia scripts]$ locate [barrie@magnolia scripts]$ locate [barrie@magnolia scripts]$ locate [barrie@magnolia scripts]$ locate l [barrie@magnolia scripts]$ locate l [barrie@magnolia scripts]$ locate lo [barrie@magnolia scripts]$ locate lo [barrie@magnolia scripts]$ locate log [barrie@magnolia scripts]$ locate log [barrie@magnolia scripts]$ locate logc [barrie@magnolia scripts]$ locate logc [barrie@magnolia scripts]$ locate logch [barrie@magnolia scripts]$ locate logch [barrie@magnolia scripts]$ locate logche [barrie@magnolia scripts]$ locate logche [barrie@magnolia scripts]$ locate logchec [barrie@magnolia scripts]$ locate logchec [barrie@magnolia scripts]$ locate logcheck [barrie@magnolia scripts]$ locate logcheck ]0;barrie@magnolia:~/scripts [barrie@magnolia scripts]$ [barrie@magnolia scripts]$ [barrie@magnolia scripts]$ l [barrie@magnolia scripts]$ l [barrie@magnolia scripts]$ ly [barrie@magnolia scripts]$ ly [barrie@magnolia scripts]$ lyn [barrie@magnolia scripts]$ lyn [barrie@magnolia scripts]$ lynx [barrie@magnolia scripts]$ lynx [barrie@magnolia scripts]$ lynx [barrie@magnolia scripts]$ lynx [barrie@magnolia scripts]$ lynx [barrie@magnolia scripts]$ lynx [barrie@magnolia scripts]$ lyn [barrie@magnolia scripts]$ lyn [barrie@magnolia scripts]$ ly [barrie@magnolia scripts]$ ly [barrie@magnolia scripts]$ l [barrie@magnolia scripts]$ l [barrie@magnolia scripts]$  [barrie@magnolia scripts]$ [barrie@magnolia scripts]$ w [barrie@magnolia scripts]$ w [barrie@magnolia scripts]$ wg [barrie@magnolia scripts]$ wg [barrie@magnolia scripts]$ wge [barrie@magnolia scripts]$ wge [barrie@magnolia scripts]$ wget [barrie@magnolia scripts]$ wget [barrie@magnolia scripts]$ wget [barrie@magnolia scripts]$ wget [barrie@magnolia scripts]$ wget h [barrie@magnolia scripts]$ wget h [barrie@magnolia scripts]$ wget ht [barrie@magnolia scripts]$ wget ht [barrie@magnolia scripts]$ wget htt [barrie@magnolia scripts]$ wget htt [barrie@magnolia scripts]$ wget http [barrie@magnolia scripts]$ wget http [barrie@magnolia scripts]$ wget http: [barrie@magnolia scripts]$ wget http: [barrie@magnolia scripts]$ wget http:/ [barrie@magnolia scripts]$ wget http:/ [barrie@magnolia scripts]$ wget http:// [barrie@magnolia scripts]$ wget http:// [barrie@magnolia scripts]$ wget http://w [barrie@magnolia scripts]$ wget http://w [barrie@magnolia scripts]$ wget http://ww [barrie@magnolia scripts]$ wget http://ww [barrie@magnolia scripts]$ wget http://www [barrie@magnolia scripts]$ wget http://www [barrie@magnolia scripts]$ wget http://www. [barrie@magnolia scripts]$ wget http://www. [barrie@magnolia scripts]$ wget http://www.p [barrie@magnolia scripts]$ wget http://www.p [barrie@magnolia scripts]$ wget http://www.ps [barrie@magnolia scripts]$ wget http://www.ps [barrie@magnolia scripts]$ wget http://www.psi [barrie@magnolia scripts]$ wget http://www.psi [barrie@magnolia scripts]$ wget http://www.psio [barrie@magnolia scripts]$ wget http://www.psio [barrie@magnolia scripts]$ wget http://www.psion [barrie@magnolia scripts]$ wget http://www.psion [barrie@magnolia scripts]$ wget http://www.psioni [barrie@magnolia scripts]$ wget http://www.psioni [barrie@magnolia scripts]$ wget http://www.psionic [barrie@magnolia scripts]$ wget http://www.psionic [barrie@magnolia scripts]$ wget http://www.psionic. [barrie@magnolia scripts]$ wget http://www.psionic. [barrie@magnolia scripts]$ wget http://www.psionic.c [barrie@magnolia scripts]$ wget http://www.psionic.c [barrie@magnolia scripts]$ wget http://www.psionic.co [barrie@magnolia scripts]$ wget http://www.psionic.co [barrie@magnolia scripts]$ wget http://www.psionic.com [barrie@magnolia scripts]$ wget http://www.psionic.com [barrie@magnolia scripts]$ wget http://www.psionic.com/ [barrie@magnolia scripts]$ wget http://www.psionic.com/ [barrie@magnolia scripts]$ wget http://www.psionic.com/a [barrie@magnolia scripts]$ wget http://www.psionic.com/a [barrie@magnolia scripts]$ wget http://www.psionic.com/ab [barrie@magnolia scripts]$ wget http://www.psionic.com/ab [barrie@magnolia scripts]$ wget http://www.psionic.com/aba [barrie@magnolia scripts]$ wget http://www.psionic.com/aba [barrie@magnolia scripts]$ wget http://www.psionic.com/abac [barrie@magnolia scripts]$ wget http://www.psionic.com/abac [barrie@magnolia scripts]$ wget http://www.psionic.com/abacu [barrie@magnolia scripts]$ wget http://www.psionic.com/abacu [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/ [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/ [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/l [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/l [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/lo [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/lo [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/log [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/log [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logc [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logc [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logch [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logch [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logche [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logche [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logchec [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logchec [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logcheck [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logcheck [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logcheck/ [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logcheck/ [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logcheck [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logcheck [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logchec [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logchec [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logche [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logche [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logch [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logch [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logc [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/logc [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/log [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/log [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/lo [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/lo [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/l [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/l [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/ [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus/ [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus [barrie@magnolia scripts]$ wget http://www.psionic.com/abacus [barrie@magnolia scripts]$ wget http://www.psionic.com/abacu [barrie@magnolia scripts]$ wget http://www.psionic.com/abacu [barrie@magnolia scripts]$ wget http://www.psionic.com/abac [barrie@magnolia scripts]$ wget http://www.psionic.com/abac [barrie@magnolia scripts]$ wget http://www.psionic.com/aba [barrie@magnolia scripts]$ wget http://www.psionic.com/aba [barrie@magnolia scripts]$ wget http://www.psionic.com/ab [barrie@magnolia scripts]$ wget http://www.psionic.com/ab [barrie@magnolia scripts]$ wget http://www.psionic.com/a [barrie@magnolia scripts]$ wget http://www.psionic.com/a [barrie@magnolia scripts]$ wget http://www.psionic.com/ [barrie@magnolia scripts]$ wget http://www.psionic.com/ [barrie@magnolia scripts]$ wget http://www.psionic.com [barrie@magnolia scripts]$ wget http://www.psionic.com [barrie@magnolia scripts]$ wget http://www.psionic.co [barrie@magnolia scripts]$ wget http://www.psionic.co [barrie@magnolia scripts]$ wget http://www.psionic.c [barrie@magnolia scripts]$ wget http://www.psionic.c [barrie@magnolia scripts]$ wget http://www.psionic. [barrie@magnolia scripts]$ wget http://www.psionic. [barrie@magnolia scripts]$ wget http://www.psionic [barrie@magnolia scripts]$ wget http://www.psionic [barrie@magnolia scripts]$ wget http://www.psioni [barrie@magnolia scripts]$ wget http://www.psioni [barrie@magnolia scripts]$ wget http://www.psion [barrie@magnolia scripts]$ wget http://www.psion [barrie@magnolia scripts]$ wget http://www.psio [barrie@magnolia scripts]$ wget http://www.psio [barrie@magnolia scripts]$ wget http://www.psi [barrie@magnolia scripts]$ wget http://www.psi [barrie@magnolia scripts]$ wget http://www.ps [barrie@magnolia scripts]$ wget http://www.ps [barrie@magnolia scripts]$ wget http://www.p [barrie@magnolia scripts]$ wget http://www.p [barrie@magnolia scripts]$ wget http://www. [barrie@magnolia scripts]$ wget http://www. [barrie@magnolia scripts]$ wget http://www [barrie@magnolia scripts]$ wget http://www [barrie@magnolia scripts]$ wget http://ww [barrie@magnolia scripts]$ wget http://ww [barrie@magnolia scripts]$ wget http://w [barrie@magnolia scripts]$ wget http://w [barrie@magnolia scripts]$ wget http:// [barrie@magnolia scripts]$ wget http:// [barrie@magnolia scripts]$ wget http:/ [barrie@magnolia scripts]$ wget http:/ [barrie@magnolia scripts]$ wget http: [barrie@magnolia scripts]$ wget http: [barrie@magnolia scripts]$ wget http [barrie@magnolia scripts]$ wget http [barrie@magnolia scripts]$ wget htt [barrie@magnolia scripts]$ wget htt [barrie@magnolia scripts]$ wget ht [barrie@magnolia scripts]$ wget ht [barrie@magnolia scripts]$ wget h [barrie@magnolia scripts]$ wget h [barrie@magnolia scripts]$ wget  [barrie@magnolia scripts]$ wget [barrie@magnolia scripts]$ wget [barrie@magnolia scripts]$ wget [barrie@magnolia scripts]$ wge [barrie@magnolia scripts]$ wge [barrie@magnolia scripts]$ wg [barrie@magnolia scripts]$ wg [barrie@magnolia scripts]$ w [barrie@magnolia scripts]$ w [barrie@magnolia scripts]$  [barrie@magnolia scripts]$  [barrie@magnolia scripts]$ [barrie@magnolia scripts]$ c [barrie@magnolia scripts]$ c [barrie@magnolia scripts]$ cd [barrie@magnolia scripts]$ cd [barrie@magnolia scripts]$ cd [barrie@magnolia scripts]$ cd [barrie@magnolia scripts]$ cd / [barrie@magnolia scripts]$ cd / [barrie@magnolia scripts]$ cd  [barrie@magnolia scripts]$ cd [barrie@magnolia scripts]$ cd . [barrie@magnolia scripts]$ cd . [barrie@magnolia scripts]$ cd .. [barrie@magnolia scripts]$ cd .. [barrie@magnolia scripts]$ cd ../ [barrie@magnolia scripts]$ cd ../ [barrie@magnolia scripts]$ cd ../t [barrie@magnolia scripts]$ cd ../t [barrie@magnolia scripts]$ cd ../tm [barrie@magnolia scripts]$ cd ../tm [barrie@magnolia scripts]$ cd ../tmp [barrie@magnolia scripts]$ cd ../tmp ]0;barrie@magnolia:~/tmp [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ w [barrie@magnolia tmp]$ w [barrie@magnolia tmp]$ wg [barrie@magnolia tmp]$ wg [barrie@magnolia tmp]$ wge [barrie@magnolia tmp]$ wge [barrie@magnolia tmp]$ wget [barrie@magnolia tmp]$ wget [barrie@magnolia tmp]$ wget [barrie@magnolia tmp]$ wget [barrie@magnolia tmp]$ wget h [barrie@magnolia tmp]$ wget h [barrie@magnolia tmp]$ wget ht [barrie@magnolia tmp]$ wget ht [barrie@magnolia tmp]$ wget htt [barrie@magnolia tmp]$ wget htt [barrie@magnolia tmp]$ wget http [barrie@magnolia tmp]$ wget http [barrie@magnolia tmp]$ wget http: [barrie@magnolia tmp]$ wget http: [barrie@magnolia tmp]$ wget http:/ [barrie@magnolia tmp]$ wget http:/ [barrie@magnolia tmp]$ wget http:// [barrie@magnolia tmp]$ wget http:// [barrie@magnolia tmp]$ wget http://w [barrie@magnolia tmp]$ wget http://w [barrie@magnolia tmp]$ wget http://ww [barrie@magnolia tmp]$ wget http://ww [barrie@magnolia tmp]$ wget http://www [barrie@magnolia tmp]$ wget http://www [barrie@magnolia tmp]$ wget http://www. [barrie@magnolia tmp]$ wget http://www. [barrie@magnolia tmp]$ wget http://www.p [barrie@magnolia tmp]$ wget http://www.p [barrie@magnolia tmp]$ wget http://www.ps [barrie@magnolia tmp]$ wget http://www.ps [barrie@magnolia tmp]$ wget http://www.psi [barrie@magnolia tmp]$ wget http://www.psi [barrie@magnolia tmp]$ wget http://www.psio [barrie@magnolia tmp]$ wget http://www.psio [barrie@magnolia tmp]$ wget http://www.psion [barrie@magnolia tmp]$ wget http://www.psion [barrie@magnolia tmp]$ wget http://www.psioni [barrie@magnolia tmp]$ wget http://www.psioni [barrie@magnolia tmp]$ wget http://www.psionic [barrie@magnolia tmp]$ wget http://www.psionic [barrie@magnolia tmp]$ wget http://www.psionic. [barrie@magnolia tmp]$ wget http://www.psionic. [barrie@magnolia tmp]$ wget http://www.psionic.c [barrie@magnolia tmp]$ wget http://www.psionic.c [barrie@magnolia tmp]$ wget http://www.psionic.co [barrie@magnolia tmp]$ wget http://www.psionic.co [barrie@magnolia tmp]$ wget http://www.psionic.com [barrie@magnolia tmp]$ wget http://www.psionic.com [barrie@magnolia tmp]$ wget http://www.psionic.com/ [barrie@magnolia tmp]$ wget http://www.psionic.com/ [barrie@magnolia tmp]$ wget http://www.psionic.com/d [barrie@magnolia tmp]$ wget http://www.psionic.com/d [barrie@magnolia tmp]$ wget http://www.psionic.com/do [barrie@magnolia tmp]$ wget http://www.psionic.com/do [barrie@magnolia tmp]$ wget http://www.psionic.com/dow [barrie@magnolia tmp]$ wget http://www.psionic.com/dow [barrie@magnolia tmp]$ wget http://www.psionic.com/down [barrie@magnolia tmp]$ wget http://www.psionic.com/down [barrie@magnolia tmp]$ wget http://www.psionic.com/downl [barrie@magnolia tmp]$ wget http://www.psionic.com/downl [barrie@magnolia tmp]$ wget http://www.psionic.com/downlo [barrie@magnolia tmp]$ wget http://www.psionic.com/downlo [barrie@magnolia tmp]$ wget http://www.psionic.com/downloa [barrie@magnolia tmp]$ wget http://www.psionic.com/downloa [barrie@magnolia tmp]$ wget http://www.psionic.com/download [barrie@magnolia tmp]$ wget http://www.psionic.com/download [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/ [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/ [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/p [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/p [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/po [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/po [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/por [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/por [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/port [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/port [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/ports [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/ports [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portse [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portse [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsen [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsen [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsent [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsent [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentr [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentr [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry- [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry- [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry-1 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry-1 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry-1. [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry-1. [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry-1.1 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry-1.1 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry-1.1. [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry-1.1. [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry-1.1.t [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry-1.1.t [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry-1.1.ta [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry-1.1.ta [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry-1.1.tar [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry-1.1.tar [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/portsentry-1.1.tar. g g gz gz --16:00:19-- http://www.psionic.com/downloads/portsentry-1.1.tar.gz => `portsentry-1.1.tar.gz' Resolving www.psionic.com... done. Connecting to www.psionic.com[216.141.86.16]:80... connected. HTTP request sent, awaiting response... 200 OK Length: 45,871 [application/x-tar] 0% [ ] 0 --.--K/s ETA --:-- 6% [=> ] 3,177 13.04K/s ETA 00:03 20% [======> ] 9,177 19.78K/s ETA 00:01 33% [===========> ] 15,177 21.86K/s ETA 00:01 51% [==================> ] 23,677 26.07K/s ETA 00:00 76% [===========================> ] 35,268 30.72K/s ETA 00:00 91% [=================================> ] 42,177 30.09K/s ETA 00:00 100%[====================================>] 45,871 31.00K/s ETA 00:00 16:00:21 (31.00 KB/s) - `portsentry-1.1.tar.gz' saved [45871/45871] ]0;barrie@magnolia:~/tmp [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ w [barrie@magnolia tmp]$ w [barrie@magnolia tmp]$ we [barrie@magnolia tmp]$ we [barrie@magnolia tmp]$ w [barrie@magnolia tmp]$ w [barrie@magnolia tmp]$ wg [barrie@magnolia tmp]$ wg [barrie@magnolia tmp]$ wge [barrie@magnolia tmp]$ wge [barrie@magnolia tmp]$ wget [barrie@magnolia tmp]$ wget [barrie@magnolia tmp]$ wget [barrie@magnolia tmp]$ wget [barrie@magnolia tmp]$ wget h [barrie@magnolia tmp]$ wget h [barrie@magnolia tmp]$ wget ht [barrie@magnolia tmp]$ wget ht [barrie@magnolia tmp]$ wget htt [barrie@magnolia tmp]$ wget htt [barrie@magnolia tmp]$ wget http [barrie@magnolia tmp]$ wget http [barrie@magnolia tmp]$ wget http: [barrie@magnolia tmp]$ wget http: [barrie@magnolia tmp]$ wget http:/ [barrie@magnolia tmp]$ wget http:/ [barrie@magnolia tmp]$ wget http:// [barrie@magnolia tmp]$ wget http:// [barrie@magnolia tmp]$ wget http://w [barrie@magnolia tmp]$ wget http://w [barrie@magnolia tmp]$ wget http://ww [barrie@magnolia tmp]$ wget http://ww [barrie@magnolia tmp]$ wget http://www [barrie@magnolia tmp]$ wget http://www [barrie@magnolia tmp]$ wget http://www. [barrie@magnolia tmp]$ wget http://www. [barrie@magnolia tmp]$ wget http://www.p [barrie@magnolia tmp]$ wget http://www.p [barrie@magnolia tmp]$ wget http://www.ps [barrie@magnolia tmp]$ wget http://www.ps [barrie@magnolia tmp]$ wget http://www.psi [barrie@magnolia tmp]$ wget http://www.psi [barrie@magnolia tmp]$ wget http://www.psio [barrie@magnolia tmp]$ wget http://www.psio [barrie@magnolia tmp]$ wget http://www.psion [barrie@magnolia tmp]$ wget http://www.psion [barrie@magnolia tmp]$ wget http://www.psioni [barrie@magnolia tmp]$ wget http://www.psioni [barrie@magnolia tmp]$ wget http://www.psionic [barrie@magnolia tmp]$ wget http://www.psionic [barrie@magnolia tmp]$ wget http://www.psionic. [barrie@magnolia tmp]$ wget http://www.psionic. [barrie@magnolia tmp]$ wget http://www.psionic.c [barrie@magnolia tmp]$ wget http://www.psionic.c [barrie@magnolia tmp]$ wget http://www.psionic.co [barrie@magnolia tmp]$ wget http://www.psionic.co [barrie@magnolia tmp]$ wget http://www.psionic.com [barrie@magnolia tmp]$ wget http://www.psionic.com [barrie@magnolia tmp]$ wget http://www.psionic.com/ [barrie@magnolia tmp]$ wget http://www.psionic.com/ [barrie@magnolia tmp]$ wget http://www.psionic.com/d [barrie@magnolia tmp]$ wget http://www.psionic.com/d [barrie@magnolia tmp]$ wget http://www.psionic.com/do [barrie@magnolia tmp]$ wget http://www.psionic.com/do [barrie@magnolia tmp]$ wget http://www.psionic.com/dow [barrie@magnolia tmp]$ wget http://www.psionic.com/dow [barrie@magnolia tmp]$ wget http://www.psionic.com/down [barrie@magnolia tmp]$ wget http://www.psionic.com/down [barrie@magnolia tmp]$ wget http://www.psionic.com/downl [barrie@magnolia tmp]$ wget http://www.psionic.com/downl [barrie@magnolia tmp]$ wget http://www.psionic.com/downlo [barrie@magnolia tmp]$ wget http://www.psionic.com/downlo [barrie@magnolia tmp]$ wget http://www.psionic.com/downloa [barrie@magnolia tmp]$ wget http://www.psionic.com/downloa [barrie@magnolia tmp]$ wget http://www.psionic.com/download [barrie@magnolia tmp]$ wget http://www.psionic.com/download [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/ [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/ [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/l [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/l [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/lo [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/lo [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/log [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/log [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logs [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logs [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logse [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logse [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsen [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsen [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsent [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsent [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentr [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentr [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry- [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry- [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1. [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1. [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1.1 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1.1 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1.1. [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1.1. [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1.1.1 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1.1.1 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1.1.1. [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1.1.1. [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1.1.1.t [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1.1.1.t [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1.1.1.ta [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1.1.1.ta [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/logsentry-1.1.1.tar . . .g .g .gz .gz --16:00:48-- http://www.psionic.com/downloads/logsentry-1.1.1.tar.gz => `logsentry-1.1.1.tar.gz' Resolving www.psionic.com... done. Connecting to www.psionic.com[216.141.86.16]:80... connected. HTTP request sent, awaiting response... 200 OK Length: 30,267 [application/x-tar] 0% [ ] 0 --.--K/s ETA --:-- 17% [=====> ] 5,177 25.28K/s ETA 00:00 30% [==========> ] 9,177 22.24K/s ETA 00:00 53% [==================> ] 16,177 25.44K/s ETA 00:00 91% [================================> ] 27,677 32.02K/s ETA 00:00 100%[====================================>] 30,267 29.53K/s ETA 00:00 16:00:49 (29.53 KB/s) - `logsentry-1.1.1.tar.gz' saved [30267/30267] ]0;barrie@magnolia:~/tmp [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ w [barrie@magnolia tmp]$ w [barrie@magnolia tmp]$ wg [barrie@magnolia tmp]$ wg [barrie@magnolia tmp]$ wge [barrie@magnolia tmp]$ wge [barrie@magnolia tmp]$ wget [barrie@magnolia tmp]$ wget [barrie@magnolia tmp]$ wget [barrie@magnolia tmp]$ wget [barrie@magnolia tmp]$ wget h [barrie@magnolia tmp]$ wget h [barrie@magnolia tmp]$ wget ht [barrie@magnolia tmp]$ wget ht [barrie@magnolia tmp]$ wget htt [barrie@magnolia tmp]$ wget htt [barrie@magnolia tmp]$ wget http [barrie@magnolia tmp]$ wget http [barrie@magnolia tmp]$ wget http: [barrie@magnolia tmp]$ wget http: [barrie@magnolia tmp]$ wget http:/ [barrie@magnolia tmp]$ wget http:/ [barrie@magnolia tmp]$ wget http:// [barrie@magnolia tmp]$ wget http:// [barrie@magnolia tmp]$ wget http://w [barrie@magnolia tmp]$ wget http://w [barrie@magnolia tmp]$ wget http://ww [barrie@magnolia tmp]$ wget http://ww [barrie@magnolia tmp]$ wget http://www [barrie@magnolia tmp]$ wget http://www [barrie@magnolia tmp]$ wget http://www. [barrie@magnolia tmp]$ wget http://www. [barrie@magnolia tmp]$ wget http://www.p [barrie@magnolia tmp]$ wget http://www.p [barrie@magnolia tmp]$ wget http://www.ps [barrie@magnolia tmp]$ wget http://www.ps [barrie@magnolia tmp]$ wget http://www.psi [barrie@magnolia tmp]$ wget http://www.psi [barrie@magnolia tmp]$ wget http://www.psio [barrie@magnolia tmp]$ wget http://www.psio [barrie@magnolia tmp]$ wget http://www.psion [barrie@magnolia tmp]$ wget http://www.psion [barrie@magnolia tmp]$ wget http://www.psioni [barrie@magnolia tmp]$ wget http://www.psioni [barrie@magnolia tmp]$ wget http://www.psionic [barrie@magnolia tmp]$ wget http://www.psionic [barrie@magnolia tmp]$ wget http://www.psionic. [barrie@magnolia tmp]$ wget http://www.psionic. [barrie@magnolia tmp]$ wget http://www.psionic.c [barrie@magnolia tmp]$ wget http://www.psionic.c [barrie@magnolia tmp]$ wget http://www.psionic.co [barrie@magnolia tmp]$ wget http://www.psionic.co [barrie@magnolia tmp]$ wget http://www.psionic.com [barrie@magnolia tmp]$ wget http://www.psionic.com [barrie@magnolia tmp]$ wget http://www.psionic.com/ [barrie@magnolia tmp]$ wget http://www.psionic.com/ [barrie@magnolia tmp]$ wget http://www.psionic.com/d [barrie@magnolia tmp]$ wget http://www.psionic.com/d [barrie@magnolia tmp]$ wget http://www.psionic.com/do [barrie@magnolia tmp]$ wget http://www.psionic.com/do [barrie@magnolia tmp]$ wget http://www.psionic.com/dow [barrie@magnolia tmp]$ wget http://www.psionic.com/dow [barrie@magnolia tmp]$ wget http://www.psionic.com/down [barrie@magnolia tmp]$ wget http://www.psionic.com/down [barrie@magnolia tmp]$ wget http://www.psionic.com/downl [barrie@magnolia tmp]$ wget http://www.psionic.com/downl [barrie@magnolia tmp]$ wget http://www.psionic.com/downlo [barrie@magnolia tmp]$ wget http://www.psionic.com/downlo [barrie@magnolia tmp]$ wget http://www.psionic.com/downloa [barrie@magnolia tmp]$ wget http://www.psionic.com/downloa [barrie@magnolia tmp]$ wget http://www.psionic.com/download [barrie@magnolia tmp]$ wget http://www.psionic.com/download [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/ [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/ [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/h [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/h [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/ho [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/ho [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hos [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hos [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/host [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/host [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hosts [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hosts [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostse [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostse [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsen [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsen [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsent [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsent [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentr [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentr [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry- [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry- [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry-0 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry-0 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry-0. [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry-0. [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry-0.0 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry-0.0 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry-0.02 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry-0.02 [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry-0.02. [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry-0.02. [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry-0.02.t [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry-0.02.t [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry-0.02.ta [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry-0.02.ta [barrie@magnolia tmp]$ wget http://www.psionic.com/downloads/hostsentry-0.02.tar . . .g .g .gz .gz --16:01:10-- http://www.psionic.com/downloads/hostsentry-0.02.tar.gz => `hostsentry-0.02.tar.gz' Resolving www.psionic.com... done. Connecting to www.psionic.com[216.141.86.16]:80... connected. HTTP request sent, awaiting response... 200 OK Length: 33,983 [application/x-tar] 0% [ ] 0 --.--K/s ETA --:-- 9% [==> ] 3,177 11.53K/s ETA 00:02 24% [=======> ] 8,177 16.50K/s ETA 00:01 41% [==============> ] 14,177 19.44K/s ETA 00:00 63% [======================> ] 21,677 22.33K/s ETA 00:00 85% [==============================> ] 29,177 24.21K/s ETA 00:00 100%[====================================>] 33,983 25.47K/s ETA 00:00 16:01:12 (25.47 KB/s) - `hostsentry-0.02.tar.gz' saved [33983/33983] ]0;barrie@magnolia:~/tmp [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ l [barrie@magnolia tmp]$ l [barrie@magnolia tmp]$ ls [barrie@magnolia tmp]$ ls ctime502_linuxre_en.tar.gz openload-0.1.2.tar.gz done openoffice-1.0.1-8.i386.rpm extra openssl-0.9.6g.tar.gz hostsentry-0.02.tar.gz openssl-0.9.6g.tar.gz.1 httpd-2.0.43.tar.gz perl kernel php logsentry-1.1.1.tar.gz portsentry-1.1.tar.gz nbtscan-1.0.3.tar.gz siege-latest.tar.gz netscape-4.79-1.src.rpm vpnclient-linux-3.6.2a.tar.gz OOo_1.0.1_LinuxIntel_install.tar.gz ]0;barrie@magnolia:~/tmp [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ c [barrie@magnolia tmp]$ c [barrie@magnolia tmp]$ cp [barrie@magnolia tmp]$ cp [barrie@magnolia tmp]$ c [barrie@magnolia tmp]$ c [barrie@magnolia tmp]$  [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ s [barrie@magnolia tmp]$ s [barrie@magnolia tmp]$ su [barrie@magnolia tmp]$ su [barrie@magnolia tmp]$ sud [barrie@magnolia tmp]$ sud [barrie@magnolia tmp]$ sudo [barrie@magnolia tmp]$ sudo [barrie@magnolia tmp]$ sudo [barrie@magnolia tmp]$ sudo [barrie@magnolia tmp]$ sudo c [barrie@magnolia tmp]$ sudo c [barrie@magnolia tmp]$ sudo cp [barrie@magnolia tmp]$ sudo cp [barrie@magnolia tmp]$ sudo cp [barrie@magnolia tmp]$ sudo cp [barrie@magnolia tmp]$ sudo cp l [barrie@magnolia tmp]$ sudo cp l [barrie@magnolia tmp]$ sudo cp lo [barrie@magnolia tmp]$ sudo cp lo [barrie@magnolia tmp]$ sudo cp log [barrie@magnolia tmp]$ sudo cp log [barrie@magnolia tmp]$ sudo cp logs [barrie@magnolia tmp]$ sudo cp logs [barrie@magnolia tmp]$ sudo cp logse [barrie@magnolia tmp]$ sudo cp logse [barrie@magnolia tmp]$ sudo cp logsen [barrie@magnolia tmp]$ sudo cp logsen [barrie@magnolia tmp]$ sudo cp logsent [barrie@magnolia tmp]$ sudo cp logsent [barrie@magnolia tmp]$ sudo cp logsentr [barrie@magnolia tmp]$ sudo cp logsentr [barrie@magnolia tmp]$ sudo cp logsentry [barrie@magnolia tmp]$ sudo cp logsentry [barrie@magnolia tmp]$ sudo cp logsentry- [barrie@magnolia tmp]$ sudo cp logsentry- [barrie@magnolia tmp]$ sudo cp logsentry-1 [barrie@magnolia tmp]$ sudo cp logsentry-1 [barrie@magnolia tmp]$ sudo cp logsentry-1. [barrie@magnolia tmp]$ sudo cp logsentry-1. [barrie@magnolia tmp]$ sudo cp logsentry-1.1 [barrie@magnolia tmp]$ sudo cp logsentry-1.1 [barrie@magnolia tmp]$ sudo cp logsentry-1.1. [barrie@magnolia tmp]$ sudo cp logsentry-1.1. [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1 [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1 [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1. [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1. [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.t [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.t [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.ta [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.ta [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar. [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar. [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.g [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.g [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz / [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz / [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /u [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /u [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /us [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /us [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /usr [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /usr [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /usr/ [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /usr/ [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /usr/l [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /usr/l [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /usr/lo [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /usr/lo [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /usr/loc [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /usr/loc [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /usr/loca [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /usr/loca [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /usr/local [barrie@magnolia tmp]$ sudo cp logsentry-1.1.1.tar.gz /usr/local Password: ]0;barrie@magnolia:~/tmp [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ l [barrie@magnolia tmp]$ l [barrie@magnolia tmp]$ ls [barrie@magnolia tmp]$ ls ctime502_linuxre_en.tar.gz openload-0.1.2.tar.gz done openoffice-1.0.1-8.i386.rpm extra openssl-0.9.6g.tar.gz hostsentry-0.02.tar.gz openssl-0.9.6g.tar.gz.1 httpd-2.0.43.tar.gz perl kernel php logsentry-1.1.1.tar.gz portsentry-1.1.tar.gz nbtscan-1.0.3.tar.gz siege-latest.tar.gz netscape-4.79-1.src.rpm vpnclient-linux-3.6.2a.tar.gz OOo_1.0.1_LinuxIntel_install.tar.gz ]0;barrie@magnolia:~/tmp [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ c [barrie@magnolia tmp]$ c [barrie@magnolia tmp]$ cd [barrie@magnolia tmp]$ cd [barrie@magnolia tmp]$ cd [barrie@magnolia tmp]$ cd [barrie@magnolia tmp]$ cd ! [barrie@magnolia tmp]$ cd ! [barrie@magnolia tmp]$ cd !$ [barrie@magnolia tmp]$ cd !$ cd ls bash: cd: ls: No such file or directory ]0;barrie@magnolia:~/tmp [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ [barrie@magnolia tmp]$ c [barrie@magnolia tmp]$ c [barrie@magnolia tmp]$ cd [barrie@magnolia tmp]$ cd [barrie@magnolia tmp]$ cd [barrie@magnolia tmp]$ cd [barrie@magnolia tmp]$ cd / [barrie@magnolia tmp]$ cd / [barrie@magnolia tmp]$ cd /u [barrie@magnolia tmp]$ cd /u [barrie@magnolia tmp]$ cd /us [barrie@magnolia tmp]$ cd /us [barrie@magnolia tmp]$ cd /usr [barrie@magnolia tmp]$ cd /usr [barrie@magnolia tmp]$ cd /usr/ [barrie@magnolia tmp]$ cd /usr/ [barrie@magnolia tmp]$ cd /usr/l [barrie@magnolia tmp]$ cd /usr/l [barrie@magnolia tmp]$ cd /usr/lo [barrie@magnolia tmp]$ cd /usr/lo [barrie@magnolia tmp]$ cd /usr/loc [barrie@magnolia tmp]$ cd /usr/loc [barrie@magnolia tmp]$ cd /usr/loca [barrie@magnolia tmp]$ cd /usr/loca [barrie@magnolia tmp]$ cd /usr/local [barrie@magnolia tmp]$ cd /usr/local ]0;barrie@magnolia:/usr/local [barrie@magnolia local]$ [barrie@magnolia local]$ [barrie@magnolia local]$ l [barrie@magnolia local]$ l [barrie@magnolia local]$ ls [barrie@magnolia local]$ ls apache2 games logsentry-1.1.1.tar.gz share bin httpd-2.0.43 mysql src CorporateTime include mysql-max-4.0.3-beta-pc-linux-gnu-i686 doc lib php-4.2.3 etc libexec sbin ]0;barrie@magnolia:/usr/local [barrie@magnolia local]$ [barrie@magnolia local]$ [barrie@magnolia local]$ w [barrie@magnolia local]$ w [barrie@magnolia local]$ wh [barrie@magnolia local]$ wh [barrie@magnolia local]$ whi [barrie@magnolia local]$ whi [barrie@magnolia local]$ whic [barrie@magnolia local]$ whic [barrie@magnolia local]$ which [barrie@magnolia local]$ which [barrie@magnolia local]$ which [barrie@magnolia local]$ which [barrie@magnolia local]$ which l [barrie@magnolia local]$ which l [barrie@magnolia local]$ which la [barrie@magnolia local]$ which la [barrie@magnolia local]$ which lao [barrie@magnolia local]$ which lao [barrie@magnolia local]$ which la [barrie@magnolia local]$ which la [barrie@magnolia local]$ which l [barrie@magnolia local]$ which l [barrie@magnolia local]$ which lo [barrie@magnolia local]$ which lo [barrie@magnolia local]$ which log [barrie@magnolia local]$ which log [barrie@magnolia local]$ which logs [barrie@magnolia local]$ which logs [barrie@magnolia local]$ which logse [barrie@magnolia local]$ which logse [barrie@magnolia local]$ which logsen [barrie@magnolia local]$ which logsen [barrie@magnolia local]$ which logsent [barrie@magnolia local]$ which logsent [barrie@magnolia local]$ which logsentr [barrie@magnolia local]$ which logsentr [barrie@magnolia local]$ which logsentry [barrie@magnolia local]$ which logsentry /usr/bin/which: no logsentry in (/usr/local/bin:/bin:/usr/bin:/usr/X11R6/bin:/sbin:/usr/sbin:/usr/local/sbin:/home/barrie/bin:/usr/local/mysql/bin) ]0;barrie@magnolia:/usr/local [barrie@magnolia local]$ [barrie@magnolia local]$ [barrie@magnolia local]$ l [barrie@magnolia local]$ l [barrie@magnolia local]$ lo [barrie@magnolia local]$ lo [barrie@magnolia local]$ loc [barrie@magnolia local]$ loc [barrie@magnolia local]$ loca [barrie@magnolia local]$ loca [barrie@magnolia local]$ locat [barrie@magnolia local]$ locat [barrie@magnolia local]$ locate [barrie@magnolia local]$ locate [barrie@magnolia local]$ locate [barrie@magnolia local]$ locate [barrie@magnolia local]$ locate l [barrie@magnolia local]$ locate l [barrie@magnolia local]$ locate lo [barrie@magnolia local]$ locate lo [barrie@magnolia local]$ locate log [barrie@magnolia local]$ locate log [barrie@magnolia local]$ locate logs [barrie@magnolia local]$ locate logs [barrie@magnolia local]$ locate logse [barrie@magnolia local]$ locate logse [barrie@magnolia local]$ locate logsen [barrie@magnolia local]$ locate logsen [barrie@magnolia local]$ locate logsent [barrie@magnolia local]$ locate logsent [barrie@magnolia local]$ locate logsentr [barrie@magnolia local]$ locate logsentr [barrie@magnolia local]$ locate logsentry [barrie@magnolia local]$ locate logsentry ]0;barrie@magnolia:/usr/local [barrie@magnolia local]$ [barrie@magnolia local]$ [barrie@magnolia local]$ t [barrie@magnolia local]$ t [barrie@magnolia local]$  [barrie@magnolia local]$ [barrie@magnolia local]$ p [barrie@magnolia local]$ p [barrie@magnolia local]$ ps [barrie@magnolia local]$ ps [barrie@magnolia local]$ ps [barrie@magnolia local]$ ps [barrie@magnolia local]$ ps - [barrie@magnolia local]$ ps - [barrie@magnolia local]$ ps -e [barrie@magnolia local]$ ps -e [barrie@magnolia local]$ ps -ef [barrie@magnolia local]$ ps -ef [barrie@magnolia local]$ ps -ef [barrie@magnolia local]$ ps -ef [barrie@magnolia local]$ ps -ef | [barrie@magnolia local]$ ps -ef | [barrie@magnolia local]$ ps -ef | [barrie@magnolia local]$ ps -ef | [barrie@magnolia local]$ ps -ef | g [barrie@magnolia local]$ ps -ef | g [barrie@magnolia local]$ ps -ef | gr [barrie@magnolia local]$ ps -ef | gr [barrie@magnolia local]$ ps -ef | gre [barrie@magnolia local]$ ps -ef | gre [barrie@magnolia local]$ ps -ef | grep [barrie@magnolia local]$ ps -ef | grep [barrie@magnolia local]$ ps -ef | grep [barrie@magnolia local]$ ps -ef | grep [barrie@magnolia local]$ ps -ef | grep l [barrie@magnolia local]$ ps -ef | grep l [barrie@magnolia local]$ ps -ef | grep lo [barrie@magnolia local]$ ps -ef | grep lo [barrie@magnolia local]$ ps -ef | grep log [barrie@magnolia local]$ ps -ef | grep log [barrie@magnolia local]$ ps -ef | grep logc [barrie@magnolia local]$ ps -ef | grep logc [barrie@magnolia local]$ ps -ef | grep logch [barrie@magnolia local]$ ps -ef | grep logch [barrie@magnolia local]$ ps -ef | grep logche [barrie@magnolia local]$ ps -ef | grep logche [barrie@magnolia local]$ ps -ef | grep logchec [barrie@magnolia local]$ ps -ef | grep logchec [barrie@magnolia local]$ ps -ef | grep logcheck [barrie@magnolia local]$ ps -ef | grep logcheck barrie 7059 1188 0 15:24 pts/1 00:00:00 script logcheckinstall021123 barrie 7060 7059 0 15:24 pts/1 00:00:00 script logcheckinstall021123 barrie 7109 7061 0 16:06 pts/3 00:00:00 grep logcheck ]0;barrie@magnolia:/usr/local [barrie@magnolia local]$ [barrie@magnolia local]$ [barrie@magnolia local]$ ps -ef | grep logcheck [barrie@magnolia local]$ ps -ef | grep logcheck [barrie@magnolia local]$ ps -ef | grep logchec [barrie@magnolia local]$ ps -ef | grep logchec [barrie@magnolia local]$ ps -ef | grep logche [barrie@magnolia local]$ ps -ef | grep logche [barrie@magnolia local]$ ps -ef | grep logch [barrie@magnolia local]$ ps -ef | grep logch [barrie@magnolia local]$ ps -ef | grep logc [barrie@magnolia local]$ ps -ef | grep logc [barrie@magnolia local]$ ps -ef | grep log [barrie@magnolia local]$ ps -ef | grep log [barrie@magnolia local]$ ps -ef | grep logs [barrie@magnolia local]$ ps -ef | grep logs [barrie@magnolia local]$ ps -ef | grep logse [barrie@magnolia local]$ ps -ef | grep logse [barrie@magnolia local]$ ps -ef | grep logsen [barrie@magnolia local]$ ps -ef | grep logsen [barrie@magnolia local]$ ps -ef | grep logsent [barrie@magnolia local]$ ps -ef | grep logsent [barrie@magnolia local]$ ps -ef | grep logsentr [barrie@magnolia local]$ ps -ef | grep logsentr [barrie@magnolia local]$ ps -ef | grep logsentry [barrie@magnolia local]$ ps -ef | grep logsentry barrie 7111 7061 0 16:06 pts/3 00:00:00 grep logsentry ]0;barrie@magnolia:/usr/local [barrie@magnolia local]$ [barrie@magnolia local]$ [barrie@magnolia local]$ g [barrie@magnolia local]$ g [barrie@magnolia local]$ gu [barrie@magnolia local]$ gu [barrie@magnolia local]$ gun [barrie@magnolia local]$ gun [barrie@magnolia local]$ gu [barrie@magnolia local]$ gu [barrie@magnolia local]$ g [barrie@magnolia local]$ g [barrie@magnolia local]$  [barrie@magnolia local]$ [barrie@magnolia local]$ s [barrie@magnolia local]$ s [barrie@magnolia local]$ su [barrie@magnolia local]$ su [barrie@magnolia local]$ sud [barrie@magnolia local]$ sud [barrie@magnolia local]$ sudo [barrie@magnolia local]$ sudo [barrie@magnolia local]$ sudo [barrie@magnolia local]$ sudo [barrie@magnolia local]$ sudo g [barrie@magnolia local]$ sudo g [barrie@magnolia local]$ sudo gu [barrie@magnolia local]$ sudo gu [barrie@magnolia local]$ sudo gun [barrie@magnolia local]$ sudo gun [barrie@magnolia local]$ sudo gunc [barrie@magnolia local]$ sudo gunc [barrie@magnolia local]$ sudo gun [barrie@magnolia local]$ sudo gun [barrie@magnolia local]$ sudo gunz [barrie@magnolia local]$ sudo gunz [barrie@magnolia local]$ sudo gunzi [barrie@magnolia local]$ sudo gunzi [barrie@magnolia local]$ sudo gunzip [barrie@magnolia local]$ sudo gunzip [barrie@magnolia local]$ sudo gunzip [barrie@magnolia local]$ sudo gunzip [barrie@magnolia local]$ sudo gunzip l [barrie@magnolia local]$ sudo gunzip l [barrie@magnolia local]$ sudo gunzip lo [barrie@magnolia local]$ sudo gunzip lo [barrie@magnolia local]$ sudo gunzip log [barrie@magnolia local]$ sudo gunzip log [barrie@magnolia local]$ sudo gunzip logs [barrie@magnolia local]$ sudo gunzip logs [barrie@magnolia local]$ sudo gunzip logse [barrie@magnolia local]$ sudo gunzip logse [barrie@magnolia local]$ sudo gunzip logsen [barrie@magnolia local]$ sudo gunzip logsen [barrie@magnolia local]$ sudo gunzip logsent [barrie@magnolia local]$ sudo gunzip logsent [barrie@magnolia local]$ sudo gunzip logsentr [barrie@magnolia local]$ sudo gunzip logsentr [barrie@magnolia local]$ sudo gunzip logsentry [barrie@magnolia local]$ sudo gunzip logsentry [barrie@magnolia local]$ sudo gunzip logsentry- [barrie@magnolia local]$ sudo gunzip logsentry- [barrie@magnolia local]$ sudo gunzip logsentry-1 [barrie@magnolia local]$ sudo gunzip logsentry-1 [barrie@magnolia local]$ sudo gunzip logsentry-1. [barrie@magnolia local]$ sudo gunzip logsentry-1. [barrie@magnolia local]$ sudo gunzip logsentry-1.1 [barrie@magnolia local]$ sudo gunzip logsentry-1.1 [barrie@magnolia local]$ sudo gunzip logsentry-1.1. [barrie@magnolia local]$ sudo gunzip logsentry-1.1. [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1 [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1 [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1. [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1. [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1.t [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1.t [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1.ta [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1.ta [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1.tar [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1.tar [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1.tar. [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1.tar. [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1.tar.g [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1.tar.g [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1.tar.gz [barrie@magnolia local]$ sudo gunzip logsentry-1.1.1.tar.gz ]0;barrie@magnolia:/usr/local [barrie@magnolia local]$ [barrie@magnolia local]$ [barrie@magnolia local]$ l [barrie@magnolia local]$ l [barrie@magnolia local]$ ls [barrie@magnolia local]$ ls apache2 games logsentry-1.1.1.tar share bin httpd-2.0.43 mysql src CorporateTime include mysql-max-4.0.3-beta-pc-linux-gnu-i686 doc lib php-4.2.3 etc libexec sbin ]0;barrie@magnolia:/usr/local [barrie@magnolia local]$ [barrie@magnolia local]$ [barrie@magnolia local]$ s [barrie@magnolia local]$ s [barrie@magnolia local]$ su [barrie@magnolia local]$ su [barrie@magnolia local]$ sud [barrie@magnolia local]$ sud [barrie@magnolia local]$ sudo [barrie@magnolia local]$ sudo [barrie@magnolia local]$ sudo [barrie@magnolia local]$ sudo [barrie@magnolia local]$ sudo [barrie@magnolia local]$ sudo [barrie@magnolia local]$ sud [barrie@magnolia local]$ sud [barrie@magnolia local]$ su [barrie@magnolia local]$ su [barrie@magnolia local]$ s [barrie@magnolia local]$ s [barrie@magnolia local]$  [barrie@magnolia local]$  [barrie@magnolia local]$ [barrie@magnolia local]$ s [barrie@magnolia local]$ s [barrie@magnolia local]$ su [barrie@magnolia local]$ su [barrie@magnolia local]$ sud [barrie@magnolia local]$ sud [barrie@magnolia local]$ sudo [barrie@magnolia local]$ sudo [barrie@magnolia local]$ sudo [barrie@magnolia local]$ sudo [barrie@magnolia local]$ sudo t [barrie@magnolia local]$ sudo t [barrie@magnolia local]$ sudo ta [barrie@magnolia local]$ sudo ta [barrie@magnolia local]$ sudo tar [barrie@magnolia local]$ sudo tar [barrie@magnolia local]$ sudo tar [barrie@magnolia local]$ sudo tar [barrie@magnolia local]$ sudo tar t [barrie@magnolia local]$ sudo tar t [barrie@magnolia local]$ sudo tar tf [barrie@magnolia local]$ sudo tar tf [barrie@magnolia local]$ sudo tar tf [barrie@magnolia local]$ sudo tar tf [barrie@magnolia local]$ sudo tar tf l [barrie@magnolia local]$ sudo tar tf l [barrie@magnolia local]$ sudo tar tf ly [barrie@magnolia local]$ sudo tar tf ly [barrie@magnolia local]$ sudo tar tf lyn [barrie@magnolia local]$ sudo tar tf lyn [barrie@magnolia local]$ sudo tar tf lynx [barrie@magnolia local]$ sudo tar tf lynx [barrie@magnolia local]$ sudo tar tf lynx2 [barrie@magnolia local]$ sudo tar tf lynx2 [barrie@magnolia local]$ sudo tar tf lynx2. [barrie@magnolia local]$ sudo tar tf lynx2. [barrie@magnolia local]$ sudo tar tf lynx2.8 [barrie@magnolia local]$ sudo tar tf lynx2.8 [barrie@magnolia local]$ sudo tar tf lynx2.8. [barrie@magnolia local]$ sudo tar tf lynx2.8. [barrie@magnolia local]$ sudo tar tf lynx2.8.4 [barrie@magnolia local]$ sudo tar tf lynx2.8.4 [barrie@magnolia local]$ sudo tar tf lynx2.8.4. [barrie@magnolia local]$ sudo tar tf lynx2.8.4. [barrie@magnolia local]$ sudo tar tf lynx2.8.4.t [barrie@magnolia local]$ sudo tar tf lynx2.8.4.t [barrie@magnolia local]$ sudo tar tf lynx2.8.4.ta [barrie@magnolia local]$ sudo tar tf lynx2.8.4.ta [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | h [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | h [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | he [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | he [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | hea [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | hea [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | head [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | head [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | hea [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | he [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | h [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar | [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar [barrie@magnolia local]$ sudo tar tf lynx2.8.4.tar [barrie@magnolia local]$ sudo tar tf lynx2.8.4.ta [barrie@magnolia local]$ sudo tar tf lynx2.8.4.t [barrie@magnolia local]$ sudo tar tf lynx2.8.4. [barrie@magnolia local]$ sudo tar tf lynx2.8.4 [barrie@magnolia local]$ sudo tar tf lynx2.8. [barrie@magnolia local]$ sudo tar tf lynx2.8. [barrie@magnolia local]$ sudo tar tf lynx2.8.[1@1 [barrie@magnolia local]$ sudo tar tf lynx2.8.1 [barrie@magnolia local]$ sudo tar tf lynx2.8. [barrie@magnolia local]$ sudo tar tf lynx2.8 [barrie@magnolia local]$ sudo tar tf lynx2. [barrie@magnolia local]$ sudo tar tf lynx2. [barrie@magnolia local]$ sudo tar tf lynx2.[1@1 [barrie@magnolia local]$ sudo tar tf lynx2.1 [barrie@magnolia local]$ sudo tar tf lynx2. [barrie@magnolia local]$ sudo tar tf lynx2 [barrie@magnolia local]$ sudo tar tf lynx [barrie@magnolia local]$ sudo tar tf lynx [barrie@magnolia local]$ sudo tar tf lynx[1@1 [barrie@magnolia local]$ sudo tar tf lynx1 [barrie@magnolia local]$ sudo tar tf lynx [barrie@magnolia local]$ sudo tar tf lynx[1@- [barrie@magnolia local]$ sudo tar tf lynx- [barrie@magnolia local]$ sudo tar tf lynx [barrie@magnolia local]$ sudo tar tf lyn [barrie@magnolia local]$ sudo tar tf lyn [barrie@magnolia local]$ sudo tar tf ly [barrie@magnolia local]$ sudo tar tf ly [barrie@magnolia local]$ sudo tar tf l [barrie@magnolia local]$ sudo tar tf l [barrie@magnolia local]$ sudo tar tf  [barrie@magnolia local]$ sudo tar tf [barrie@magnolia local]$ sudo tar tf [1@l [barrie@magnolia local]$ sudo tar tf l [barrie@magnolia local]$ sudo tar tf l[1@o [barrie@magnolia local]$ sudo tar tf lo [barrie@magnolia local]$ sudo tar tf lo[1@g [barrie@magnolia local]$ sudo tar tf log [barrie@magnolia local]$ sudo tar tf log[1@s [barrie@magnolia local]$ sudo tar tf logs [barrie@magnolia local]$ sudo tar tf logs[1@e [barrie@magnolia local]$ sudo tar tf logse [barrie@magnolia local]$ sudo tar tf logse[1@n [barrie@magnolia local]$ sudo tar tf logsen [barrie@magnolia local]$ sudo tar tf logsen[1@t [barrie@magnolia local]$ sudo tar tf logsent [barrie@magnolia local]$ sudo tar tf logsent[1@r [barrie@magnolia local]$ sudo tar tf logsentr [barrie@magnolia local]$ sudo tar tf logsentr[1@y [barrie@magnolia local]$ sudo tar tf logsentry logcheck-1.1.1/ logcheck-1.1.1/src/ logcheck-1.1.1/src/logtail.c logcheck-1.1.1/systems/ logcheck-1.1.1/systems/sun/ logcheck-1.1.1/systems/sun/logcheck.sh logcheck-1.1.1/systems/sun/logcheck.hacking logcheck-1.1.1/systems/sun/logcheck.ignore logcheck-1.1.1/systems/sun/logcheck.violations logcheck-1.1.1/systems/sun/logcheck.violations.ignore ]0;barrie@magnolia:/usr/local [barrie@magnolia local]$ [barrie@magnolia local]$ [barrie@magnolia local]$ t [barrie@magnolia local]$ t [barrie@magnolia local]$ tr [barrie@magnolia local]$ tr [barrie@magnolia local]$ t [barrie@magnolia local]$ t [barrie@magnolia local]$ ta [barrie@magnolia local]$ ta [barrie@magnolia local]$ tar [barrie@magnolia local]$ tar [barrie@magnolia local]$ tar [barrie@magnolia local]$ tar [barrie@magnolia local]$ tar x [barrie@magnolia local]$ tar x [barrie@magnolia local]$ tar xv [barrie@magnolia local]$ tar xv [barrie@magnolia local]$ tar xvf [barrie@magnolia local]$ tar xvf [barrie@magnolia local]$ tar xvf [barrie@magnolia local]$ tar xvf [barrie@magnolia local]$ tar xvf l [barrie@magnolia local]$ tar xvf l [barrie@magnolia local]$ tar xvf lo [barrie@magnolia local]$ tar xvf lo [barrie@magnolia local]$ tar xvf log [barrie@magnolia local]$ tar xvf log [barrie@magnolia local]$ tar xvf logs [barrie@magnolia local]$ tar xvf logs [barrie@magnolia local]$ tar xvf logse [barrie@magnolia local]$ tar xvf logse [barrie@magnolia local]$ tar xvf logsen [barrie@magnolia local]$ tar xvf logsen [barrie@magnolia local]$ tar xvf logsent [barrie@magnolia local]$ tar xvf logsent [barrie@magnolia local]$ tar xvf logsentr [barrie@magnolia local]$ tar xvf logsentr [barrie@magnolia local]$ tar xvf logsentry [barrie@magnolia local]$ tar xvf logsentry [barrie@magnolia local]$ tar xvf logsentry- [barrie@magnolia local]$ tar xvf logsentry- [barrie@magnolia local]$ tar xvf logsentry-2 [barrie@magnolia local]$ tar xvf logsentry-2 [barrie@magnolia local]$ tar xvf logsentry- [barrie@magnolia local]$ tar xvf logsentry- [barrie@magnolia local]$ tar xvf logsentry-1 [barrie@magnolia local]$ tar xvf logsentry-1 [barrie@magnolia local]$ tar xvf logsentry-1. [barrie@magnolia local]$ tar xvf logsentry-1. [barrie@magnolia local]$ tar xvf logsentry-1.1 [barrie@magnolia local]$ tar xvf logsentry-1.1 [barrie@magnolia local]$ tar xvf logsentry-1.1. [barrie@magnolia local]$ tar xvf logsentry-1.1. [barrie@magnolia local]$ tar xvf logsentry-1.1.1 [barrie@magnolia local]$ tar xvf logsentry-1.1.1 [barrie@magnolia local]$ tar xvf logsentry-1.1.1. [barrie@magnolia local]$ tar xvf logsentry-1.1.1. [barrie@magnolia local]$ tar xvf logsentry-1.1.1.t [barrie@magnolia local]$ tar xvf logsentry-1.1.1.t [barrie@magnolia local]$ tar xvf logsentry-1.1.1.ta [barrie@magnolia local]$ tar xvf logsentry-1.1.1.ta [barrie@magnolia local]$ tar xvf logsentry-1.1.1.tar [barrie@magnolia local]$ tar xvf logsentry-1.1.1.tar [barrie@magnolia local]$ tar xvf logsentry-1.1.1.ta [barrie@magnolia local]$ tar xvf logsentry-1.1.1.t [barrie@magnolia local]$ tar xvf logsentry-1.1.1. [barrie@magnolia local]$ tar xvf logsentry-1.1.1 [barrie@magnolia local]$ tar xvf logsentry-1.1. [barrie@magnolia local]$ tar xvf logsentry-1.1 [barrie@magnolia local]$ tar xvf logsentry-1. [barrie@magnolia local]$ tar xvf logsentry-1 [barrie@magnolia local]$ tar xvf logsentry- [barrie@magnolia local]$ tar xvf logsentry [barrie@magnolia local]$ tar xvf logsentr [barrie@magnolia local]$ tar xvf logsent [barrie@magnolia local]$ tar xvf logsen [barrie@magnolia local]$ tar xvf logse [barrie@magnolia local]$ tar xvf logs [barrie@magnolia local]$ tar xvf log [barrie@magnolia local]$ tar xvf lo [barrie@magnolia local]$ tar xvf l [barrie@magnolia local]$ tar xvf [barrie@magnolia local]$ tar xvf [barrie@magnolia local]$ tar xv [barrie@magnolia local]$ tar x [barrie@magnolia local]$ tar [barrie@magnolia local]$ tar [barrie@magnolia local]$ ta [barrie@magnolia local]$ t [barrie@magnolia local]$ [barrie@magnolia local]$ [1@s [barrie@magnolia local]$ s [barrie@magnolia local]$ s[1@u [barrie@magnolia local]$ su [barrie@magnolia local]$ su[1@d [barrie@magnolia local]$ sud [barrie@magnolia local]$ sud[1@o [barrie@magnolia local]$ sudo [barrie@magnolia local]$ sudo[1@ [barrie@magnolia local]$ sudo logcheck-1.1.1/ logcheck-1.1.1/src/ logcheck-1.1.1/src/logtail.c logcheck-1.1.1/systems/ logcheck-1.1.1/systems/sun/ logcheck-1.1.1/systems/sun/logcheck.sh logcheck-1.1.1/systems/sun/logcheck.hacking logcheck-1.1.1/systems/sun/logcheck.ignore logcheck-1.1.1/systems/sun/logcheck.violations logcheck-1.1.1/systems/sun/logcheck.violations.ignore logcheck-1.1.1/systems/sun/README logcheck-1.1.1/systems/freebsd/ logcheck-1.1.1/systems/freebsd/logcheck.sh logcheck-1.1.1/systems/freebsd/logcheck.hacking logcheck-1.1.1/systems/freebsd/logcheck.ignore logcheck-1.1.1/systems/freebsd/logcheck.violations logcheck-1.1.1/systems/freebsd/logcheck.violations.ignore logcheck-1.1.1/systems/freebsd/README logcheck-1.1.1/systems/linux/ logcheck-1.1.1/systems/linux/logcheck.sh logcheck-1.1.1/systems/linux/logcheck.hacking logcheck-1.1.1/systems/linux/logcheck.ignore logcheck-1.1.1/systems/linux/logcheck.violations logcheck-1.1.1/systems/linux/logcheck.violations.ignore logcheck-1.1.1/systems/linux/README.linux logcheck-1.1.1/systems/linux/README.linux.IMPORTANT logcheck-1.1.1/systems/generic/ logcheck-1.1.1/systems/generic/logcheck.hacking logcheck-1.1.1/systems/generic/logcheck.ignore logcheck-1.1.1/systems/generic/logcheck.sh logcheck-1.1.1/systems/generic/logcheck.violations logcheck-1.1.1/systems/generic/logcheck.violations.ignore logcheck-1.1.1/systems/generic/README logcheck-1.1.1/systems/hpux/ logcheck-1.1.1/systems/hpux/logcheck.hacking logcheck-1.1.1/systems/hpux/logcheck.ignore logcheck-1.1.1/systems/hpux/logcheck.sh logcheck-1.1.1/systems/hpux/logcheck.violations logcheck-1.1.1/systems/hpux/logcheck.violations.ignore logcheck-1.1.1/systems/hpux/README.HPUX logcheck-1.1.1/systems/digital/ logcheck-1.1.1/systems/digital/README logcheck-1.1.1/systems/digital/logcheck.hacking logcheck-1.1.1/systems/digital/logcheck.ignore logcheck-1.1.1/systems/digital/logcheck.sh logcheck-1.1.1/systems/digital/logcheck.violations logcheck-1.1.1/systems/digital/logcheck.violations.ignore logcheck-1.1.1/systems/bsdos/ logcheck-1.1.1/systems/bsdos/logcheck.hacking logcheck-1.1.1/systems/bsdos/logcheck.ignore logcheck-1.1.1/systems/bsdos/logcheck.sh logcheck-1.1.1/systems/bsdos/README.bsdi logcheck-1.1.1/systems/bsdos/logcheck.violations logcheck-1.1.1/systems/bsdos/logcheck.violations.ignore logcheck-1.1.1/systems/bsdos/logcheck.violations.ignoret logcheck-1.1.1/CHANGES logcheck-1.1.1/CREDITS logcheck-1.1.1/INSTALL logcheck-1.1.1/LICENSE logcheck-1.1.1/Makefile logcheck-1.1.1/README logcheck-1.1.1/README.how.to.interpret logcheck-1.1.1/README.keywords ]0;barrie@magnolia:/usr/local [barrie@magnolia local]$ [barrie@magnolia local]$ [barrie@magnolia local]$ l [barrie@magnolia local]$ l [barrie@magnolia local]$ ls [barrie@magnolia local]$ ls apache2 games logcheck-1.1.1 sbin bin httpd-2.0.43 logsentry-1.1.1.tar share CorporateTime include mysql src doc lib mysql-max-4.0.3-beta-pc-linux-gnu-i686 etc libexec php-4.2.3 ]0;barrie@magnolia:/usr/local [barrie@magnolia local]$ [barrie@magnolia local]$ [barrie@magnolia local]$ c [barrie@magnolia local]$ c [barrie@magnolia local]$ cd [barrie@magnolia local]$ cd [barrie@magnolia local]$ cd [barrie@magnolia local]$ cd [barrie@magnolia local]$ cd l [barrie@magnolia local]$ cd l [barrie@magnolia local]$ cd lo [barrie@magnolia local]$ cd lo [barrie@magnolia local]$ cd log [barrie@magnolia local]$ cd log [barrie@magnolia local]$ cd logc [barrie@magnolia local]$ cd logc [barrie@magnolia local]$ cd logch [barrie@magnolia local]$ cd logch [barrie@magnolia local]$ cd logche [barrie@magnolia local]$ cd logche [barrie@magnolia local]$ cd logchec [barrie@magnolia local]$ cd logchec [barrie@magnolia local]$ cd logcheck [barrie@magnolia local]$ cd logcheck [barrie@magnolia local]$ cd logcheck- [barrie@magnolia local]$ cd logcheck- [barrie@magnolia local]$ cd logcheck-1 [barrie@magnolia local]$ cd logcheck-1 [barrie@magnolia local]$ cd logcheck-1. [barrie@magnolia local]$ cd logcheck-1. [barrie@magnolia local]$ cd logcheck-1.1 [barrie@magnolia local]$ cd logcheck-1.1 [barrie@magnolia local]$ cd logcheck-1.1. [barrie@magnolia local]$ cd logcheck-1.1. [barrie@magnolia local]$ cd logcheck-1.1.1 [barrie@magnolia local]$ cd logcheck-1.1.1 ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [barrie@magnolia logcheck-1.1.1]$ [barrie@magnolia logcheck-1.1.1]$ [barrie@magnolia logcheck-1.1.1]$ l [barrie@magnolia logcheck-1.1.1]$ l [barrie@magnolia logcheck-1.1.1]$ ls [barrie@magnolia logcheck-1.1.1]$ ls CHANGES INSTALL Makefile README.how.to.interpret src CREDITS LICENSE README README.keywords systems ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [barrie@magnolia logcheck-1.1.1]$ [barrie@magnolia logcheck-1.1.1]$ [barrie@magnolia logcheck-1.1.1]$ m [barrie@magnolia logcheck-1.1.1]$ m [barrie@magnolia logcheck-1.1.1]$ mo [barrie@magnolia logcheck-1.1.1]$ mo [barrie@magnolia logcheck-1.1.1]$ mor [barrie@magnolia logcheck-1.1.1]$ mor [barrie@magnolia logcheck-1.1.1]$ more [barrie@magnolia logcheck-1.1.1]$ more [barrie@magnolia logcheck-1.1.1]$ more [barrie@magnolia logcheck-1.1.1]$ more [barrie@magnolia logcheck-1.1.1]$ more R [barrie@magnolia logcheck-1.1.1]$ more R [barrie@magnolia logcheck-1.1.1]$ more RE [barrie@magnolia logcheck-1.1.1]$ more RE [barrie@magnolia logcheck-1.1.1]$ more REA [barrie@magnolia logcheck-1.1.1]$ more REA [barrie@magnolia logcheck-1.1.1]$ more READ [barrie@magnolia logcheck-1.1.1]$ more READ [barrie@magnolia logcheck-1.1.1]$ more READM [barrie@magnolia logcheck-1.1.1]$ more READM [barrie@magnolia logcheck-1.1.1]$ more README [barrie@magnolia logcheck-1.1.1]$ more README README: Permission denied ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [barrie@magnolia logcheck-1.1.1]$ [barrie@magnolia logcheck-1.1.1]$ [barrie@magnolia logcheck-1.1.1]$ s [barrie@magnolia logcheck-1.1.1]$ s [barrie@magnolia logcheck-1.1.1]$ su [barrie@magnolia logcheck-1.1.1]$ su [barrie@magnolia logcheck-1.1.1]$ sue [barrie@magnolia logcheck-1.1.1]$ sue [barrie@magnolia logcheck-1.1.1]$ sueo [barrie@magnolia logcheck-1.1.1]$ sueo [barrie@magnolia logcheck-1.1.1]$ sue [barrie@magnolia logcheck-1.1.1]$ sue [barrie@magnolia logcheck-1.1.1]$ su [barrie@magnolia logcheck-1.1.1]$ su [barrie@magnolia logcheck-1.1.1]$ s [barrie@magnolia logcheck-1.1.1]$ s [barrie@magnolia logcheck-1.1.1]$  [barrie@magnolia logcheck-1.1.1]$ [barrie@magnolia logcheck-1.1.1]$ s [barrie@magnolia logcheck-1.1.1]$ s [barrie@magnolia logcheck-1.1.1]$ su [barrie@magnolia logcheck-1.1.1]$ su Password: ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more R [root@magnolia logcheck-1.1.1]# more R [root@magnolia logcheck-1.1.1]# more RE [root@magnolia logcheck-1.1.1]# more RE [root@magnolia logcheck-1.1.1]# more REA [root@magnolia logcheck-1.1.1]# more REA [root@magnolia logcheck-1.1.1]# more READ [root@magnolia logcheck-1.1.1]# more READ [root@magnolia logcheck-1.1.1]# more READM [root@magnolia logcheck-1.1.1]# more READM [root@magnolia logcheck-1.1.1]# more README [root@magnolia logcheck-1.1.1]# more README Title: logcheck Author: Craig H. Rowland License: See LICENSE file. Warranty: Money back guarantee. Not responsible for any consequences from use!! Abstract Logcheck is software package that is designed to automatically run and check system log files for security violations and unusual activity. Logcheck utilizes a program called logtail that remembers the last position it read from in a log file and uses this position on subsequent runs to process new information. All source code is available for review and the implementation was kept simple to avoid problems. This package is a clone of the frequentcheck.sh script from the Trusted Information Systems Gauntlet(tm) firewall package. TIS has granted permission for me to clone this package. Purpose It bothers me to read stories of system administrators who have had a break-in realize it too late and report "Well I checked the logs from two --More--(17%) weeks ago and found such and such had happened..." or "We've never had problems on that system before so we never bothered to check the logs.." Auditing and logging system events is important! What is more important is that system administrators be aware of these events so they can prevent problems that will inevitably occur if you have a system connected to the Internet. What is great about Unix is that virtually all modern implementations support the syslog(8) facility to report, and quite extensively if configured and supported correctly, virtually all happenings good or bad on the host system. This allows the creation of an audit trail that can be used very effectively to subvert potential attacks and alert system administrators that action should be taken. Unfortunately for most Unices (and Windows NT ) it doesn't matter how much you log activity if nobody ever checks the logs which is often the case. This is where logcheck will help. Logcheck automates the auditing process and weeds out "normal" log information to give you a condensed look at problems and potential troublemakers mailed to wherever you please. So you ask: There are other programs out there that do the same thing, --More--(40%) why do I need this one? Well I say try the other ones and see which one fits your needs. There are many out there that are very good (i.e. swatch), and they all come at a great price (free). This package has some features though that may be easier for you to use because it doesn't require a constantly running program and can mail all findings from many systems back to a single location. Additionally, it reports any unusual system messages that you may not have seen before, a distinct advantage as it is often impossible to know every possible syslog message that may come into the logs from the daemons. Design Logcheck is based upon a log checking program called frequentcheck.sh featured in the Gauntlet(tm) firewall package by Trusted Information Systems Inc. (http://www.tis.com). The logcheck shell script and logtail.c program have been completely re-written from scratch and is implemented in a slightly different manner to accommodate for two methods of log file auditing: 1) By reporting everything you tell it to specifically look for via keywords. --More--(60%)  2) By reporting everything you didn't tell it to ignore via keywords. This ensures that important messages are specifically brought to your attention (via the keywords you look for) and that important messages that you may have overlooked are also reported (by only ignoring items you tell it to). The original frequentcheck.sh script was implemented in a somewhat similar manner. The script is a simple shell programming model and the logtail.c program uses basic ANSI C compatible functions with comments and easy to follow source. Unusual tricks and "golly-gee" features have been left out to prevent problems. The logcheck script should be run at least hourly on your hosts from the cron daemon. This script will check files for unusual activity through the use of simple grep(1) commands and will mail all findings (if any) to the administrator. If nothing is found you'll receive no mail. System Information This program comes with default keyword filter files tuned for the firewall --More--(79%) toolkit by TIS and systems running Wietse Venema's TCP Wrapper package (Which ALL systems should be running IMHO). This program is also very BSDish so you may have to tune it a little if you are running something other than a BSD variant (as if there are any other types of unix ;) ). I've tested the program extensively on BSDI 2.x, Linux, HPUX 10.x and FreeBSD 2.x without any hassles or major explosions of any type (although on HPUX you may need to get a real compiler and not that braindead piece of garbage that ships with it). I am _always_ looking for comments and suggestions. Additionally if you have a keyword file you find is nicely tuned for your version of Unix (IRIX, AIX, HP, Solaris, etc. ) please send it to me for inclusion in any subsequent updates. Basic keyword files that work well for BSDI 2.x, FreeBSD, HPUX, Solaris, SunOS and Linux are included. PLEASE read the INSTALL file for proper installation procedures and other tips. If you have any questions, comments, flames, then please e-mail me at crowland@psionic.com Thanks, Craig Rowland --More--(99%) crowland@psionic.com ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]#  [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# s [root@magnolia logcheck-1.1.1]# s [root@magnolia logcheck-1.1.1]#  [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more I [root@magnolia logcheck-1.1.1]# more I [root@magnolia logcheck-1.1.1]# more IN [root@magnolia logcheck-1.1.1]# more IN [root@magnolia logcheck-1.1.1]# more INS [root@magnolia logcheck-1.1.1]# more INS [root@magnolia logcheck-1.1.1]# more INST [root@magnolia logcheck-1.1.1]# more INST [root@magnolia logcheck-1.1.1]# more INSTA [root@magnolia logcheck-1.1.1]# more INSTA [root@magnolia logcheck-1.1.1]# more INSTAL [root@magnolia logcheck-1.1.1]# more INSTAL [root@magnolia logcheck-1.1.1]# more INSTALL [root@magnolia logcheck-1.1.1]# more INSTALL INSTALLATION: Please read the entire file!! Operation --------- Logcheck contains several files: logcheck.sh -- The main script. This file controls all processing and looks at log files with simple grep commands. This file is executed on a timed basis from cron and reports findings to the sysadmin. logtail -- A custom executable that remembers the last position of a text file. This program is used by logcheck to parse out information from the last time the log was opened, this prevents reviewing old material twice. All log files will be processed with this program and will have a file named "########.offset" put in the same directory, where ####### is the name of the log file checked. This file contains the decimal offset information for logtail to work. If you delete it, logtail will parse the file from the beginning again. Logcheck tracks the size and inode of log files to enable it to tell when a log file has been rotated. If the inode of the log changes, or the file size is smaller than the last run, logtail will reset the counter and parse the entire file. --More--(7%)  logcheck.hacking -- This file contains keywords that are certifiable attacks on your system. I leave this file sparse, unless I know what a certain pattern of attack looks like (The default keywords are almost always generated by Internet Security Scanner attacks, or sendmail(8) if it is being fed illegal syntax in address lines). Any keyword in a log file that matches here will generate a report with a more obnoxious header to grab your attention faster: "ACTIVE SYSTEM ATTACK" logcheck.violations -- This file contains keywords of system events that are usually seen as negative. Words such as "denied", "refused", etc. Positive words such as 'su' successes are also put in here. This file is of course not all inclusive and is heavily biased towards FWTK messages and BSDish messages with TCP wrappers installed. Violations here are reported under the heading "Security Violations" in the reports. logcheck.violations.ignore -- This file contains words that are reverse searched against the logcheck.violations file. If these words are found, that entry is not reported. An example of this are the following log entries: Feb 28 21:00:08 nemesis sendmail[5475]: VAA05473: to=crowland, ctladdr=root (0/0), delay=00:00:02, xdelay=00:00:01, mailer=local, stat=refused --More--(16%)  Feb 28 22:13:53 nemesis rshd: refused connect from hacker@evil.com:1490 The top entry is from sendmail and is a fairly common error, the stat line indicates that the remote host refused connections (stat=refused). This can happen for a variety of reasons and generally is not a problem. The bottom line however indicates that a person (hacker@evil.com) has tried unsuccessfully to start an rsh session on my machine, this is bad (of course you shouldn't be running rshd to begin with). The logcheck.violations file will find the word 'refused' and will flag it to be logged, however this will report both instances as being bad and you will get false alarms from sendmail (both had the word refused). By putting the following in the logcheck.violations.ignore file you tell logcheck to ignore the sendmail problem and it will only report to you the bad rsh connection: (in logcheck.violations.ignore) mailer=local, stat=refused --More--(22%) This will prevent reports from any line that contains "refused" but has the rest of the keywords "mailer=local, stat=refused." This is of course pretty basic, and not very intelligent, however you must remember that by forcing you to be specific in what you ignore, you will not overlook something important. A word of caution though, if you don't pick a long enough string to put in the logcheck.violations.ignore file then you could ignore significant events. Be very very careful what you put in here. The default file has only one entry in it to allow grep to run. Tune it to your system carefully! If the above did not make sense at all, leave the file as it is. logcheck.ignore -- This file is the catch-all file for words to look for in the logs and to NOT REPORT. Again be specific with what you want to ignore and go easy on the wildcards. Anything that does not match what is in this file is reported (so you don't risk missing anything) as "Unusual System Activity." The default is again BSDish and biased towards FWTK and TCP Wrappers. To preserve integrity of the scans the following search order and rules are kept: 1) Active System Attacks are reported first. 2) Security Violations are reported second. --More--(31%) 3) Unusual System Events are reported last. Keyword searches on the logcheck.hacking and logcheck.violations file are CASE INSENSITIVE to ensure we don't miss anything. Keyword searches on the logcheck.violations.ignore and logcheck.ignore files are CASE SENSITIVE to ensure again that we don't miss anything. The *.ignore files REQUIRE you to put in the exact text as part of the contents. The more sensitive logcheck.violations and logcheck.hacking files will report on any word, regardless of case, that is found as a match. The whole process follows the following structure: logcheck.sh executes hourly ----> logcheck.sh executes logtail on log files ----> logtail parses off any text from the last time it was run ---> logcheck greps text for system attack messages ---> logcheck greps text for security violations ---> logcheck greps text for security violations to ignore ---> logcheck greps text for all messages to ignore. ---> any messages found are mailed to system admin. Overall it's a very simple process and is surprisingly good at telling you --More--(38%) information about your system you were never aware of, but probably should have been. Installation ------------ If you know what a syslog.conf file is, know you have it set up to log as much information as possible, AND HAVE SECURED THE LOGS, go to step TWO, otherwise you should read step ONE. Step ONE: Configuring syslog daemon and SECURING your log files. Before setting up logcheck, you should ensure that your system is not only running syslog, but that you have it configured for maximum logging. On most all systems I recommend that you send all syslog messages to ONE file for logcheck to parse through. This configuration ensures that messages will not be missed. On BSDish systems this involves editing the file syslog.conf located in /etc. This file contains parameters for syslogd and if you don't understand them, PLEASE check: man syslog.conf --More--(44%)  - OR - A book. Many syslog.conf files are sensitive to using tabs instead of spaces for your entries and you will mysteriously hose syslogd daemon if you put in spaces so be careful. In the syslog.conf file you should put in an entry like this: *.info /var/log/messages Which will log EVERYTHING to the file "messages" located in /var/log. Obviously you should substitute /var/log to the directory typically found on your system. For BSDI and most variants this is /var/log for Linux this is /var/adm. Your syslog.conf file for your site will have the default in it. Remember this will log everything, if you have a very high volume server (for instance: mail) you may want to cut back on the logging to prevent over running of disk space. You can do this in the following way: *.info;mail.none /var/log/messages --More--(50%) mail.notice /var/log/messages This will only log non-standard mail messages, I don't recommend this however as it will make it hard to track mail into and out of your system if someone attempts, or succeeds, to gain entry. Many systems have separate log files for different system services, configuring syslog to do this could look like the following *.info;mail,ftp,daemon,authpriv.none /var/log/messages mail.info /var/log/mail.log ftp.info /var/log/ftp.log daemon.info /var/log/daemon.log authpriv.* /var/log/secure.log This configuration will have separate logs for the general system messages, mail, ftp, daemon and security messages. Logcheck can be setup to check for all of them. Again please see your syslog.conf man page for more information. Now that you have edited your syslog.conf file you need to re-start syslogd by sending the HUP signal to it. --More--(56%) IMPORTANT: You must now go to your log directory (/var/log in the example above) and change the log file to owner root, group wheel and mode 600 on file permissions. First check if the file exists if it doesn't, you should make it. For example if your log files is simply called 'messages' you would do the following: touch /var/log/messages Now you must ensure that you change the permissions in the following way: chown root.wheel /var/log/messages chmod 600 /var/log/messages I also recommend that any other log files have their permissions set in a similar way (at least to mode 600 if you can't change the owner/group). Log files contain very sensitive data about system operations and could contain passwords, system errors, and other data that can reveal vulnerabilites if you are not careful. I personally feel that these files should never be readable by any person other than root. BSD and FreeBSD: You should go to the /etc directory and edit the /etc/daily, /etc/weekly, and /etc/monthly scripts and change the --More--(63%) 'rotate()' script function to change the log permissions on rotation. Simply change the line: cp /dev/null "$file"; chmod 644 "$file" To: cp /dev/null "$file"; chmod 600 "$file" (The above is for BSDI 2.x, BSDI 3.x uses an external rotate function now, just change the mode sent to it from 644 to 600 and you'll be OK. FreeBSD will be similiar to the BSDI 2.x script) When logs are auto-rotated they will have the permissions set automatically. Once these steps have been completed you can move onto step TWO: Step TWO: Logcheck and logtail installation. Logcheck requires the following files to run: logcheck.sh logtail.c logcheck.hacking logcheck.violations logcheck.violations.ignore --More--(68%) logcheck.ignore Pull logcheck.sh into your favorite editor and find the section entitled: CONFIGURATION SECTION. Change the name of the SYSADMIN variable to one of your liking. You can use local names (default is root), or e-mail addresses for remote logging. Go to the section entitled: LOG FILE CONFIGURATION SECTION and either uncomment the log files that apply to you, or add your own. Be sure you know the difference between the > and >> operators before you do this. If you have one of the default system types (Linux, BSDI, FreeBSD, SunOS, Digital) you can simply type "make " and it will install for you at this point. If you are using an alternate path for the files (i.e NOT in /usr/local/whatever), you need to change the path entries for logcheck.hacking, logcheck.violations, logcheck.ignore, logcheck.violations.ignore, and logtail in the main logcheck.sh script. I don't recommend you do this unless you have to. If you changed the default paths /usr/local/etc and /usr/local/bin in the logcheck.sh file you need to edit the Makefile and change INSTALLDIR and INSTALLDIR_BIN to point to the same directories. --More--(76%) Note that the Makefile will create a directory called /usr/local/etc/tmp by default. This is the scratch area for logcheck to handle it's files. I do NOT recommend that you use /tmp for any reason as it is publically accessible and may pose a danger if a user creates symbolic links to trick the logcheck script into overwriting an important system file. I would also change all automated system scripts to use this directory instead of /tmp which is notoriously unsafe. Editing Cron ------------ After installing logcheck, you should edit your local crontab file for root and set logcheck to run once per hour (recommended, although you can do it more frequently, or less frequently, although the absolute minimum in my opinion is once every few hours or so). Examples are the following: Hourly check (BSD Systems and Redhat /etc/crontab): 00 * * * * root /bin/sh /usr/local/etc/logcheck.sh 15 Minute check (Linux Slackware Systems /var/spool/cron/crontabs/root): 00,15,30,45 * * * * /usr/local/etc/logcheck.sh --More--(83%) The 15 minute check I would recommend for firewalls that generally don't produce messages unless they are in trouble. Remember, logcheck does not report anything if it has nothing useful to say (only if the rest of USENET could do this). So running it every 15 minutes will have no impact on your mailbox if the system being watched is quiet. Busier systems can be addressed by less frequent reporting, however longer reports mean you must spend more time analyzing them, and you may not like this either. Again I recommend hourly. After you have edited the crontab, you must send the crond daemon a HUP to reset it. Final Check and Troubleshooting ------------------------------- You are almost done. I recommend that you run the logcheck.sh script by hand to ensure that it reads the log files without errors and sends mail to the right account. You should check that syslog is in fact logging events and that you generate an event or two (just su to root) for logcheck to report. You should have a report mailed to you. Run logcheck multiple times to ensure that you don't get repeat messages. If you get repeat messages then something is wrong with the logtail program (not marking the file correctly) and you should check your log directory --More--(92%) for files that end in *.offset. If you do not see these files there you have a problem with the logtail binary. Run logtail manually against these logs to see if it correctly marks the file offsets. If it still refuses to do it you should check your file permissions and make sure that you are running all this as root. Default file permissions for logcheck files: logcheck* -- 600 -- Read/Write for root ONLY. Owner root. Group Wheel. logtail* -- 700 -- Read/Write/Execute for root ONLY. Owner root. Group Wheel. *** NOTE: None of the files should ever be SUID root for any reason. For the more cautious, you may want to create a special group/user that owns the logfiles and have the logfile scanner run as that user. Configuration to do this should be rather straight forward, just adjust the file permissions on the logcheck files accordingly and ensure they can read and write to the directory where the logs are stored. If you have any questions you can send e-mail for some limited help... unfortunately my schedule keeps me rather busy so be patient with the response... Thanks, Craig Rowland --More--(99%)  crowland@psionic.com ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# w [root@magnolia logcheck-1.1.1]# w [root@magnolia logcheck-1.1.1]# wh [root@magnolia logcheck-1.1.1]# wh [root@magnolia logcheck-1.1.1]# who [root@magnolia logcheck-1.1.1]# who [root@magnolia logcheck-1.1.1]# whoa [root@magnolia logcheck-1.1.1]# whoa [root@magnolia logcheck-1.1.1]# whoam [root@magnolia logcheck-1.1.1]# whoam [root@magnolia logcheck-1.1.1]# whoami [root@magnolia logcheck-1.1.1]# whoami root ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# c [root@magnolia logcheck-1.1.1]# c [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd / [root@magnolia logcheck-1.1.1]# cd / [root@magnolia logcheck-1.1.1]# cd /e [root@magnolia logcheck-1.1.1]# cd /e [root@magnolia logcheck-1.1.1]# cd /et [root@magnolia logcheck-1.1.1]# cd /et [root@magnolia logcheck-1.1.1]# cd /etc [root@magnolia logcheck-1.1.1]# cd /etc ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# v [root@magnolia etc]# v [root@magnolia etc]# vi [root@magnolia etc]# vi [root@magnolia etc]# vi [root@magnolia etc]# vi [root@magnolia etc]# vi s [root@magnolia etc]# vi s [root@magnolia etc]# vi sy [root@magnolia etc]# vi sy [root@magnolia etc]# vi sys [root@magnolia etc]# vi sys [root@magnolia etc]# vi sysl [root@magnolia etc]# vi sysl [root@magnolia etc]# vi syslo [root@magnolia etc]# vi syslo [root@magnolia etc]# vi syslog [root@magnolia etc]# vi syslog [root@magnolia etc]# vi syslog. [root@magnolia etc]# vi syslog. [root@magnolia etc]# vi syslog.c [root@magnolia etc]# vi syslog.c [root@magnolia etc]# vi syslog.co [root@magnolia etc]# vi syslog.co [root@magnolia etc]# vi syslog.con [root@magnolia etc]# vi syslog.con [root@magnolia etc]# vi syslog.conf [root@magnolia etc]# vi syslog.conf [?1048h[?1047h[?1h=[?25h[?25h[?25l"syslog.conf" 26L, 693C# Log all kernel messages to the console. # Logging much else clutters up the screen. #kern.* /dev/console # Log anything (except mail) of level info or higher. # Don't log private authentication messages! *.info;mail.none;authpriv.none;cron.none/var/log/messages # The authpriv file has restricted access. authpriv.*/var/log/secure # Log all the mail messages in one place. mail.*/var/log/maillog # Log cron stuff cron.*/var/log/cron # Everybody gets emergency messages *.emerg* # Save news errors of level crit and higher in a special file. uucp,news.crit/var/log/spooler # Save boot messages also to boot.log local7.*/var/log/boot.log ~ 1,1All[?25h[?25l:[?25hsyslog.conf.last021124 [?25lNot an editor command: syslog.conf.last0211241,1All[?25h[?25l26,1[?25h[?25l:[?25hw syslog.conf.last021123 [?25l"syslog.conf.last021123" [New] 26L, 693C written26,1All26,1All[?25h[?25l[?25h[?25l:[?25hw syslog.conf [?25l"syslog.conf" 26L, 693C written26,1All26,1All[?25h[?25l[?25h[?25l:[?25hq! [?25l[?1l>[?25h[?1047l[?1048l]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# m [root@magnolia etc]# m [root@magnolia etc]# ma [root@magnolia etc]# ma [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man s [root@magnolia etc]# man s [root@magnolia etc]# man sy [root@magnolia etc]# man sy [root@magnolia etc]# man sys [root@magnolia etc]# man sys [root@magnolia etc]# man sysl [root@magnolia etc]# man sysl [root@magnolia etc]# man syslo [root@magnolia etc]# man syslo [root@magnolia etc]# man syslog [root@magnolia etc]# man syslog [root@magnolia etc]# man syslog. [root@magnolia etc]# man syslog. [root@magnolia etc]# man syslog.c [root@magnolia etc]# man syslog.c [root@magnolia etc]# man syslog.co [root@magnolia etc]# man syslog.co [root@magnolia etc]# man syslog.con [root@magnolia etc]# man syslog.con [root@magnolia etc]# man syslog.conf [root@magnolia etc]# man syslog.conf [?1048h[?1047h[?1h=SYSLOG.CONF(5) Linux System Administration SYSLOG.CONF(5) NAME syslog.conf − syslogd(8) configuration file DESCRIPTION The syslog.conf file is the main configuration file for the syslogd(8) which logs system messages on *nix systems. This file specifies rules for logging. For special features see the sysklogd(8) manpage. Every rule consists of two fields, a selector field and an action field. These two fields are separated by one or more spaces or tabs. The selector field specifies a pattern of facilities and priorities belonging to the specified action. Lines starting with a hash mark (‘‘#’’) and empty lines are ignored. This release of syslogd is able to understand an extended syntax. One rule can be divided into several lines if the leading line is termi†nated with an backslash (‘‘\’’). SELECTORS The selector field itself again consists of two parts, a facility and a priority, separated by a period (‘‘.’’). Both parts are case insensi†tive and can also be specified as decimal numbers, but don’t do that, you have been warned. Both facilities and priorities are described in syslog(3). The names mentioned below correspond to the similar : LOG_â€values in /usr/include/syslog.h. The facility is one of the following keywords: auth, authpriv, cron, daemon, kern, lpr, mail, mark, news, security (same as auth), syslog, user, uucp and local0 through local7. The keyword security should not be used anymore and mark is only for internal use and therefore should not be used in applications. Anyway, you may want to specify and redi†rect these messages here. The facility specifies the subsystem that produced the message, i.e. all mail programs log with the mail facility (LOG_MAIL) if they log using syslog. The priority is one of the following keywords, in ascending order: debug, info, notice, warning, warn (same as warning), err, error (same as err), crit, alert, emerg, panic (same as emerg). The keywords error, warn and panic are deprecated and should not be used anymore. The priority defines the severity of the message The behavior of the original BSD syslogd is that all messages of the specified priority and higher are logged according to the given action. This syslogd(8) behaves the same, but has some extensions. In addition to the above mentioned names the syslogd(8) understands the following extensions: An asterisk (‘‘*’’) stands for all facilities or all priorities, depending on where it is used (before or after the period). The keyword none stands for no priority of the given facil†ity. : ESCESCOOAAM syslog(3). The names mentioned below correspond to the similar : ESCESCOOAAM you have been warned. Both facilities and priorities are described in : ESCESCOOAAM tive and can also be specified as decimal numbers, but don’t do that, : ESCESCOOAAM priority, separated by a period (‘‘.’’). Both parts are case insensi†: ESCESCOOAAM The selector field itself again consists of two parts, a facility and a : ESCESCOOAAMSELECTORS : ESCESCOOAAM : ESCESCOOAAM nated with an backslash (‘‘\’’). : ESCESCOOAAM rule can be divided into several lines if the leading line is termi†: ESCESCOOAAM This release of syslogd is able to understand an extended syntax. One : ESCESCOOAAM : ESCESCOOAAM Lines starting with a hash mark (‘‘#’’) and empty lines are ignored. : ESCESCOOAAM : ESCESCOOAAM belonging to the specified action. : ESCESCOOAAM The selector field specifies a pattern of facilities and priorities : ESCESCOOAAM field. These two fields are separated by one or more spaces or tabs. : ESCESCOOAAM Every rule consists of two fields, a selector field and an action : ESCESCOOAAM : ESCESCOOBB (LOG_MAIL) if they log using syslog. : ESCESCOOBB : ESCESCOOBB The priority is one of the following keywords, in ascending order: : ESCESCOOBB debug, info, notice, warning, warn (same as warning), err, error (same : ESCESCOOBB as err), crit, alert, emerg, panic (same as emerg). The keywords : ESCESCOOBB error, warn and panic are deprecated and should not be used anymore. : ESCESCOOBB The priority defines the severity of the message : ESCESCOOBB : ESCESCOOBB The behavior of the original BSD syslogd is that all messages of the : ESCESCOOBB specified priority and higher are logged according to the given action. : ESCESCOOBB This syslogd(8) behaves the same, but has some extensions. : ESCESCOOBB : ESCESCOOBB In addition to the above mentioned names the syslogd(8) understands the : ESCESCOOBB following extensions: An asterisk (‘‘*’’) stands for all facilities or : ESCESCOOBB all priorities, depending on where it is used (before or after the : ESCESCOOBB period). The keyword none stands for no priority of the given facil†: ESCESCOOBB ity. : ESCESCOOBB : ESCESCOOBB You can specify multiple facilities with the same priority pattern in : ESCESCOOBB one statement using the comma (‘‘,’’) operator. You may specify as : ESCESCOOBB much facilities as you want. Remember that only the facility part from : such a statement is taken, a priority part would be skipped. Multiple selectors may be specified for a single action using the semi†colon (‘‘;’’) separator. Remember that each selector in the selector field is capable to overwrite the preceding ones. Using this behavior you can exclude some priorities from the pattern. This syslogd(8) has a syntax extension to the original BSD source, that makes its use more intuitively. You may precede every priority with an equation sign (‘‘=’’) to specify only this single priority and not any of the above. You may also (both is valid, too) precede the priority with an exclamation mark (‘‘!’’) to ignore all that priorities, either exact this one or this and any higher priority. If you use both exten†sions than the exclamation mark must occur before the equation sign, just use it intuitively. ACTIONS The action field of a rule describes the abstract term ‘‘logfile’’. A ‘‘logfile’’ need not to be a real file, btw. The syslogd(8) provides the following actions. Regular File Typically messages are logged to real files. The file has to be speci†fied with full pathname, beginning with a slash ‘‘/’’. You may prefix each entry with the minus ‘‘â€â€™â€™ sign to omit syncing the file after every logging. Note that you might lose information if the : ESCESCOOAAM much facilities as you want. Remember that only the facility part from : ESCESCOOAAM one statement using the comma (‘‘,’’) operator. You may specify as : ESCESCOOAAM You can specify multiple facilities with the same priority pattern in : ESCESCOOAAM : ESCESCOOAAM ity. : ESCESCOOAAM period). The keyword none stands for no priority of the given facil†: Regular File Typically messages are logged to real files. The file has to be speci†fied with full pathname, beginning with a slash ‘‘/’’. You may prefix each entry with the minus ‘‘â€â€™â€™ sign to omit syncing the file after every logging. Note that you might lose information if the system crashes right behind a write attempt. Nevertheless this might give you back some performance, especially if you run programs that use logging in a very verbose manner. Named Pipes This version of syslogd(8) has support for logging output to named pipes (fifos). A fifo or named pipe can be used as a destination for log messages by prepending a pipe symbol (‘‘|’’) to the name of the file. This is handy for debugging. Note that the fifo must be created with the mkfifo(1) command before syslogd(8) is started. Terminal and Console If the file you specified is a tty, special ttyâ€handling is done, same with /dev/console. Remote Machine This syslogd(8) provides full remote logging, i.e. is able to send mes†sages to a remote host running syslogd(8) and to receive messages from remote hosts. The remote host won’t forward the message again, it will just log them locally. To forward messages to another host, prepend the hostname with the at sign (‘‘@’’). : ESCESCOOAAM : ESCESCOOAAM the following actions. : ESCESCOOAAM ‘‘logfile’’ need not to be a real file, btw. The syslogd(8) provides : ESCESCOOAAM The action field of a rule describes the abstract term ‘‘logfile’’. A : ESCESCOOAAMACTIONS : ESCESCOOAAM : ESCESCOOAAM just use it intuitively. : Remote Machine This syslogd(8) provides full remote logging, i.e. is able to send mes†sages to a remote host running syslogd(8) and to receive messages from remote hosts. The remote host won’t forward the message again, it will just log them locally. To forward messages to another host, prepend the hostname with the at sign (‘‘@’’). Using this feature you’re able to control all syslog messages on one host, if all other machines will log remotely to that. This tears down administration needs. List of Users Usually critical messages are also directed to ‘‘root’’ on that machine. You can specify a list of users that shall get the message by simply writing the login. You may specify more than one user by sepa†rating them with commas (‘‘,’’). If they’re logged in they get the message. Don’t think a mail would be sent, that might be too late. Everyone logged on Emergency messages often go to all users currently online to notify them that something strange is happening with the system. To specify this wall(1)â€feature use an asterisk (‘‘*’’). EXAMPLES Here are some example, partially taken from a real existing site and configuration. Hopefully they rub out all questions to the configura†: ESCESCOOAAM with /dev/console. : ESCESCOOAAM If the file you specified is a tty, special ttyâ€handling is done, same : ESCESCOOAAM Terminal and Console : ESCESCOOAAM : ESCESCOOAAM with the mkfifo(1) command before syslogd(8) is started. : ESCESCOOAAM file. This is handy for debugging. Note that the fifo must be created : ESCESCOOAAM log messages by prepending a pipe symbol (‘‘|’’) to the name of the : ESCESCOOBB Emergency messages often go to all users currently online to notify : ESCESCOOBB them that something strange is happening with the system. To specify : ESCESCOOBB this wall(1)â€feature use an asterisk (‘‘*’’). : ESCESCOOBB : ESCESCOOBBEXAMPLES : ESCESCOOBB Here are some example, partially taken from a real existing site and : ESCESCOOBB configuration. Hopefully they rub out all questions to the configura†: ESCESCOOBB tion, if not, drop me (Joey) a line. : ESCESCOOBB : ESCESCOOBB # Store critical stuff in critical : ESCESCOOBB # : ESCESCOOBB *.=crit;kern.none /var/adm/critical : ESCESCOOBB : ESCESCOOBB This will store all messages with the priority crit in the file : ESCESCOOBB /var/adm/critical, except for any kernel message. : ESCESCOOBB : ESCESCOOBB # Kernel messages are first, stored in the kernel : ESCESCOOBB # file, critical messages and higher ones also go : ESCESCOOBB # to another host and to the console : ESCESCOOBB # : ESCESCOOBB kern.* /var/adm/kernel : ESCESCOOBB kern.crit @finlandia : ESCESCOOBB kern.crit /dev/console : ESCESCOOBB kern.info;kern.!err /var/adm/kernelâ€info : ESCESCOOBB : ESCESCOOBB The first rule direct any message that has the kernel facility to the : ESCESCOOBB file /var/adm/kernel. : ESCESCOOBB : ESCESCOOBB The second statement directs all kernel messages of the priority crit : ESCESCOOBB and higher to the remote host finlandia. This is useful, because if : ESCESCOOBB the host crashes and the disks get irreparable errors you might not be : ESCESCOOBB able to read the stored messages. If they’re on a remote host, too, : ESCESCOOBB you still can try to find out the reason for the crash. : ESCESCOOBB : ESCESCOOBB The third rule directs these messages to the actual console, so the : ESCESCOOBB person who works on the machine will get them, too. : ESCESCOOBB : ESCESCOOBB The fourth line tells the syslogd to save all kernel messages that come : ESCESCOOBB with priorities from info up to warning in the file /var/adm/kernel†: ESCESCOOBB info. Everything from err and higher is excluded. : ESCESCOOBB : ESCESCOOBB # The tcp wrapper loggs with mail.info, we display : ESCESCOOBB # all the connections on tty12 : ESCESCOOBB # : ESCESCOOBB mail.=info /dev/tty12 : ESCESCOOBB : ESCESCOOBB This directs all messages that uses mail.info (in source LOG_MAIL | : ESCESCOOBB LOG_INFO) to /dev/tty12, the 12th console. For example the tcpwrapper : ESCESCOOBB tcpd(8) uses this as it’s default. : ESCESCOOBB : ESCESCOOBB # Store all mail concerning stuff in a file : ESCESCOOBB # : ESCESCOOBB mail.*;mail.!=info /var/adm/mail : ESCESCOOBB : ESCESCOOBB This pattern matches all messages that come with the mail facility, : ESCESCOOBB except for the info priority. These will be stored in the file : ESCESCOOBB /var/adm/mail. : ESCESCOOBB : ESCESCOOBB # Log all mail.info and news.info messages to info : ESCESCOOBB # : ESCESCOOBB mail,news.=info /var/adm/info : ESCESCOOBB : ESCESCOOBB This will extract all messages that come either with mail.info or with : ESCESCOOBB news.info and store them in the file /var/adm/info. : ESCESCOOBB : ESCESCOOBB # Log info and notice messages to messages file : ESCESCOOBB # : ESCESCOOBB *.=info;*.=notice;\ : ESCESCOOBB mail.none /var/log/messages : ESCESCOOBB : ESCESCOOBB This lets the syslogd log all messages that come with either the info : ESCESCOOBB or the notice facility into the file /var/log/messages, except for all : ESCESCOOBB messages that use the mail facility. : ESCESCOOBB : ESCESCOOBB # Log info messages to messages file : ESCESCOOBB # : ESCESCOOBB *.=info;\ : ESCESCOOBB mail,news.none /var/log/messages : ESCESCOOBB : ESCESCOOBB This statement causes the syslogd to log all messages that come with : ESCESCOOBB the info priority to the file /var/log/messages. But any message com†: ESCESCOOBB ing either with the mail or the news facility will not be stored. : ESCESCOOBB : ESCESCOOBB # Emergency messages will be displayed using wall : ESCESCOOBB # : ESCESCOOBB *.=emerg * : ESCESCOOBB : ESCESCOOBB This rule tells the syslogd to write all emergency messages to all cur†: ESCESCOOBB rently logged in users. This is the wall action. : ESCESCOOBB : ESCESCOOBB # Messages of the priority alert will be directed : ESCESCOOBB # to the operator : ESCESCOOBB # : ESCESCOOBB *.alert root,joey : ESCESCOOBB : ESCESCOOBB This rule directs all messages with a priority of alert or higher to : ESCESCOOBB the terminals of the operator, i.e. of the users ‘‘root’’ and ‘‘joey’’ : ESCESCOOBB if they’re logged in. : ESCESCOOBB : ESCESCOOBB *.* @finlandia : ESCESCOOBB : ESCESCOOBB This rule would redirect all messages to a remote host called finlan†: ESCESCOOBB dia. This is useful especially in a cluster of machines where all sys†: ESCESCOOBB log messages will be stored on only one machine. : ESCESCOOBB : ESCESCOOBBCONFIGURATION FILE SYNTAX DIFFERENCES : ESCESCOOBB Syslogd uses a slightly different syntax for its configuration file : ESCESCOOBB than the original BSD sources. Originally all messages of a specific : ESCESCOOBB priority and above were forwarded to the log file. The modifiers : ESCESCOOBB ‘‘=’’, ‘‘!’’ and ‘‘â€â€™â€™ were added to make the syslogd more flexible : ESCESCOOBB and to use it in a more intuitive manner. : ESCESCOOBB : ESCESCOOBB The original BSD syslogd doesn’t understand spaces as separators : ESCESCOOBB between the selector and the action field. : ESCESCOOBB : ESCESCOOBBFILES : ESCESCOOBB /etc/syslog.conf : ESCESCOOBB Configuration file for syslogd : ESCESCOOBB : ESCESCOOBBBUGS : ESCESCOOBB The effects of multiple selectors are sometimes not intuitive. For : ESCESCOOBB example ‘‘mail.crit,*.err’’ will select ‘‘mail’’ facility messages at : ESCESCOOBB the level of ‘‘err’’ or higher, not at the level of ‘‘crit’’ or higher. : ESCESCOOBB : ESCESCOOBBSEE ALSO : ESCESCOOBB sysklogd(8), klogd(8), logger(1), syslog(2), syslog(3) : ESCESCOOBB : ESCESCOOBBAUTHORS : ESCESCOOBB The syslogd is taken from BSD sources, Greg Wettstein (greg@wind.enjel†: ESCESCOOBB lic.com) performed the port to Linux, Martin Schulze (joey@linux.de) : ESCESCOOBB made some bugfixes and added some new features. : ESCESCOOBB : ESCESCOOBBVersion 1.3 1 January 1998 SYSLOG.CONF(5) : ESCESCOOBB(END)  ESCESCOOBB(END)  ESCESCOOBB(END)  ESCESCOOBB(END) [?1l>[?1047l[?1048l]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# man syslog.conf [root@magnolia etc]# man syslog.conf [root@magnolia etc]# vi [root@magnolia etc]# vi syslog.conf [?1048h[?1047h[?1h=[?25h[?25h[?25l"syslog.conf" 26L, 693C# Log all kernel messages to the console. # Logging much else clutters up the screen. #kern.* /dev/console # Log anything (except mail) of level info or higher. # Don't log private authentication messages! *.info;mail.none;authpriv.none;cron.none/var/log/messages # The authpriv file has restricted access. authpriv.*/var/log/secure # Log all the mail messages in one place. mail.*/var/log/maillog # Log cron stuff cron.*/var/log/cron # Everybody gets emergency messages *.emerg* # Save news errors of level crit and higher in a special file. uucp,news.crit/var/log/spooler # Save boot messages also to boot.log local7.*/var/log/boot.log ~ 26,1All[?25h[?25l5[?25h[?25l4,0-1[?25h[?25l3,1 [?25h[?25l2[?25h[?25l1,0-1[?25h[?25l0,1 [?25h[?25l19[?25h[?25l8,0-1[?25h[?25l7,1 [?25h[?25l6[?25h[?25l5,0-1[?25h[?25l4[?25h[?25l3,1 [?25h[?25l2[?25h[?25l1,0-1[?25h[?25l0,1 [?25h[?25l9,1 [?25h[?25l8,0-1[?25h[?25l7,1 [?25h[?25l6[?25h[?25l5[?25h[?25l4,0-1[?25h[?25l3,1 [?25h[?25l2[?25h[?25l1[?25h[?25l2[?25h[?25l3[?25h[?25l4,0-1[?25h[?25l5,1 [?25h[?25l:[?25hq! [?25l[?1l>[?25h[?1047l[?1048l]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# c [root@magnolia etc]# c [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd / [root@magnolia etc]# cd / [root@magnolia etc]# cd /v [root@magnolia etc]# cd /v [root@magnolia etc]# cd /va [root@magnolia etc]# cd /va [root@magnolia etc]# cd /var [root@magnolia etc]# cd /var [root@magnolia etc]# cd /var/ [root@magnolia etc]# cd /var/ [root@magnolia etc]# cd /var/l [root@magnolia etc]# cd /var/l [root@magnolia etc]# cd /var/lo [root@magnolia etc]# cd /var/lo [root@magnolia etc]# cd /var/log [root@magnolia etc]# cd /var/log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# l [root@magnolia log]# l [root@magnolia log]# ls [root@magnolia log]# ls [root@magnolia log]# l [root@magnolia log]# l [root@magnolia log]# ll [root@magnolia log]# ll total 1988 -rw------- 1 root root 0 Nov 24 13:11 boot.log -rw------- 1 root root 76261 Nov 24 12:06 boot.log.1 -rw------- 1 root root 12189 Nov 17 07:37 boot.log.2 -rw------- 1 root root 42988 Nov 10 10:53 boot.log.3 -rw------- 1 root root 18426 Nov 3 08:51 boot.log.4 -rw------- 1 root root 1141 Nov 24 20:01 cron -rw------- 1 root root 4459 Nov 24 13:11 cron.1 -rw------- 1 root root 1947 Nov 17 08:42 cron.2 -rw------- 1 root root 4261 Nov 10 11:58 cron.3 -rw------- 1 root root 3095 Nov 3 09:57 cron.4 drwxr-xr-x 2 lp root 4096 Aug 30 06:22 cups -rw-r--r-- 1 root root 8007 Nov 24 12:06 dmesg drwxr-xr-x 2 root root 4096 Sep 5 22:23 gdm drwx------ 2 root root 4096 Oct 27 20:59 httpd -rw-r--r-- 1 root root 66566 Nov 24 12:06 ksyms.0 -rw-r--r-- 1 root root 54353 Nov 24 11:31 ksyms.1 -rw-r--r-- 1 root root 66566 Nov 17 20:38 ksyms.2 -rw-r--r-- 1 root root 66566 Nov 17 20:37 ksyms.3 -rw-r--r-- 1 root root 54353 Nov 17 19:18 ksyms.4 -rw-r--r-- 1 root root 66566 Nov 17 18:30 ksyms.5 -rw-r--r-- 1 root root 54353 Nov 17 14:17 ksyms.6 -r-------- 1 root root 19136220 Nov 24 12:07 lastlog -rw------- 1 root root 0 Nov 24 13:11 maillog -rw------- 1 root root 4332 Nov 24 12:06 maillog.1 -rw------- 1 root root 722 Nov 17 07:37 maillog.2 -rw------- 1 root root 4478 Nov 10 11:58 maillog.3 -rw------- 1 root root 2059 Nov 3 08:51 maillog.4 -rw------- 1 root root 136 Nov 24 16:10 messages -rw------- 1 root root 286631 Nov 24 12:13 messages.1 -rw------- 1 root root 50573 Nov 17 08:30 messages.2 -rw------- 1 root root 169975 Nov 10 10:59 messages.3 -rw------- 1 root root 73520 Nov 3 08:58 messages.4 -rw-r--r-- 1 root root 18238 Nov 24 13:11 rpmpkgs -rw-r--r-- 1 root root 18238 Nov 17 08:42 rpmpkgs.1 -rw-r--r-- 1 root root 18238 Nov 10 11:58 rpmpkgs.2 -rw-r--r-- 1 root root 18168 Nov 9 17:58 rpmpkgs.3 -rw-r--r-- 1 root root 18192 Oct 28 07:20 rpmpkgs.4 drwx------ 2 root root 4096 Aug 28 12:03 samba -rw-r--r-- 1 root root 8824 Oct 18 21:13 scrollkeeper.log -rw------- 1 root root 512 Nov 24 16:09 secure -rw------- 1 root root 3357 Nov 24 12:12 secure.1 -rw------- 1 root root 284 Nov 17 07:37 secure.2 -rw------- 1 root root 2313 Nov 10 10:59 secure.3 -rw------- 1 root root 3994 Nov 3 08:58 secure.4 -rw------- 1 root root 0 Nov 24 13:11 spooler -rw------- 1 root root 0 Nov 17 08:42 spooler.1 -rw------- 1 root root 0 Nov 10 11:58 spooler.2 -rw------- 1 root root 0 Nov 3 09:57 spooler.3 -rw------- 1 root root 0 Oct 27 20:59 spooler.4 -rw-rw-r-- 1 root root 0 Nov 24 13:11 up2date -rw-rw-r-- 1 root root 0 Nov 17 08:42 up2date.1 -rw-rw-r-- 1 root root 0 Nov 10 11:58 up2date.2 -rw-rw-r-- 1 root root 286 Nov 9 17:28 up2date.3 -rw-rw-r-- 1 root root 0 Oct 27 20:59 up2date.4 drwxr-xr-x 2 root root 4096 Jul 1 13:26 vbox -rw-rw-r-- 1 root utmp 302208 Nov 24 16:21 wtmp -rw-rw-r-- 1 root utmp 173184 Nov 3 08:58 wtmp.1 -rw-rw-r-- 1 root barrie 29465 Nov 24 12:07 XFree86.0.log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# q [root@magnolia log]# q [root@magnolia log]#  [root@magnolia log]# [root@magnolia log]# c [root@magnolia log]# c [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd / [root@magnolia log]# cd / [root@magnolia log]# cd /e [root@magnolia log]# cd /e [root@magnolia log]# cd /et [root@magnolia log]# cd /et [root@magnolia log]# cd /etc [root@magnolia log]# cd /etc ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# cd /etc [root@magnolia etc]# cd /etc [root@magnolia etc]# ll [root@magnolia etc]# ll [root@magnolia etc]# cd /var/log [root@magnolia etc]# cd /var/log [root@magnolia etc]# vi syslog.conf [root@magnolia etc]# vi syslog.conf [?1048h[?1047h[?1h=[?25h[?25h[?25l"syslog.conf" 26L, 693C# Log all kernel messages to the console. # Logging much else clutters up the screen. #kern.* /dev/console # Log anything (except mail) of level info or higher. # Don't log private authentication messages! *.info;mail.none;authpriv.none;cron.none/var/log/messages # The authpriv file has restricted access. authpriv.*/var/log/secure # Log all the mail messages in one place. mail.*/var/log/maillog # Log cron stuff cron.*/var/log/cron # Everybody gets emergency messages *.emerg* # Save news errors of level crit and higher in a special file. uucp,news.crit/var/log/spooler # Save boot messages also to boot.log local7.*/var/log/boot.log ~ 5,1All[?25h[?25l:[?25hq! [?25l[?1l>[?25h[?1047l[?1048l]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# c [root@magnolia etc]# c [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd / [root@magnolia etc]# cd / [root@magnolia etc]# cd /v [root@magnolia etc]# cd /v [root@magnolia etc]# cd /va [root@magnolia etc]# cd /va [root@magnolia etc]# cd /var [root@magnolia etc]# cd /var [root@magnolia etc]# cd /var/ [root@magnolia etc]# cd /var/ [root@magnolia etc]# cd /var/l [root@magnolia etc]# cd /var/l [root@magnolia etc]# cd /var/lo [root@magnolia etc]# cd /var/lo [root@magnolia etc]# cd /var/log [root@magnolia etc]# cd /var/log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# l [root@magnolia log]# l [root@magnolia log]# ls [root@magnolia log]# ls [root@magnolia log]# ls [root@magnolia log]# ls [root@magnolia log]# ls | [root@magnolia log]# ls | [root@magnolia log]# ls | [root@magnolia log]# ls | [root@magnolia log]# ls | m [root@magnolia log]# ls | m [root@magnolia log]# ls | mo [root@magnolia log]# ls | mo [root@magnolia log]# ls | mor [root@magnolia log]# ls | mor [root@magnolia log]# ls | more [root@magnolia log]# ls | more boot.log boot.log.1 boot.log.2 boot.log.3 boot.log.4 cron cron.1 cron.2 cron.3 cron.4 cups dmesg gdm httpd ksyms.0 ksyms.1 ksyms.2 ksyms.3 ksyms.4 ksyms.5 ksyms.6 lastlog maillog maillog.1 maillog.2 maillog.3 --More-- ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# l [root@magnolia log]# l [root@magnolia log]# ll [root@magnolia log]# ll [root@magnolia log]# ll [root@magnolia log]# ll [root@magnolia log]# ll | [root@magnolia log]# ll | [root@magnolia log]# ll | [root@magnolia log]# ll | [root@magnolia log]# ll | m [root@magnolia log]# ll | m [root@magnolia log]# ll | mo [root@magnolia log]# ll | mo [root@magnolia log]# ll | mor [root@magnolia log]# ll | mor [root@magnolia log]# ll | more [root@magnolia log]# ll | more total 1988 -rw------- 1 root root 0 Nov 24 13:11 boot.log -rw------- 1 root root 76261 Nov 24 12:06 boot.log.1 -rw------- 1 root root 12189 Nov 17 07:37 boot.log.2 -rw------- 1 root root 42988 Nov 10 10:53 boot.log.3 -rw------- 1 root root 18426 Nov 3 08:51 boot.log.4 -rw------- 1 root root 1141 Nov 24 20:01 cron -rw------- 1 root root 4459 Nov 24 13:11 cron.1 -rw------- 1 root root 1947 Nov 17 08:42 cron.2 -rw------- 1 root root 4261 Nov 10 11:58 cron.3 -rw------- 1 root root 3095 Nov 3 09:57 cron.4 drwxr-xr-x 2 lp root 4096 Aug 30 06:22 cups -rw-r--r-- 1 root root 8007 Nov 24 12:06 dmesg drwxr-xr-x 2 root root 4096 Sep 5 22:23 gdm drwx------ 2 root root 4096 Oct 27 20:59 httpd -rw-r--r-- 1 root root 66566 Nov 24 12:06 ksyms.0 -rw-r--r-- 1 root root 54353 Nov 24 11:31 ksyms.1 -rw-r--r-- 1 root root 66566 Nov 17 20:38 ksyms.2 -rw-r--r-- 1 root root 66566 Nov 17 20:37 ksyms.3 -rw-r--r-- 1 root root 54353 Nov 17 19:18 ksyms.4 -rw-r--r-- 1 root root 66566 Nov 17 18:30 ksyms.5 -rw-r--r-- 1 root root 54353 Nov 17 14:17 ksyms.6 -r-------- 1 root root 19136220 Nov 24 12:07 lastlog -rw------- 1 root root 0 Nov 24 13:11 maillog -rw------- 1 root root 4332 Nov 24 12:06 maillog.1 -rw------- 1 root root 722 Nov 17 07:37 maillog.2 --More-- ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# l [root@magnolia log]# l [root@magnolia log]# ll [root@magnolia log]# ll [root@magnolia log]# ll [root@magnolia log]# ll [root@magnolia log]# ll * [root@magnolia log]# ll * [root@magnolia log]# ll *l [root@magnolia log]# ll *l [root@magnolia log]# ll *lo [root@magnolia log]# ll *lo [root@magnolia log]# ll *log [root@magnolia log]# ll *log [root@magnolia log]# ll *log* [root@magnolia log]# ll *log* [root@magnolia log]# ll *log* [root@magnolia log]# ll *log* [root@magnolia log]# ll *log* | [root@magnolia log]# ll *log* | [root@magnolia log]# ll *log* | [root@magnolia log]# ll *log* | [root@magnolia log]# ll *log* | m [root@magnolia log]# ll *log* | m [root@magnolia log]# ll *log* | mo [root@magnolia log]# ll *log* | mo [root@magnolia log]# ll *log* | mor [root@magnolia log]# ll *log* | mor [root@magnolia log]# ll *log* | more [root@magnolia log]# ll *log* | more -rw------- 1 root root 0 Nov 24 13:11 boot.log -rw------- 1 root root 76261 Nov 24 12:06 boot.log.1 -rw------- 1 root root 12189 Nov 17 07:37 boot.log.2 -rw------- 1 root root 42988 Nov 10 10:53 boot.log.3 -rw------- 1 root root 18426 Nov 3 08:51 boot.log.4 -r-------- 1 root root 19136220 Nov 24 12:07 lastlog -rw------- 1 root root 0 Nov 24 13:11 maillog -rw------- 1 root root 4332 Nov 24 12:06 maillog.1 -rw------- 1 root root 722 Nov 17 07:37 maillog.2 -rw------- 1 root root 4478 Nov 10 11:58 maillog.3 -rw------- 1 root root 2059 Nov 3 08:51 maillog.4 -rw-r--r-- 1 root root 8824 Oct 18 21:13 scrollkeeper.log -rw-rw-r-- 1 root barrie 29465 Nov 24 12:07 XFree86.0.log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# c [root@magnolia log]# c [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd m [root@magnolia log]# cd m [root@magnolia log]# cd me [root@magnolia log]# cd me [root@magnolia log]# cd mee [root@magnolia log]# cd mee [root@magnolia log]# cd me [root@magnolia log]# cd me [root@magnolia log]# cd mes [root@magnolia log]# cd mes [root@magnolia log]# cd mess [root@magnolia log]# cd mess [root@magnolia log]# cd messa [root@magnolia log]# cd messa [root@magnolia log]# cd messag [root@magnolia log]# cd messag [root@magnolia log]# cd messagf [root@magnolia log]# cd messagf [root@magnolia log]# cd messagfe [root@magnolia log]# cd messagfe [root@magnolia log]# cd messagf [root@magnolia log]# cd messagf [root@magnolia log]# cd messag [root@magnolia log]# cd messag [root@magnolia log]# cd message [root@magnolia log]# cd message [root@magnolia log]# cd messages [root@magnolia log]# cd messages bash: cd: messages: Not a directory ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# l [root@magnolia log]# l [root@magnolia log]# ls [root@magnolia log]# ls [root@magnolia log]# ls [root@magnolia log]# ls [root@magnolia log]# ls m [root@magnolia log]# ls m [root@magnolia log]# ls me [root@magnolia log]# ls me [root@magnolia log]# ls me* [root@magnolia log]# ls me* messages messages.1 messages.2 messages.3 messages.4 ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# l [root@magnolia log]# l [root@magnolia log]# ll [root@magnolia log]# ll [root@magnolia log]# ll [root@magnolia log]# ll [root@magnolia log]# ll m [root@magnolia log]# ll m [root@magnolia log]# ll me [root@magnolia log]# ll me [root@magnolia log]# ll me* [root@magnolia log]# ll me* -rw------- 1 root root 136 Nov 24 16:10 messages -rw------- 1 root root 286631 Nov 24 12:13 messages.1 -rw------- 1 root root 50573 Nov 17 08:30 messages.2 -rw------- 1 root root 169975 Nov 10 10:59 messages.3 -rw------- 1 root root 73520 Nov 3 08:58 messages.4 ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# m [root@magnolia log]# m [root@magnolia log]# mo [root@magnolia log]# mo [root@magnolia log]# mor [root@magnolia log]# mor [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more X [root@magnolia log]# more X [root@magnolia log]# more XF [root@magnolia log]# more XF [root@magnolia log]# more XFr [root@magnolia log]# more XFr [root@magnolia log]# more XFre [root@magnolia log]# more XFre [root@magnolia log]# more XFree [root@magnolia log]# more XFree [root@magnolia log]# more XFree8 [root@magnolia log]# more XFree8 [root@magnolia log]# more XFree86 [root@magnolia log]# more XFree86 [root@magnolia log]# more XFree86. [root@magnolia log]# more XFree86. [root@magnolia log]# more XFree86.0 [root@magnolia log]# more XFree86.0 [root@magnolia log]# more XFree86.0. [root@magnolia log]# more XFree86.0. [root@magnolia log]# more XFree86.0.l [root@magnolia log]# more XFree86.0.l [root@magnolia log]# more XFree86.0.lo [root@magnolia log]# more XFree86.0.lo [root@magnolia log]# more XFree86.0.log [root@magnolia log]# more XFree86.0.log XFree86 Version 4.2.0 (Red Hat Linux release: 4.2.0-72) / X Window System (protocol Version 11, revision 0, vendor release 6600) Release Date: 23 January 2002 If the server is older than 6-12 months, or if your card is newer than the above date, look for a newer version before reporting problems. (See http://www.XFree86.Org/) Build Operating System: Linux 2.4.18-11smp i686 [ELF] Build Host: daffy.perf.redhat.com Module Loader present OS Kernel: Linux version 2.4.18-14 (bhcompile@stripples.devel.redhat.com) (gcc version 3.2 20020 903 (Red Hat Linux 8.0 3.2-7)) #1 Wed Sep 4 13:35:50 EDT 2002 Markers: (--) probed, (**) from config file, (==) default setting, (++) from command line, (!!) notice, (II) informational, (WW) warning, (EE) error, (NI) not implemented, (??) unknown. (==) Log file: "/var/log/XFree86.0.log", Time: Sun Nov 24 12:07:10 2002 (==) Using config file: "/etc/X11/XF86Config" (==) ServerLayout "Anaconda Configured" (**) |-->Screen "Screen0" (0) (**) | |-->Monitor "Monitor0" (**) | |-->Device "NVIDIA GeForce 2 MX (generic)" (**) |-->Input Device "Mouse0" (**) |-->Input Device "Mouse1" (**) |-->Input Device "Keyboard0" (**) Option "XkbRules" "xfree86" --More--(4%) (**) XKB: rules: "xfree86" (**) Option "XkbModel" "pc105" (**) XKB: model: "pc105" (**) Option "XkbLayout" "us" (**) XKB: layout: "us" (==) Keyboard: CustomKeycode disabled (**) FontPath set to "unix/:7100" (**) RgbPath set to "/usr/X11R6/lib/X11/rgb" (==) ModulePath set to "/usr/X11R6/lib/modules" (--) using VT number 7 (II) Open APM successful (II) Module ABI versions: XFree86 ANSI C Emulation: 0.1 XFree86 Video Driver: 0.5 XFree86 XInput driver : 0.3 XFree86 Server Extension : 0.1 XFree86 Font Renderer : 0.3 (II) Loader running on linux (II) LoadModule: "bitmap" (II) Loading /usr/X11R6/lib/modules/fonts/libbitmap.a (II) Module bitmap: vendor="The XFree86 Project" compiled for 4.2.0, module version = 1.0.0 Module class: XFree86 Font Renderer ABI class: XFree86 Font Renderer, version 0.3 (II) Loading font Bitmap --More--(6%) (II) LoadModule: "pcidata" (II) Loading /usr/X11R6/lib/modules/libpcidata.a (II) Module pcidata: vendor="The XFree86 Project" compiled for 4.2.0, module version = 0.1.0 ABI class: XFree86 Video Driver, version 0.5 (II) PCI: Probing config type using method 1 (II) PCI: Config type is 1 (II) PCI: stages = 0x03, oldVal1 = 0x8002080c, mode1Res1 = 0x80000000 (II) PCI: PCI scan (all values are in hex) (II) PCI: 00:00:0: chip 8086,1a30 card 8086,1a30 rev 04 class 06,00,00 hdr 00 (II) PCI: 00:01:0: chip 8086,1a31 card 0000,0000 rev 04 class 06,04,00 hdr 01 (II) PCI: 00:1e:0: chip 8086,244e card 0000,0000 rev 05 class 06,04,00 hdr 01 (II) PCI: 00:1f:0: chip 8086,2440 card 0000,0000 rev 05 class 06,01,00 hdr 80 (II) PCI: 00:1f:1: chip 8086,244b card 1462,3981 rev 05 class 01,01,80 hdr 00 (II) PCI: 00:1f:2: chip 8086,2442 card 1462,3981 rev 05 class 0c,03,00 hdr 00 (II) PCI: 00:1f:3: chip 8086,2443 card 1462,3981 rev 05 class 0c,05,00 hdr 00 (II) PCI: 00:1f:4: chip 8086,2444 card 1462,3981 rev 05 class 0c,03,00 hdr 00 (II) PCI: 01:00:0: chip 10de,0111 card 1462,8839 rev b2 class 03,00,00 hdr 00 (II) PCI: 02:01:0: chip 1113,1216 card 10b8,1255 rev 11 class 02,00,00 hdr 00 (II) PCI: 02:03:0: chip 1813,4000 card 0000,0000 rev 02 class 07,80,00 hdr 00 (II) PCI: 02:09:0: chip 13f6,0111 card 1462,3980 rev 10 class 04,01,00 hdr 00 (II) PCI: 02:0a:0: chip 105a,5275 card 105a,1275 rev 01 class 01,04,85 hdr 00 (II) PCI: 02:0c:0: chip 1033,0035 card 1033,0035 rev 41 class 0c,03,10 hdr 80 (II) PCI: 02:0c:1: chip 1033,0035 card 1033,0035 rev 41 class 0c,03,10 hdr 00 (II) PCI: 02:0c:2: chip 1033,00e0 card 1462,3504 rev 02 class 0c,03,20 hdr 00 (II) PCI: End of PCI scan --More--(12%) (II) LoadModule: "scanpci" (II) Loading /usr/X11R6/lib/modules/libscanpci.a (II) Module scanpci: vendor="The XFree86 Project" compiled for 4.2.0, module version = 0.1.0 ABI class: XFree86 Video Driver, version 0.5 (II) UnloadModule: "scanpci" (II) Unloading /usr/X11R6/lib/modules/libscanpci.a (II) Host-to-PCI bridge: (II) PCI-to-ISA bridge: (II) PCI-to-PCI bridge: (II) PCI-to-PCI bridge: (II) Bus 0: bridge is at (0:0:0), (-1,0,0), BCTRL: 0x08 (VGA_EN is set) (II) Bus 0 I/O range: [0] -1 0x00000000 - 0x0000ffff (0x10000) IX[B] (II) Bus 0 non-prefetchable memory range: [0] -1 0x00000000 - 0xffffffff (0x0) MX[B] (II) Bus 0 prefetchable memory range: [0] -1 0x00000000 - 0xffffffff (0x0) MX[B] (II) Bus 1: bridge is at (0:1:0), (0,1,1), BCTRL: 0x0f (VGA_EN is set) (II) Bus 1 I/O range: (II) Bus 1 non-prefetchable memory range: [0] -1 0xddd00000 - 0xdfdfffff (0x2100000) MX[B] (II) Bus 1 prefetchable memory range: [0] -1 0xcda00000 - 0xddafffff (0x10100000) MX[B] (II) Bus 2: bridge is at (0:30:0), (0,2,2), BCTRL: 0x06 (VGA_EN is cleared) (II) Bus 2 I/O range: --More--(16%) ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# more XFree86.0.log [root@magnolia log]# more XFree86.0.log [root@magnolia log]# ll me* [root@magnolia log]# ll me* [root@magnolia log]# ls [root@magnolia log]# ls me* [root@magnolia log]# cd messages [root@magnolia log]# cd messages [root@magnolia log]# ll *log* | more [root@magnolia log]# ll *log* | more -rw------- 1 root root 0 Nov 24 13:11 boot.log -rw------- 1 root root 76261 Nov 24 12:06 boot.log.1 -rw------- 1 root root 12189 Nov 17 07:37 boot.log.2 -rw------- 1 root root 42988 Nov 10 10:53 boot.log.3 -rw------- 1 root root 18426 Nov 3 08:51 boot.log.4 -r-------- 1 root root 19136220 Nov 24 12:07 lastlog -rw------- 1 root root 0 Nov 24 13:11 maillog -rw------- 1 root root 4332 Nov 24 12:06 maillog.1 -rw------- 1 root root 722 Nov 17 07:37 maillog.2 -rw------- 1 root root 4478 Nov 10 11:58 maillog.3 -rw------- 1 root root 2059 Nov 3 08:51 maillog.4 -rw-r--r-- 1 root root 8824 Oct 18 21:13 scrollkeeper.log -rw-rw-r-- 1 root barrie 29465 Nov 24 12:07 XFree86.0.log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# c [root@magnolia log]# c [root@magnolia log]#  [root@magnolia log]# [root@magnolia log]# m [root@magnolia log]# m [root@magnolia log]# mo [root@magnolia log]# mo [root@magnolia log]# mor [root@magnolia log]# mor [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more s [root@magnolia log]# more s [root@magnolia log]# more sc [root@magnolia log]# more sc [root@magnolia log]# more scr [root@magnolia log]# more scr [root@magnolia log]# more scri [root@magnolia log]# more scri [root@magnolia log]# more scrio [root@magnolia log]# more scrio [root@magnolia log]# more scri [root@magnolia log]# more scri [root@magnolia log]# more scr [root@magnolia log]# more scr [root@magnolia log]# more scro [root@magnolia log]# more scro [root@magnolia log]# more scrol [root@magnolia log]# more scrol [root@magnolia log]# more scroll [root@magnolia log]# more scroll [root@magnolia log]# more scrollk [root@magnolia log]# more scrollk [root@magnolia log]# more scrollke [root@magnolia log]# more scrollke [root@magnolia log]# more scrollkee [root@magnolia log]# more scrollkee [root@magnolia log]# more scrollkeep [root@magnolia log]# more scrollkeep [root@magnolia log]# more scrollkeepr [root@magnolia log]# more scrollkeepr [root@magnolia log]# more scrollkeep [root@magnolia log]# more scrollkeep [root@magnolia log]# more scrollkeepe [root@magnolia log]# more scrollkeepe [root@magnolia log]# more scrollkeeper [root@magnolia log]# more scrollkeeper [root@magnolia log]# more scrollkeeper. [root@magnolia log]# more scrollkeeper. [root@magnolia log]# more scrollkeeper.o [root@magnolia log]# more scrollkeeper.o [root@magnolia log]# more scrollkeeper.or [root@magnolia log]# more scrollkeeper.or [root@magnolia log]# more scrollkeeper.org [root@magnolia log]# more scrollkeeper.org [root@magnolia log]# more scrollkeeper.or [root@magnolia log]# more scrollkeeper.or [root@magnolia log]# more scrollkeeper.o [root@magnolia log]# more scrollkeeper.o [root@magnolia log]# more scrollkeeper. [root@magnolia log]# more scrollkeeper. [root@magnolia log]# more scrollkeeper.l [root@magnolia log]# more scrollkeeper.l [root@magnolia log]# more scrollkeeper.lo [root@magnolia log]# more scrollkeeper.lo [root@magnolia log]# more scrollkeeper.log [root@magnolia log]# more scrollkeeper.log Oct 18 09:07:18 PM Installing ScrollKeeper 0.3.10... Oct 18 09:07:18 PM scrollkeeper-rebuilddb: Rebuilding ScrollKeeper database... Oct 18 09:07:18 PM scrollkeeper-update: scrollkeeper-update: /usr/local/share/omf: No such file or directory Oct 18 09:07:18 PM scrollkeeper-update: scrollkeeper-update: /opt/gnome/share/omf: No such file or directory Oct 18 09:07:18 PM scrollkeeper-update: scrollkeeper-update: /opt/gnome-2.0/share/omf: No such f ile or directory Oct 18 09:07:18 PM scrollkeeper-update: scrollkeeper-update: /opt/kde/omf: No such file or direc tory Oct 18 09:07:19 PM scrollkeeper-update: Registering /usr/share/omf/gnome-system-monitor/gnome-sy stem-monitor-C.omf xmlNanoHTTPConnectHost: Failed to resolve host 'scrollkeeper.sourceforge.net' - Non-authoritive host not found or server failure.xmlNanoHTTPConnectHost: Failed to resolve host 'scrollkeeper. sourceforge.net' - Non-authoritive host not found or server failure./usr/share/omf/scrollkeeper/ writing_scrollkeeper_omf_files-C.omf:2: warning: failed to load external entity "http://scrollke eper.sourceforge.net/dtds/scrollkeeper-omf-1.0/scrollkeeper-omf.dtd" p://scrollkeeper.sourceforge.net/dtds/scrollkeeper-omf-1.0/scrollkeeper-omf.dtd ^ Oct 18 09:07:19 PM scrollkeeper-update: Registering /usr/share/omf/scrollkeeper/writing_scrollke eper_omf_files-C.omf Oct 18 09:07:19 PM scrollkeeper-rebuilddb: Done rebuilding ScrollKeeper database. Oct 18 09:07:20 PM scrollkeeper-update: scrollkeeper-update: /usr/local/share/omf: No such file or directory Oct 18 09:07:20 PM scrollkeeper-update: scrollkeeper-update: /opt/gnome/share/omf: No such file or directory --More--(19%) ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# l [root@magnolia log]# l [root@magnolia log]#  [root@magnolia log]# [root@magnolia log]# more scrollkeeper.log [root@magnolia log]# more scrollkeeper.log [root@magnolia log]# ll *log* | more [root@magnolia log]# ll *log* | more -rw------- 1 root root 0 Nov 24 13:11 boot.log -rw------- 1 root root 76261 Nov 24 12:06 boot.log.1 -rw------- 1 root root 12189 Nov 17 07:37 boot.log.2 -rw------- 1 root root 42988 Nov 10 10:53 boot.log.3 -rw------- 1 root root 18426 Nov 3 08:51 boot.log.4 -r-------- 1 root root 19136220 Nov 24 12:07 lastlog -rw------- 1 root root 0 Nov 24 13:11 maillog -rw------- 1 root root 4332 Nov 24 12:06 maillog.1 -rw------- 1 root root 722 Nov 17 07:37 maillog.2 -rw------- 1 root root 4478 Nov 10 11:58 maillog.3 -rw------- 1 root root 2059 Nov 3 08:51 maillog.4 -rw-r--r-- 1 root root 8824 Oct 18 21:13 scrollkeeper.log -rw-rw-r-- 1 root barrie 29465 Nov 24 12:07 XFree86.0.log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# c [root@magnolia log]# c [root@magnolia log]# ch [root@magnolia log]# ch [root@magnolia log]# chm [root@magnolia log]# chm [root@magnolia log]# chmo [root@magnolia log]# chmo [root@magnolia log]# chmod [root@magnolia log]# chmod [root@magnolia log]# chmod [root@magnolia log]# chmod [root@magnolia log]# chmod 6 [root@magnolia log]# chmod 6 [root@magnolia log]# chmod 60 [root@magnolia log]# chmod 60 [root@magnolia log]# chmod 600 [root@magnolia log]# chmod 600 [root@magnolia log]# chmod 600 [root@magnolia log]# chmod 600 [root@magnolia log]# chmod 600 s [root@magnolia log]# chmod 600 s [root@magnolia log]# chmod 600 sc [root@magnolia log]# chmod 600 sc [root@magnolia log]# chmod 600 scr [root@magnolia log]# chmod 600 scr [root@magnolia log]# chmod 600 scro [root@magnolia log]# chmod 600 scro [root@magnolia log]# chmod 600 scrol [root@magnolia log]# chmod 600 scrol [root@magnolia log]# chmod 600 scroll [root@magnolia log]# chmod 600 scroll [root@magnolia log]# chmod 600 scrollk [root@magnolia log]# chmod 600 scrollk [root@magnolia log]# chmod 600 scrollke [root@magnolia log]# chmod 600 scrollke [root@magnolia log]# chmod 600 scrollkee [root@magnolia log]# chmod 600 scrollkee [root@magnolia log]# chmod 600 scrollkeep [root@magnolia log]# chmod 600 scrollkeep [root@magnolia log]# chmod 600 scrollkeepe [root@magnolia log]# chmod 600 scrollkeepe [root@magnolia log]# chmod 600 scrollkeeper [root@magnolia log]# chmod 600 scrollkeeper [root@magnolia log]# chmod 600 scrollkeeper. [root@magnolia log]# chmod 600 scrollkeeper. [root@magnolia log]# chmod 600 scrollkeeper.l [root@magnolia log]# chmod 600 scrollkeeper.l [root@magnolia log]# chmod 600 scrollkeeper.lo [root@magnolia log]# chmod 600 scrollkeeper.lo [root@magnolia log]# chmod 600 scrollkeeper.log [root@magnolia log]# chmod 600 scrollkeeper.log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# chmod 600 scrollkeeper.log [root@magnolia log]# chmod 600 scrollkeeper.log [root@magnolia log]# ll *log* | more [root@magnolia log]# ll *log* | more -rw------- 1 root root 0 Nov 24 13:11 boot.log -rw------- 1 root root 76261 Nov 24 12:06 boot.log.1 -rw------- 1 root root 12189 Nov 17 07:37 boot.log.2 -rw------- 1 root root 42988 Nov 10 10:53 boot.log.3 -rw------- 1 root root 18426 Nov 3 08:51 boot.log.4 -r-------- 1 root root 19136220 Nov 24 12:07 lastlog -rw------- 1 root root 0 Nov 24 13:11 maillog -rw------- 1 root root 4332 Nov 24 12:06 maillog.1 -rw------- 1 root root 722 Nov 17 07:37 maillog.2 -rw------- 1 root root 4478 Nov 10 11:58 maillog.3 -rw------- 1 root root 2059 Nov 3 08:51 maillog.4 -rw------- 1 root root 8824 Oct 18 21:13 scrollkeeper.log -rw-rw-r-- 1 root barrie 29465 Nov 24 12:07 XFree86.0.log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# c [root@magnolia log]# c [root@magnolia log]# ch [root@magnolia log]# ch [root@magnolia log]# cho [root@magnolia log]# cho [root@magnolia log]# chow [root@magnolia log]# chow [root@magnolia log]# chown [root@magnolia log]# chown [root@magnolia log]# chown [root@magnolia log]# chown [root@magnolia log]# chown r [root@magnolia log]# chown r [root@magnolia log]# chown ro [root@magnolia log]# chown ro [root@magnolia log]# chown roo [root@magnolia log]# chown roo [root@magnolia log]# chown root [root@magnolia log]# chown root [root@magnolia log]# chown root. [root@magnolia log]# chown root. [root@magnolia log]# chown root.r [root@magnolia log]# chown root.r [root@magnolia log]# chown root.ro [root@magnolia log]# chown root.ro [root@magnolia log]# chown root.roo [root@magnolia log]# chown root.roo [root@magnolia log]# chown root.root [root@magnolia log]# chown root.root [root@magnolia log]# chown root.root [root@magnolia log]# chown root.root [root@magnolia log]# chown root.root X [root@magnolia log]# chown root.root X [root@magnolia log]# chown root.root XF [root@magnolia log]# chown root.root XF [root@magnolia log]# chown root.root XFr [root@magnolia log]# chown root.root XFr [root@magnolia log]# chown root.root XFre [root@magnolia log]# chown root.root XFre [root@magnolia log]# chown root.root XFree [root@magnolia log]# chown root.root XFree [root@magnolia log]# chown root.root XFree8 [root@magnolia log]# chown root.root XFree8 [root@magnolia log]# chown root.root XFree86 [root@magnolia log]# chown root.root XFree86 [root@magnolia log]# chown root.root XFree86. [root@magnolia log]# chown root.root XFree86. [root@magnolia log]# chown root.root XFree86.0 [root@magnolia log]# chown root.root XFree86.0 [root@magnolia log]# chown root.root XFree86.0. [root@magnolia log]# chown root.root XFree86.0. [root@magnolia log]# chown root.root XFree86.0.l [root@magnolia log]# chown root.root XFree86.0.l [root@magnolia log]# chown root.root XFree86.0.lo [root@magnolia log]# chown root.root XFree86.0.lo [root@magnolia log]# chown root.root XFree86.0.log [root@magnolia log]# chown root.root XFree86.0.log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# chown root.root XFree86.0.log [root@magnolia log]# chown root.root XFree86.0.log [root@magnolia log]# ll *log* | more [root@magnolia log]# ll *log* | more -rw------- 1 root root 0 Nov 24 13:11 boot.log -rw------- 1 root root 76261 Nov 24 12:06 boot.log.1 -rw------- 1 root root 12189 Nov 17 07:37 boot.log.2 -rw------- 1 root root 42988 Nov 10 10:53 boot.log.3 -rw------- 1 root root 18426 Nov 3 08:51 boot.log.4 -r-------- 1 root root 19136220 Nov 24 12:07 lastlog -rw------- 1 root root 0 Nov 24 13:11 maillog -rw------- 1 root root 4332 Nov 24 12:06 maillog.1 -rw------- 1 root root 722 Nov 17 07:37 maillog.2 -rw------- 1 root root 4478 Nov 10 11:58 maillog.3 -rw------- 1 root root 2059 Nov 3 08:51 maillog.4 -rw------- 1 root root 8824 Oct 18 21:13 scrollkeeper.log -rw-rw-r-- 1 root root 29465 Nov 24 12:07 XFree86.0.log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# c [root@magnolia log]# c [root@magnolia log]# ch [root@magnolia log]# ch [root@magnolia log]# chm [root@magnolia log]# chm [root@magnolia log]# chmo [root@magnolia log]# chmo [root@magnolia log]# chmod [root@magnolia log]# chmod [root@magnolia log]# chmod [root@magnolia log]# chmod [root@magnolia log]# chmod 6 [root@magnolia log]# chmod 6 [root@magnolia log]# chmod 60 [root@magnolia log]# chmod 60 [root@magnolia log]# chmod 600 [root@magnolia log]# chmod 600 [root@magnolia log]# chmod 600 [root@magnolia log]# chmod 600 [root@magnolia log]# chmod 600 X [root@magnolia log]# chmod 600 X [root@magnolia log]# chmod 600 XF [root@magnolia log]# chmod 600 XF [root@magnolia log]# chmod 600 XFr [root@magnolia log]# chmod 600 XFr [root@magnolia log]# chmod 600 XFre [root@magnolia log]# chmod 600 XFre [root@magnolia log]# chmod 600 XFree [root@magnolia log]# chmod 600 XFree [root@magnolia log]# chmod 600 XFree8 [root@magnolia log]# chmod 600 XFree8 [root@magnolia log]# chmod 600 XFree86 [root@magnolia log]# chmod 600 XFree86 [root@magnolia log]# chmod 600 XFree86. [root@magnolia log]# chmod 600 XFree86. [root@magnolia log]# chmod 600 XFree86.0 [root@magnolia log]# chmod 600 XFree86.0 [root@magnolia log]# chmod 600 XFree86.0. [root@magnolia log]# chmod 600 XFree86.0. [root@magnolia log]# chmod 600 XFree86.0.l [root@magnolia log]# chmod 600 XFree86.0.l [root@magnolia log]# chmod 600 XFree86.0.lo [root@magnolia log]# chmod 600 XFree86.0.lo [root@magnolia log]# chmod 600 XFree86.0.log [root@magnolia log]# chmod 600 XFree86.0.log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# l [root@magnolia log]# l [root@magnolia log]# ll [root@magnolia log]# ll [root@magnolia log]# l [root@magnolia log]# l [root@magnolia log]#  [root@magnolia log]# [root@magnolia log]# chmod 600 XFree86.0.log [root@magnolia log]# chmod 600 XFree86.0.log [root@magnolia log]# ll *log* | more [root@magnolia log]# ll *log* | more -rw------- 1 root root 0 Nov 24 13:11 boot.log -rw------- 1 root root 76261 Nov 24 12:06 boot.log.1 -rw------- 1 root root 12189 Nov 17 07:37 boot.log.2 -rw------- 1 root root 42988 Nov 10 10:53 boot.log.3 -rw------- 1 root root 18426 Nov 3 08:51 boot.log.4 -r-------- 1 root root 19136220 Nov 24 12:07 lastlog -rw------- 1 root root 0 Nov 24 13:11 maillog -rw------- 1 root root 4332 Nov 24 12:06 maillog.1 -rw------- 1 root root 722 Nov 17 07:37 maillog.2 -rw------- 1 root root 4478 Nov 10 11:58 maillog.3 -rw------- 1 root root 2059 Nov 3 08:51 maillog.4 -rw------- 1 root root 8824 Oct 18 21:13 scrollkeeper.log -rw------- 1 root root 29465 Nov 24 12:07 XFree86.0.log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# ll *log* | more [root@magnolia log]# ll *log* | more [root@magnolia log]# chmod 600 XFree86.0.log [root@magnolia log]# chmod 600 XFree86.0.log [root@magnolia log]# ll *log* | more [root@magnolia log]# ll *log* | more [root@magnolia log]# chown root.root XFree86.0.log [root@magnolia log]# chown root.root XFree86.0.log [root@magnolia log]# ll *log* | more [root@magnolia log]# ll *log* | more [root@magnolia log]# chmod 600 scrollkeeper.log [root@magnolia log]# chmod 600 scrollkeeper.log [root@magnolia log]# ll *log* | more [root@magnolia log]# ll *log* | more [root@magnolia log]# more scrollkeeper.log [root@magnolia log]# more scrollkeeper.log [root@magnolia log]# ll *log* | more [root@magnolia log]# ll *log* | more [root@magnolia log]# more XFree86.0.log [root@magnolia log]# more XFree86.0.log [root@magnolia log]# ll me* [root@magnolia log]# ll me* [root@magnolia log]# ls [root@magnolia log]# ls me* [root@magnolia log]# ll [root@magnolia log]# ll me* -rw------- 1 root root 136 Nov 24 16:10 messages -rw------- 1 root root 286631 Nov 24 12:13 messages.1 -rw------- 1 root root 50573 Nov 17 08:30 messages.2 -rw------- 1 root root 169975 Nov 10 10:59 messages.3 -rw------- 1 root root 73520 Nov 3 08:58 messages.4 ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# c [root@magnolia log]# c [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd / [root@magnolia log]# cd / [root@magnolia log]# cd /e [root@magnolia log]# cd /e [root@magnolia log]# cd /et [root@magnolia log]# cd /et [root@magnolia log]# cd /etc [root@magnolia log]# cd /etc [root@magnolia log]# cd /etc/ [root@magnolia log]# cd /etc/ [root@magnolia log]# cd /etc/d [root@magnolia log]# cd /etc/d [root@magnolia log]# cd /etc/da [root@magnolia log]# cd /etc/da [root@magnolia log]# cd /etc/dai [root@magnolia log]# cd /etc/dai [root@magnolia log]# cd /etc/dail [root@magnolia log]# cd /etc/dail [root@magnolia log]# cd /etc/daily [root@magnolia log]# cd /etc/daily bash: cd: /etc/daily: No such file or directory ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# c [root@magnolia log]# c [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd e [root@magnolia log]# cd e [root@magnolia log]# cd et [root@magnolia log]# cd et [root@magnolia log]# cd etc [root@magnolia log]# cd etc [root@magnolia log]# cd et [root@magnolia log]# cd et [root@magnolia log]# cd e [root@magnolia log]# cd e [root@magnolia log]# cd  [root@magnolia log]# cd [root@magnolia log]# cd / [root@magnolia log]# cd / [root@magnolia log]# cd /e [root@magnolia log]# cd /e [root@magnolia log]# cd /et [root@magnolia log]# cd /et [root@magnolia log]# cd /etc [root@magnolia log]# cd /etc ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# l [root@magnolia etc]# l [root@magnolia etc]# ls [root@magnolia etc]# ls a2ps.cfg gshadow mail.rc rc5.d a2ps-site.cfg gshadow- makedev.d rc6.d adjtime gtk man.config rc.d aep gtk-2.0 mime-magic rc.local aep.conf host.conf mime-magic.dat rc.sysinit aeplog.conf hosts mime.types redhat-release alchemist hosts.allow minicom.users resolv.conf aliases hosts.deny modules.conf rmt aliases.db hotplug modules.conf~ rndc.conf aliasesLAST20021019 htdig.conf motd rndc.key alternatives httpd mtab rpc anacrontab im_palette.pal mtools.conf rpm at.deny im_palette-small.pal Muttrc samba auto.master im_palette-tiny.pal named.custom sane.d auto.misc imrc nscd.conf screenrc bashrc info-dir nsswitch.conf scrollkeeper.conf bonobo-activation init.d ntp securetty cdrecord.conf initlog.conf ntp.conf security CiscoSystemsVPNClient inittab oaf sensors.conf CORBA inputrc openldap services cron.d ioctl.save openoffice sgml cron.daily iproute2 opt shadow cron.hourly isdn pam.d shadow- cron.monthly issue pam_smb.conf shells crontab issue.net pango skel cron.weekly kde paper.config slrn.rc csh.cshrc kderc passwd smrsh csh.login krb5.conf passwd- snmp cups krb.conf passwdLAST20021020 sound default krb.realms passwd.OLD ssh DIR_COLORS ksysguarddrc pbm2ppa.conf sudoers DIR_COLORS.xterm ldap.conf pcmcia sudoersLAST20021019 dumpdates ld.so.cache pine.conf sysconfig esd.conf ld.so.conf pine.conf.fixed sysctl.conf ethereal lftp.conf pinforc syslog.conf exports libuser.conf pnm2ppa.conf syslog.conf.last021123 fam.conf lilo.conf.anaconda postfix termcap fb.modes locale ppp updatedb.conf fdprm localtime printcap updfstab.conf filesystems log.d printcap.local updfstab.conf.default fonts login.defs printcap.old vfontcap fstab logrotate.conf printconf.local vfs fstab.REVOKE logrotate.d profile warnquota.conf gconf lpd.conf profile.d webalizer.conf gimp lpd.perms protocols wgetrc gnome ltrace.conf pwdb.conf X11 gnome-vfs-2.0 lvmtab rc xinetd.conf gnome-vfs-mime-magic lvmtab.d rc0.d xinetd.d gpm-root.conf lynx.cfg rc1.d xml group lynx-site.cfg rc2.d xpdfrc group- mail rc3.d yp.conf grub.conf mailcap rc4.d ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# l [root@magnolia etc]# l [root@magnolia etc]# ls [root@magnolia etc]# ls [root@magnolia etc]# ls [root@magnolia etc]# ls [root@magnolia etc]# ls d [root@magnolia etc]# ls d [root@magnolia etc]# ls d* [root@magnolia etc]# ls d* dumpdates default: useradd ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]#  [root@magnolia etc]# [root@magnolia etc]# c [root@magnolia etc]# c [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd c [root@magnolia etc]# cd c [root@magnolia etc]# cd cr [root@magnolia etc]# cd cr [root@magnolia etc]# cd cro [root@magnolia etc]# cd cro [root@magnolia etc]# cd cron [root@magnolia etc]# cd cron [root@magnolia etc]# cd cron. [root@magnolia etc]# cd cron. [root@magnolia etc]# cd cron.d [root@magnolia etc]# cd cron.d [root@magnolia etc]# cd cron.da [root@magnolia etc]# cd cron.da [root@magnolia etc]# cd cron.dai [root@magnolia etc]# cd cron.dai [root@magnolia etc]# cd cron.dail [root@magnolia etc]# cd cron.dail [root@magnolia etc]# cd cron.daily [root@magnolia etc]# cd cron.daily ]0;barrie@magnolia:/etc/cron.daily [root@magnolia cron.daily]# [root@magnolia cron.daily]# [root@magnolia cron.daily]# l [root@magnolia cron.daily]# l [root@magnolia cron.daily]# ls [root@magnolia cron.daily]# ls 00-logwatch 0anacron makewhatis.cron slocate.cron tmpwatch 00webalizer logrotate rpm tetex.cron ]0;barrie@magnolia:/etc/cron.daily [root@magnolia cron.daily]# [root@magnolia cron.daily]# [root@magnolia cron.daily]# [root@magnolia cron.daily]# [root@magnolia cron.daily]#  [root@magnolia cron.daily]#  [root@magnolia cron.daily]# [root@magnolia cron.daily]# m [root@magnolia cron.daily]# m [root@magnolia cron.daily]# mo [root@magnolia cron.daily]# mo [root@magnolia cron.daily]# mor [root@magnolia cron.daily]# mor [root@magnolia cron.daily]# more [root@magnolia cron.daily]# more [root@magnolia cron.daily]# more [root@magnolia cron.daily]# more [root@magnolia cron.daily]# more l [root@magnolia cron.daily]# more l [root@magnolia cron.daily]# more lo [root@magnolia cron.daily]# more lo [root@magnolia cron.daily]# more log [root@magnolia cron.daily]# more log [root@magnolia cron.daily]# more logr [root@magnolia cron.daily]# more logr [root@magnolia cron.daily]# more logro [root@magnolia cron.daily]# more logro [root@magnolia cron.daily]# more logrot [root@magnolia cron.daily]# more logrot [root@magnolia cron.daily]# more logrota [root@magnolia cron.daily]# more logrota [root@magnolia cron.daily]# more logrotat [root@magnolia cron.daily]# more logrotat [root@magnolia cron.daily]# more logrotate [root@magnolia cron.daily]# more logrotate #!/bin/sh /usr/sbin/logrotate /etc/logrotate.conf ]0;barrie@magnolia:/etc/cron.daily [root@magnolia cron.daily]# [root@magnolia cron.daily]# [root@magnolia cron.daily]# c [root@magnolia cron.daily]# c [root@magnolia cron.daily]# cd [root@magnolia cron.daily]# cd [root@magnolia cron.daily]# cd [root@magnolia cron.daily]# cd [root@magnolia cron.daily]# cd / [root@magnolia cron.daily]# cd / [root@magnolia cron.daily]# cd /e [root@magnolia cron.daily]# cd /e [root@magnolia cron.daily]# cd /et [root@magnolia cron.daily]# cd /et [root@magnolia cron.daily]# cd /etc [root@magnolia cron.daily]# cd /etc [root@magnolia cron.daily]# cd /etc/ [root@magnolia cron.daily]# cd /etc/ [root@magnolia cron.daily]# cd /etc [root@magnolia cron.daily]# cd /etc ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# m [root@magnolia etc]# m [root@magnolia etc]# mo [root@magnolia etc]# mo [root@magnolia etc]# mor [root@magnolia etc]# mor [root@magnolia etc]# more [root@magnolia etc]# more [root@magnolia etc]# more [root@magnolia etc]# more [root@magnolia etc]# more l [root@magnolia etc]# more l [root@magnolia etc]# more lo [root@magnolia etc]# more lo [root@magnolia etc]# more log [root@magnolia etc]# more log [root@magnolia etc]# more logr [root@magnolia etc]# more logr [root@magnolia etc]# more logro [root@magnolia etc]# more logro [root@magnolia etc]# more logrot [root@magnolia etc]# more logrot [root@magnolia etc]# more logrota [root@magnolia etc]# more logrota [root@magnolia etc]# more logrotat [root@magnolia etc]# more logrotat [root@magnolia etc]# more logrotate [root@magnolia etc]# more logrotate [root@magnolia etc]# more logrotate. [root@magnolia etc]# more logrotate. [root@magnolia etc]# more logrotate.c [root@magnolia etc]# more logrotate.c [root@magnolia etc]# more logrotate.co [root@magnolia etc]# more logrotate.co [root@magnolia etc]# more logrotate.con [root@magnolia etc]# more logrotate.con [root@magnolia etc]# more logrotate.conf [root@magnolia etc]# more logrotate.conf # see "man logrotate" for details # rotate log files weekly weekly # keep 4 weeks worth of backlogs rotate 4 # create new (empty) log files after rotating old ones create # uncomment this if you want your log files compressed #compress # RPM packages drop log rotation information into this directory include /etc/logrotate.d # no packages own wtmp -- we'll rotate them here /var/log/wtmp { monthly create 0664 root utmp rotate 1 } # system-specific logs may be also be configured here. ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# m [root@magnolia etc]# m [root@magnolia etc]# ma [root@magnolia etc]# ma [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man l [root@magnolia etc]# man l [root@magnolia etc]# man lo [root@magnolia etc]# man lo [root@magnolia etc]# man log [root@magnolia etc]# man log [root@magnolia etc]# man logr [root@magnolia etc]# man logr [root@magnolia etc]# man logro [root@magnolia etc]# man logro [root@magnolia etc]# man logrot [root@magnolia etc]# man logrot [root@magnolia etc]# man logrota [root@magnolia etc]# man logrota [root@magnolia etc]# man logrotat [root@magnolia etc]# man logrotat [root@magnolia etc]# man logrotate [root@magnolia etc]# man logrotate [?1048h[?1047h[?1h=LOGROTATE(8) System Administrator’s Manual LOGROTATE(8) NAME logrotate − rotates, compresses, and mails system logs SYNOPSIS logrotate [â€dv] [â€f|â€â€force] [â€s|â€â€state file] config_file+ DESCRIPTION logrotate is designed to ease administration of systems that generate large numbers of log files. It allows automatic rotation, compression, removal, and mailing of log files. Each log file may be handled daily, weekly, monthly, or when it grows too large. Normally, logrotate is run as a daily cron job. It will not modify a log multiple times in one day unless the criterium for that log is based on the log’s size and logrotate is being run multiple times each day, or unless the â€f or â€force option is used. Any number of config files may be given on the command line. Later con†fig files may override the options given in earlier files, so the order in which the logrotate config files are listed in is important. Nor†mally, a single config file which includes any other config files which are needed should be used. See below for more information on how to use the include directive to accomplish this. If a directory is given on the command line, every file in that directory is used as a config file. : If no command line arguments are given, logrotate will print version and copyright information, along with a short usage summary. If any errors occur while rotating logs, logrotate will exit with nonâ€zero status. OPTIONS â€d Turns on debug mode and implies â€v. In debug mode, no changes will be made to the logs or to the logrotate state file. â€f, â€âˆ’force Tells logrotate to force the rotation, even if it doesn’t think this is necessary. Sometimes this is useful after adding new entries to logrotate, or if old log files have been removed by hand, as the new files will be created, and logging will con†tinue correctly. â€m, â€âˆ’mail  Tells logrotate which command to use when mailing logs. This command should accept two arguments: 1) the subject of the mes†sage, and 2) the recipient. The command must then read a message on standard input and mail it to the recipient. The default mail command is /bin/mail â€s. â€s, â€âˆ’state  Tells logrotate to use an alternate state file. This is useful if logrotate is being run as a different user for various sets : of log files. The default state file is /var/lib/logrotate/sta†tus. â€âˆ’usage Prints a short usage message. CONFIGURATION FILE logrotate reads everything about the log files it should be handling from the series of configuration files specified on the command line. Each configuration file can set global options (local definitions over†ride global ones, and later definitions override earlier ones) and specify a logfile to rotate. A simple configuration file looks like this: # sample logrotate configuration file compress /var/log/messages { rotate 5 weekly postrotate /sbin/killall â€HUP syslogd endscript } "/var/log/httpd/access.log" /var/log/httpd/error.log { rotate 5 : mail www@my.org size=100k sharedscripts postrotate /sbin/killall â€HUP httpd endscript } /var/log/news/* { monthly rotate 2 olddir /var/log/news/old missingok postrotate kill â€HUP ‘cat /var/run/inn.pid‘ endscript nocompress } The first few lines set global options; in the example, logs are com†pressed after they are rotated. Note that comments may appear anywhere in the config file as long as the first nonâ€whitespace character on the line is a #. The next section of the config files defined how to handle the log file /var/log/messages. The log will go through five weekly rotations before being removed. After the log file has been rotated (but before the old : version of the log has been compressed), the command /sbin/killall â€HUP syslogd will be executed. The next section defines the parameters for both /var/log/httpd/access.log and /var/log/httpd/error.log. They are rotated whenever is grows over 100k is size, and the old logs files are mailed (uncompressed) to www@my.org after going through 5 rotations, rather then being removed. The sharedscripts means that the postrotate script will only be run once, not once for each log which is rotated. Note that the double quotes around the first filename at the beginning of this section allows logrotate to rotate logs with spaces in the name. Normal shell quoting rules apply, with ’, ", and \ characters supported. The last section defines the parameters for all of the files in /var/log/news. Each file is rotated on a monthly basis. This is con†sidered a single rotation directive and if errors occur for more then one file, the log files are not compressed. Please use wildcards with caution. If you specify *, logrotate will rotate all files, including previously rotated ones. A way around this is to use the olddir directive or a more exact wildcard (such as *.log). Here is more information on the directives which may be included in a logrotate configuration file: : ESCESCOOAAM being removed. After the log file has been rotated (but before the old : ESCESCOOAAM /var/log/messages. The log will go through five weekly rotations before : ESCESCOOAAM The next section of the config files defined how to handle the log file : ESCESCOOAAM : ESCESCOOAAM line is a #. : ESCESCOOAAM in the config file as long as the first nonâ€whitespace character on the : ESCESCOOAAM pressed after they are rotated. Note that comments may appear anywhere : ESCESCOOAAM The first few lines set global options; in the example, logs are com†: ESCESCOOAAM : ESCESCOOAAM } : ESCESCOOAAM nocompress : ESCESCOOAAM endscript : ESCESCOOAAM kill â€HUP ‘cat /var/run/inn.pid‘ : ESCESCOOAAM postrotate : ESCESCOOAAM missingok : ESCESCOOAAM olddir /var/log/news/old : ESCESCOOAAM rotate 2 : ESCESCOOAAM monthly : ESCESCOOAAM /var/log/news/* { : ESCESCOOAAM : ESCESCOOAAM } : ESCESCOOAAM endscript : ESCESCOOAAM /sbin/killall â€HUP httpd : ESCESCOOBB /var/log/httpd/access.log and /var/log/httpd/error.log. They are : ESCESCOOBB rotated whenever is grows over 100k is size, and the old logs files are : ESCESCOOBB mailed (uncompressed) to www@my.org after going through 5 rotations, : ESCESCOOBB rather then being removed. The sharedscripts means that the postrotate : ESCESCOOBB script will only be run once, not once for each log which is rotated. : ESCESCOOBB Note that the double quotes around the first filename at the beginning : ESCESCOOBB of this section allows logrotate to rotate logs with spaces in the : ESCESCOOBB name. Normal shell quoting rules apply, with ’, ", and \ characters : ESCESCOOBB supported. : ESCESCOOBB : ESCESCOOBB The last section defines the parameters for all of the files in : ESCESCOOBB /var/log/news. Each file is rotated on a monthly basis. This is con†: ESCESCOOBB sidered a single rotation directive and if errors occur for more then : ESCESCOOBB one file, the log files are not compressed. : ESCESCOOBB : ESCESCOOBB Please use wildcards with caution. If you specify *, logrotate will : ESCESCOOBB rotate all files, including previously rotated ones. A way around this : ESCESCOOBB is to use the olddir directive or a more exact wildcard (such as : ESCESCOOBB *.log). : ESCESCOOBB : ESCESCOOBB Here is more information on the directives which may be included in a : ESCESCOOBB logrotate configuration file: : ESCESCOOBB : ESCESCOOBB compress : ESCESCOOBB Old versions of log files are compressed with gzip by default. : ESCESCOOBB See also nocompress. : ESCESCOOBB : ESCESCOOBB compresscmd : ESCESCOOBB Specifies which command to use to compress log files. The : ESCESCOOBB default is gzip. See also compress. : ESCESCOOBB : ESCESCOOBB uncompresscmd : ESCESCOOBB Specifies which command to use to uncompress log files. The : ESCESCOOBB default is gunzip. : ESCESCOOBB : ESCESCOOBB compressext : ESCESCOOBB Specifies which extension to use on compressed logfiles, if com†: ESCESCOOBB pression is enabled. The default follows that of the configured : ESCESCOOBB compression command. : ESCESCOOBB : ESCESCOOBB compressoptions : ESCESCOOBB Command line options may be passed to the compression program, : ESCESCOOBB if one is in use. The default, for gzip, is "â€9" (maximum com†: ESCESCOOBB pression). : ESCESCOOBB : ESCESCOOBB copy Make a copy of the log file, but don’t change the original at : ESCESCOOBB all. This option can be used, for instance, to make a snapshot : ESCESCOOBB of the current log file, or when some other utility needs to : ESCESCOOBB truncate or pare the file. When this option is used, the create : ESCESCOOBB option will have no effect, as the old log file stays in place. : ESCESCOOBB : ESCESCOOBB copytruncate : ESCESCOOBB Truncate the original log file in place after creating a copy, : ESCESCOOBB instead of moving the old log file and optionally creating a new : ESCESCOOBB one, It can be used when some program can not be told to close : ESCESCOOBB its logfile and thus might continue writing (appending) to the : ESCESCOOBB previous log file forever. Note that there is a very small time : ESCESCOOBB slice between copying the file and truncating it, so some log†: ESCESCOOBB ging data might be lost. When this option is used, the create : ESCESCOOBB option will have no effect, as the old log file stays in place. : ESCESCOOBB : ESCESCOOBB create mode owner group : ESCESCOOBB Immediately after rotation (before the postrotate script is run) : ESCESCOOBB the log file is created (with the same name as the log file just : ESCESCOOBB rotated). mode specifies the mode for the log file in octal : ESCESCOOBB (the same as chmod(2)), owner specifies the user name who will : ESCESCOOBB own the log file, and group specifies the group the log file : ESCESCOOBB will belong to. Any of the log file attributes may be omitted, : ESCESCOOBB in which case those attributes for the new file will use the : ESCESCOOBB same values as the original log file for the omitted attributes. : ESCESCOOBB This option can be disabled using the nocreate option. : ESCESCOOBB : ESCESCOOBB daily Log files are rotated every day. : ESCESCOOBB : ESCESCOOBB delaycompress : ESCESCOOBB Postpone compression of the previous log file to the next rota†: ESCESCOOBB tion cycle. This has only effect when used in combination with : ESCESCOOBB compress. It can be used when some program can not be told to : ESCESCOOBB close its logfile and thus might continue writing to the previ†: ESCESCOOBB ous log file for some time. : ESCESCOOBB : ESCESCOOBB extension ext : ESCESCOOBB Log files are given the final extension ext after rotation. If : ESCESCOOBB compression is used, the compression extension (normally .gz) : ESCESCOOBB appears after ext. : ESCESCOOBB : ESCESCOOBB ifempty : ESCESCOOBB Rotate the log file even if it is empty, overiding the : ESCESCOOBB notifempty option (ifempty is the default). : ESCESCOOBB : ESCESCOOBB include file_or_directory : ESCESCOOBB Reads the file given as an argument as if it was included inline : ESCESCOOBB where the include directive appears. If a directory is given, : ESCESCOOBB most of the files in that directory are read in alphabetic order : ESCESCOOBB before processing of the including file continues. The only : ESCESCOOBB files which are ignored are files which are not regular files : ESCESCOOBB (such as directories and named pipes) and files whose names end : ESCESCOOBB with one of the taboo extensions, as specified by the tabooext : ESCESCOOBB directive. The include directive may not appear inside of a log : ESCESCOOBB file definition. : ESCESCOOBB : ESCESCOOBB mail address : ESCESCOOBB When a log is rotated outâ€ofâ€existence, it is mailed to address. : ESCESCOOBB If no mail should be generated by a particular log, the nomail : ESCESCOOBB directive may be used. : ESCESCOOBB : ESCESCOOBB mailfirst : ESCESCOOBB When using the mail command, mail the justâ€rotated file, instead : ESCESCOOBB of the aboutâ€toâ€expire file. : ESCESCOOBB : ESCESCOOBB maillast : ESCESCOOBB When using the mail command, mail the aboutâ€toâ€expire file, : ESCESCOOBB instead of the justâ€rotated file (this is the default). : ESCESCOOBB : ESCESCOOBB missingok : ESCESCOOBB If the log file is missing, go on to the next one without issu†: ESCESCOOBB ing an error message. See also nomissingok. : ESCESCOOBB : ESCESCOOBB monthly : ESCESCOOBB Log files are rotated the first time logrotate is run in a month : ESCESCOOBB (this is normally on the first day of the month). : ESCESCOOBB : ESCESCOOBB nocompress : ESCESCOOBB Old versions of log files are not compressed with gzip. See also : ESCESCOOBB compress. : ESCESCOOBB : ESCESCOOBB nocopy Do not copy the original log file and leave it in place. (this : ESCESCOOBB overrides the copy option). : ESCESCOOBB : ESCESCOOBB nocopytruncate : ESCESCOOBB Do not truncate the original log file in place after creating a : ESCESCOOBB copy (this overrides the copytruncate option). : ESCESCOOBB : ESCESCOOBB nocreate : ESCESCOOBB New log files are not created (this overrides the create : ESCESCOOBB option). : ESCESCOOBB : ESCESCOOBB nodelaycompress : ESCESCOOBB Do not postpone compression of the previous log file to the next : ESCESCOOBB rotation cycle (this overrides the delaycompress option). : ESCESCOOBB : ESCESCOOBB nomail Don’t mail old log files to any address. : ESCESCOOBB : ESCESCOOBB nomissingok : ESCESCOOBB If a log file does not exist, issue an error. This is the : ESCESCOOBB default. : ESCESCOOBB : ESCESCOOBB noolddir : ESCESCOOBB Logs are rotated in the same directory the log normally resides : ESCESCOOBB in (this overrides the olddir option). : ESCESCOOBB : ESCESCOOBB nosharedscripts : ESCESCOOBB Run prerotate and postrotate scripts for every script which is : ESCESCOOBB rotated (this is the default, and overrides the sharedscripts : ESCESCOOBB option). : ESCESCOOBB : ESCESCOOBB notifempty : ESCESCOOBB Do not rotate the log if it is empty (this overrides the ifempty : ESCESCOOBB option). : ESCESCOOBB : ESCESCOOBB olddir directory : ESCESCOOBB Logs are moved into directory for rotation. The directory must : ESCESCOOBB be on the same physical device as the log file being rotated. : ESCESCOOBB When this option is used all old versions of the log end up in : ESCESCOOBB directory. This option may be overriden by the noolddir option. : ESCESCOOBB : ESCESCOOBB postrotate/endscript : ESCESCOOBB The lines between postrotate and endscript (both of which must : ESCESCOOBB appear on lines by themselves) are executed after the log file : ESCESCOOBB is rotated. These directives may only appear inside of a log : ESCESCOOBB file definition. See prerotate as well. : ESCESCOOBB : ESCESCOOBB prerotate/endscriptThe lines between prerotate and endscript (both of : ESCESCOOBB which : ESCESCOOBB must appear on lines by themselves) are executed before the log : ESCESCOOBB file is rotated and only if the log will actually be rotated. : ESCESCOOBB These directives may only appear inside of a log file defini†: ESCESCOOBB tion. See postrotate as well. : ESCESCOOBB : ESCESCOOBB rotate count : ESCESCOOBB Log files are rotated times before being removed or : ESCESCOOBB mailed to the address specified in a mail directive. If count is : ESCESCOOBB 0, old versions are removed rather then rotated. : ESCESCOOBB : ESCESCOOBB size size : ESCESCOOBB Log files are rotated when they grow bigger then size bytes. If : ESCESCOOBB size is followed by M, the size if assumed to be in megabytes. : ESCESCOOBB If the k is used, the size is in kilobytes. So size 100, size : ESCESCOOBB 100k, and size 100M are all valid. : ESCESCOOBB : ESCESCOOBB sharedscripts : ESCESCOOBB Normally, prescript and postscript scripts are run for each log : ESCESCOOBB which is rotated, meaning that a single script may be run multi†: ESCESCOOBB ple times for log file entries which match multiple files (such : ESCESCOOBB as the /var/log/news/* example). If sharedscript is specified, : ESCESCOOBB the scripts are only run once, no matter how many logs match the : ESCESCOOBB wildcarded pattern. However, if none of the logs in the pattern : ESCESCOOBB require rotating, the scripts will not be run at all. This : ESCESCOOBB option overrides the nosharedscripts option. : ESCESCOOBB : ESCESCOOBB start count : ESCESCOOBB This is the number to use as the base for rotation. For example, : ESCESCOOBB if you specify 0, the logs will be created with a .0 extension : ESCESCOOBB as they are rotated from the original log files. If you specify : ESCESCOOBB 9, log files will be created with a .9, skipping 0â€8. Files : ESCESCOOBB will still be rotated the number of times specified with the : ESCESCOOBB count directive. : ESCESCOOBB : ESCESCOOBB tabooext [+] list : ESCESCOOBB The current taboo extension list is changed (see the include : ESCESCOOBB directive for information on the taboo extensions). If a + pre†: ESCESCOOBB cedes the list of extensions, the current taboo extension list : ESCESCOOBB is augmented, otherwise it is replaced. At startup, the taboo : ESCESCOOBB extension list contains .rpmorig, .rpmsave, ,v, .swp, .rpmnew, : ESCESCOOBB and ~. : ESCESCOOBB : ESCESCOOBB weekly Log files are rotated if the current weekday is less then the : ESCESCOOBB weekday of the last rotation or if more then a week has passed : ESCESCOOBB since the last rotation. This is normally the same as rotating : ESCESCOOBB logs on the first day of the week, but it works better if logro†: ESCESCOOBB tate is not run every night. : ESCESCOOBB : ESCESCOOBBFILES : ESCESCOOBB /var/lib/logrotate/status Default state file. : ESCESCOOBB /etc/logrotate.conf Configuration options. : ESCESCOOBB : ESCESCOOBBSEE ALSO : ESCESCOOBB gzip(1) : ESCESCOOBB : ESCESCOOBBAUTHORS : ESCESCOOBB Erik Troan : ESCESCOOBB Preston Brown : ESCESCOOBB : ESCESCOOBB4th Berkeley Distribution Wed Nov 28 2001 LOGROTATE(8) : ESCESCOOBB(END)  ESCESCOOBB(END)  ESCESCOOBB(END)  ESCESCOOBB(END)  ESCESCOOBB(END)  ESCESCOOBB(END)  ESCESCOOBB(END) [?1l>[?1047l[?1048l]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# l [root@magnolia etc]# l [root@magnolia etc]# ls [root@magnolia etc]# ls [root@magnolia etc]# ls [root@magnolia etc]# ls [root@magnolia etc]# ls * [root@magnolia etc]# ls * [root@magnolia etc]# ls *l [root@magnolia etc]# ls *l [root@magnolia etc]# ls *lo [root@magnolia etc]# ls *lo [root@magnolia etc]# ls *log [root@magnolia etc]# ls *log [root@magnolia etc]# ls *log* [root@magnolia etc]# ls *log* aeplog.conf initlog.conf logrotate.conf syslog.conf.last021123 csh.login login.defs syslog.conf log.d: conf logwatch logwatch.conf scripts logrotate.d: named rpm samba snmpd syslog up2date ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# c [root@magnolia etc]# c [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd c [root@magnolia etc]# cd c [root@magnolia etc]# cd cr [root@magnolia etc]# cd cr [root@magnolia etc]# cd cro [root@magnolia etc]# cd cro [root@magnolia etc]# cd cron [root@magnolia etc]# cd cron [root@magnolia etc]# cd cron. [root@magnolia etc]# cd cron. [root@magnolia etc]# cd cron.d [root@magnolia etc]# cd cron.d [root@magnolia etc]# cd cron.da [root@magnolia etc]# cd cron.da [root@magnolia etc]# cd cron.dai [root@magnolia etc]# cd cron.dai [root@magnolia etc]# cd cron.dail [root@magnolia etc]# cd cron.dail [root@magnolia etc]# cd cron.daily [root@magnolia etc]# cd cron.daily ]0;barrie@magnolia:/etc/cron.daily [root@magnolia cron.daily]# [root@magnolia cron.daily]# [root@magnolia cron.daily]# l [root@magnolia cron.daily]# l [root@magnolia cron.daily]# ls [root@magnolia cron.daily]# ls 00-logwatch 0anacron makewhatis.cron slocate.cron tmpwatch 00webalizer logrotate rpm tetex.cron ]0;barrie@magnolia:/etc/cron.daily [root@magnolia cron.daily]# [root@magnolia cron.daily]# [root@magnolia cron.daily]# m [root@magnolia cron.daily]# m [root@magnolia cron.daily]# mo [root@magnolia cron.daily]# mo [root@magnolia cron.daily]# mor [root@magnolia cron.daily]# mor [root@magnolia cron.daily]# more [root@magnolia cron.daily]# more [root@magnolia cron.daily]# more [root@magnolia cron.daily]# more [root@magnolia cron.daily]# more l [root@magnolia cron.daily]# more l [root@magnolia cron.daily]# more lo [root@magnolia cron.daily]# more lo [root@magnolia cron.daily]# more log [root@magnolia cron.daily]# more log [root@magnolia cron.daily]# more logr [root@magnolia cron.daily]# more logr [root@magnolia cron.daily]# more logro [root@magnolia cron.daily]# more logro [root@magnolia cron.daily]# more logrot [root@magnolia cron.daily]# more logrot [root@magnolia cron.daily]# more logrota [root@magnolia cron.daily]# more logrota [root@magnolia cron.daily]# more logrotat [root@magnolia cron.daily]# more logrotat [root@magnolia cron.daily]# more logrotate [root@magnolia cron.daily]# more logrotate #!/bin/sh /usr/sbin/logrotate /etc/logrotate.conf ]0;barrie@magnolia:/etc/cron.daily [root@magnolia cron.daily]# [root@magnolia cron.daily]# [root@magnolia cron.daily]# c [root@magnolia cron.daily]# c [root@magnolia cron.daily]# cd [root@magnolia cron.daily]# cd [root@magnolia cron.daily]# cd [root@magnolia cron.daily]# cd [root@magnolia cron.daily]# cd / [root@magnolia cron.daily]# cd / [root@magnolia cron.daily]# cd /u [root@magnolia cron.daily]# cd /u [root@magnolia cron.daily]# cd /us [root@magnolia cron.daily]# cd /us [root@magnolia cron.daily]# cd /usr [root@magnolia cron.daily]# cd /usr [root@magnolia cron.daily]# cd /usr/ [root@magnolia cron.daily]# cd /usr/ [root@magnolia cron.daily]# cd /usr/s [root@magnolia cron.daily]# cd /usr/s [root@magnolia cron.daily]# cd /usr/sb [root@magnolia cron.daily]# cd /usr/sb [root@magnolia cron.daily]# cd /usr/sbi [root@magnolia cron.daily]# cd /usr/sbi [root@magnolia cron.daily]# cd /usr/sbin [root@magnolia cron.daily]# cd /usr/sbin ]0;barrie@magnolia:/usr/sbin [root@magnolia sbin]# [root@magnolia sbin]# [root@magnolia sbin]# l [root@magnolia sbin]# l [root@magnolia sbin]# ls [root@magnolia sbin]# ls [root@magnolia sbin]# ls [root@magnolia sbin]# ls [root@magnolia sbin]# ls l [root@magnolia sbin]# ls l [root@magnolia sbin]# ls lo [root@magnolia sbin]# ls lo [root@magnolia sbin]# ls log [root@magnolia sbin]# ls log [root@magnolia sbin]# ls logr [root@magnolia sbin]# ls logr [root@magnolia sbin]# ls logr* [root@magnolia sbin]# ls logr* logrotate ]0;barrie@magnolia:/usr/sbin [root@magnolia sbin]# [root@magnolia sbin]# [root@magnolia sbin]# m [root@magnolia sbin]# m [root@magnolia sbin]# mo [root@magnolia sbin]# mo [root@magnolia sbin]# mor [root@magnolia sbin]# mor [root@magnolia sbin]# more [root@magnolia sbin]# more [root@magnolia sbin]# more [root@magnolia sbin]# more [root@magnolia sbin]# more l [root@magnolia sbin]# more l [root@magnolia sbin]# more lo [root@magnolia sbin]# more lo [root@magnolia sbin]# more log [root@magnolia sbin]# more log [root@magnolia sbin]# more logr [root@magnolia sbin]# more logr [root@magnolia sbin]# more logro [root@magnolia sbin]# more logro [root@magnolia sbin]# more logrot [root@magnolia sbin]# more logrot [root@magnolia sbin]# more logrota [root@magnolia sbin]# more logrota [root@magnolia sbin]# more logrotat [root@magnolia sbin]# more logrotat [root@magnolia sbin]# more logrotate [root@magnolia sbin]# more logrotate ******** logrotate: Not a text file ******** ]0;barrie@magnolia:/usr/sbin [root@magnolia sbin]# [root@magnolia sbin]# [root@magnolia sbin]# v [root@magnolia sbin]# v [root@magnolia sbin]#  [root@magnolia sbin]# [root@magnolia sbin]# v [root@magnolia sbin]# v [root@magnolia sbin]# vf [root@magnolia sbin]# vf [root@magnolia sbin]# vf [root@magnolia sbin]# vf [root@magnolia sbin]# vf [root@magnolia sbin]# vf [root@magnolia sbin]# v [root@magnolia sbin]# v [root@magnolia sbin]#  [root@magnolia sbin]# [root@magnolia sbin]# c [root@magnolia sbin]# c [root@magnolia sbin]# cd [root@magnolia sbin]# cd [root@magnolia sbin]# cd [root@magnolia sbin]# cd [root@magnolia sbin]# cd / [root@magnolia sbin]# cd / [root@magnolia sbin]# cd /l [root@magnolia sbin]# cd /l [root@magnolia sbin]# cd /lo [root@magnolia sbin]# cd /lo [root@magnolia sbin]# cd /log [root@magnolia sbin]# cd /log bash: cd: /log: No such file or directory ]0;barrie@magnolia:/usr/sbin [root@magnolia sbin]# [root@magnolia sbin]# [root@magnolia sbin]# l [root@magnolia sbin]# l [root@magnolia sbin]# ls [root@magnolia sbin]# ls accept hwclock ntp-genkeys rpc.mountd adduser ibod ntpq rpc.nfsd adsl-connect icnctrl ntptime rpc.rquotad adsl-setup iconvconfig ntptimeset rtacct adsl-start imon ntptrace safe_finger adsl-status imontty ntp-wait saned adsl-stop inetdconvert ntsysv saslauthd aepdaemon internet-druid packer sasldblistusers aepload ipppd pcbitctl sasldblistusers2 aeptest ipppstats ping6 saslpasswd aepversion iprofd pmap_dump saslpasswd2 alternatives irattach pmap_set sendmail anacron irdaping postalias sendmail.postfix apmd isdnctrl postcat sendmail.sendmail arping isdnlog postconf sensors-detect atd isdnup postdrop serviceconf atrun kbdconfig postfix setclock authconfig kbdrate postkick setpcaps automount kppp postlock setquota avmcapictrl ksconfig postlog setup bonobo-activation-sysconf kudzu postmap showmount build-locale-archive lchage postqueue smbd camel-lock-helper lgroupadd postsuper smrsh capiinit lgroupdel pppd smtp-sink chat lgroupmod pppdump smtp-source checkpc lid pppoe snmpd chkfontpath lnewusers pppoe-relay snmptrapd chpasswd lockdev pppoe-server sshd chroot logrotate pppoe-sniff strfile clockdiff logwatch pppstats stunnel crond lokkit praliases sucap cupsaddsmb loopctrl printconf sys-unconfig cupsd lpadmin printconf-backend tcpd dbconverter-2 lpasswd printconf-gui tcpdump ddcprobe lpc printconf-tui tcpslice dns-keygen lpc.cups printtool tethereal dnssec-keygen lpc.LPRng pwck tickadj dnssec-makekeyset lpd pwconv timeconfig dnssec-signkey lpdomatic pwunconv tmpwatch dnssec-signzone lpinfo quotastats tracepath dongle_attach lpmove ramsize tracepath6 editcap lsof rcapid traceroute edquota luseradd rdev traceroute6 ethtool luserdel rdisc try-from execcap lusermod rdistd tunelp exportfs lwresd readprofile unstr fbset mailstats redhat-cdinstall-helper up2date findchip makemap redhat-config-bind up2date-config firstboot makewhatis redhat-config-bind-gui up2date-nox foomatic-addpjloptions mkdict redhat-config-kickstart update-alternatives foomatic-fix-xml mklost+found redhat-config-network updfstab foomatic-getpjloptions mksock redhat-config-network-cmd useradd foomatic-kitload mkzonedb redhat-config-network-druid userdel foomatic-ppdload modeline2fb redhat-config-packages userhelper foomatic-preferred-driver module_upgrade redhat-config-printer userisdnctl gdmaskpass monitor redhat-config-printer-gui usermod gdmconfig mouseconfig redhat-config-printer-tui usernetctl gdmopen mtr redhat-config-proc utempter gdm-restart named redhat-config-services vboxd gdm-safe-restart named-bootconf redhat-install-packages vidmode gdmsetup named-checkconf redhat-switchmail vigr getpcaps named-checkzone redhat-switchmail-nox vipw glibc_post_upgrade neat redhat-switch-printer visudo gnome-pty-helper neat-tui redhat-switch-printer-nox warnquota gpm netconfig reject winbindd groupadd newusers repquota xcdroast groupdel nfsstat rhn_check xinetd groupmod nhfsstone rhnreg_ks xinetd-ipv6 grpck nmbd rhnsd yppoll grpconv nscd rndc ypset grpunconv ntpd rndc-confgen yptest hisaxctrl ntpdate rootflags zdump hotplugctl ntpdc rpcinfo zic ]0;barrie@magnolia:/usr/sbin [root@magnolia sbin]# [root@magnolia sbin]# [root@magnolia sbin]# m [root@magnolia sbin]# m [root@magnolia sbin]# mo [root@magnolia sbin]# mo [root@magnolia sbin]# mor [root@magnolia sbin]# mor [root@magnolia sbin]# more [root@magnolia sbin]# more [root@magnolia sbin]# more [root@magnolia sbin]# more [root@magnolia sbin]# more l [root@magnolia sbin]# more l [root@magnolia sbin]# more lo [root@magnolia sbin]# more lo [root@magnolia sbin]# more log [root@magnolia sbin]# more log [root@magnolia sbin]# more logr [root@magnolia sbin]# more logr [root@magnolia sbin]# more logro [root@magnolia sbin]# more logro [root@magnolia sbin]# more logrot [root@magnolia sbin]# more logrot [root@magnolia sbin]# more logrota [root@magnolia sbin]# more logrota [root@magnolia sbin]# more logrotat [root@magnolia sbin]# more logrotat [root@magnolia sbin]# more logrotate [root@magnolia sbin]# more logrotate [root@magnolia sbin]# more logrotate. [root@magnolia sbin]# more logrotate. [root@magnolia sbin]# more logrotate.c [root@magnolia sbin]# more logrotate.c [root@magnolia sbin]# more logrotate.co [root@magnolia sbin]# more logrotate.co [root@magnolia sbin]# more logrotate.con [root@magnolia sbin]# more logrotate.con [root@magnolia sbin]# more logrotate.conf [root@magnolia sbin]# more logrotate.conf logrotate.conf: No such file or directory ]0;barrie@magnolia:/usr/sbin [root@magnolia sbin]# [root@magnolia sbin]# [root@magnolia sbin]# m [root@magnolia sbin]# m [root@magnolia sbin]# mo [root@magnolia sbin]# mo [root@magnolia sbin]# mor [root@magnolia sbin]# mor [root@magnolia sbin]# more [root@magnolia sbin]# more [root@magnolia sbin]# more [root@magnolia sbin]# more [root@magnolia sbin]# more r [root@magnolia sbin]# more r [root@magnolia sbin]# more ro [root@magnolia sbin]# more ro [root@magnolia sbin]# more rot [root@magnolia sbin]# more rot [root@magnolia sbin]# more rote [root@magnolia sbin]# more rote [root@magnolia sbin]# more rotea [root@magnolia sbin]# more rotea [root@magnolia sbin]# more roteat [root@magnolia sbin]# more roteat [root@magnolia sbin]# more rotea [root@magnolia sbin]# more rotea [root@magnolia sbin]# more rote [root@magnolia sbin]# more rote [root@magnolia sbin]# more rot [root@magnolia sbin]# more rot [root@magnolia sbin]# more rota [root@magnolia sbin]# more rota [root@magnolia sbin]# more rotat [root@magnolia sbin]# more rotat [root@magnolia sbin]# more rotate [root@magnolia sbin]# more rotate [root@magnolia sbin]# more rotate. [root@magnolia sbin]# more rotate. [root@magnolia sbin]# more rotate.c [root@magnolia sbin]# more rotate.c [root@magnolia sbin]# more rotate.co [root@magnolia sbin]# more rotate.co [root@magnolia sbin]# more rotate.con [root@magnolia sbin]# more rotate.con [root@magnolia sbin]# more rotate.conf [root@magnolia sbin]# more rotate.conf rotate.conf: No such file or directory ]0;barrie@magnolia:/usr/sbin [root@magnolia sbin]# [root@magnolia sbin]# [root@magnolia sbin]# c [root@magnolia sbin]# c [root@magnolia sbin]# cd [root@magnolia sbin]# cd [root@magnolia sbin]# cd [root@magnolia sbin]# cd [root@magnolia sbin]# cd / [root@magnolia sbin]# cd / [root@magnolia sbin]# cd /v [root@magnolia sbin]# cd /v [root@magnolia sbin]# cd /va [root@magnolia sbin]# cd /va [root@magnolia sbin]# cd /var [root@magnolia sbin]# cd /var [root@magnolia sbin]# cd /var/ [root@magnolia sbin]# cd /var/ [root@magnolia sbin]# cd /var/l [root@magnolia sbin]# cd /var/l [root@magnolia sbin]# cd /var/lo [root@magnolia sbin]# cd /var/lo [root@magnolia sbin]# cd /var/log [root@magnolia sbin]# cd /var/log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# m [root@magnolia log]# m [root@magnolia log]# mo [root@magnolia log]# mo [root@magnolia log]# mor [root@magnolia log]# mor [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more l [root@magnolia log]# more l [root@magnolia log]# more  [root@magnolia log]# more [root@magnolia log]# more r [root@magnolia log]# more r [root@magnolia log]# more ro [root@magnolia log]# more ro [root@magnolia log]# more rot [root@magnolia log]# more rot [root@magnolia log]# more rota [root@magnolia log]# more rota [root@magnolia log]# more rotat [root@magnolia log]# more rotat [root@magnolia log]# more rotate [root@magnolia log]# more rotate [root@magnolia log]# more rotate. [root@magnolia log]# more rotate. [root@magnolia log]# more rotate.c [root@magnolia log]# more rotate.c [root@magnolia log]# more rotate.co [root@magnolia log]# more rotate.co [root@magnolia log]# more rotate.con [root@magnolia log]# more rotate.con [root@magnolia log]# more rotate.conf [root@magnolia log]# more rotate.conf rotate.conf: No such file or directory ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# m [root@magnolia log]# m [root@magnolia log]# mo [root@magnolia log]# mo [root@magnolia log]# mor [root@magnolia log]# mor [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more l [root@magnolia log]# more l [root@magnolia log]# more lo [root@magnolia log]# more lo [root@magnolia log]# more log [root@magnolia log]# more log [root@magnolia log]# more logr [root@magnolia log]# more logr [root@magnolia log]# more logro [root@magnolia log]# more logro [root@magnolia log]# more logrot [root@magnolia log]# more logrot [root@magnolia log]# more logrota [root@magnolia log]# more logrota [root@magnolia log]# more logrotat [root@magnolia log]# more logrotat [root@magnolia log]# more logrotat. [root@magnolia log]# more logrotat. [root@magnolia log]# more logrotat [root@magnolia log]# more logrotat [root@magnolia log]# more logrotate [root@magnolia log]# more logrotate [root@magnolia log]# more logrotate. [root@magnolia log]# more logrotate. [root@magnolia log]# more logrotate.c [root@magnolia log]# more logrotate.c [root@magnolia log]# more logrotate.co [root@magnolia log]# more logrotate.co [root@magnolia log]# more logrotate.con [root@magnolia log]# more logrotate.con [root@magnolia log]# more logrotate.conf [root@magnolia log]# more logrotate.conf logrotate.conf: No such file or directory ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# l [root@magnolia log]# l [root@magnolia log]# ls [root@magnolia log]# ls boot.log cron.4 ksyms.4 messages rpmpkgs.4 spooler.1 vbox boot.log.1 cups ksyms.5 messages.1 samba spooler.2 wtmp boot.log.2 dmesg ksyms.6 messages.2 scrollkeeper.log spooler.3 wtmp.1 boot.log.3 gdm lastlog messages.3 secure spooler.4 XFree86.0.log boot.log.4 httpd maillog messages.4 secure.1 up2date cron ksyms.0 maillog.1 rpmpkgs secure.2 up2date.1 cron.1 ksyms.1 maillog.2 rpmpkgs.1 secure.3 up2date.2 cron.2 ksyms.2 maillog.3 rpmpkgs.2 secure.4 up2date.3 cron.3 ksyms.3 maillog.4 rpmpkgs.3 spooler up2date.4 ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# c [root@magnolia log]# c [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd / [root@magnolia log]# cd / [root@magnolia log]# cd /e [root@magnolia log]# cd /e [root@magnolia log]# cd /et [root@magnolia log]# cd /et [root@magnolia log]# cd /etc [root@magnolia log]# cd /etc ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# m [root@magnolia etc]# m [root@magnolia etc]# mo [root@magnolia etc]# mo [root@magnolia etc]# mor [root@magnolia etc]# mor [root@magnolia etc]# more [root@magnolia etc]# more [root@magnolia etc]# more [root@magnolia etc]# more [root@magnolia etc]# more l [root@magnolia etc]# more l [root@magnolia etc]# more lo [root@magnolia etc]# more lo [root@magnolia etc]# more log [root@magnolia etc]# more log [root@magnolia etc]# more logr [root@magnolia etc]# more logr [root@magnolia etc]# more logro [root@magnolia etc]# more logro [root@magnolia etc]# more logrot [root@magnolia etc]# more logrot [root@magnolia etc]# more logrota [root@magnolia etc]# more logrota [root@magnolia etc]# more logrotat [root@magnolia etc]# more logrotat [root@magnolia etc]# more logrotate [root@magnolia etc]# more logrotate [root@magnolia etc]# more logrotate. [root@magnolia etc]# more logrotate. [root@magnolia etc]# more logrotate.c [root@magnolia etc]# more logrotate.c [root@magnolia etc]# more logrotate.co [root@magnolia etc]# more logrotate.co [root@magnolia etc]# more logrotate.con [root@magnolia etc]# more logrotate.con [root@magnolia etc]# more logrotate.conf [root@magnolia etc]# more logrotate.conf # see "man logrotate" for details # rotate log files weekly weekly # keep 4 weeks worth of backlogs rotate 4 # create new (empty) log files after rotating old ones create # uncomment this if you want your log files compressed #compress # RPM packages drop log rotation information into this directory include /etc/logrotate.d # no packages own wtmp -- we'll rotate them here /var/log/wtmp { monthly create 0664 root utmp rotate 1 } # system-specific logs may be also be configured here. ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# c [root@magnolia etc]# c [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd . [root@magnolia etc]# cd . [root@magnolia etc]# cd .v [root@magnolia etc]# cd .v [root@magnolia etc]# cd .va [root@magnolia etc]# cd .va [root@magnolia etc]# cd .var [root@magnolia etc]# cd .var [root@magnolia etc]# cd .va [root@magnolia etc]# cd .va [root@magnolia etc]# cd .v [root@magnolia etc]# cd .v [root@magnolia etc]# cd . [root@magnolia etc]# cd . [root@magnolia etc]# cd  [root@magnolia etc]# cd [root@magnolia etc]# cd / [root@magnolia etc]# cd / [root@magnolia etc]# cd /v [root@magnolia etc]# cd /v [root@magnolia etc]# cd /va [root@magnolia etc]# cd /va [root@magnolia etc]# cd /var [root@magnolia etc]# cd /var [root@magnolia etc]# cd /var/ [root@magnolia etc]# cd /var/ [root@magnolia etc]# cd /var/l [root@magnolia etc]# cd /var/l [root@magnolia etc]# cd /var/lo [root@magnolia etc]# cd /var/lo [root@magnolia etc]# cd /var/log [root@magnolia etc]# cd /var/log [root@magnolia etc]# cd /var/log/ [root@magnolia etc]# cd /var/log/ [root@magnolia etc]# cd /var/log/w [root@magnolia etc]# cd /var/log/w [root@magnolia etc]# cd /var/log/wt [root@magnolia etc]# cd /var/log/wt [root@magnolia etc]# cd /var/log/wtm [root@magnolia etc]# cd /var/log/wtm [root@magnolia etc]# cd /var/log/wtmp [root@magnolia etc]# cd /var/log/wtmp bash: cd: /var/log/wtmp: Not a directory ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# c [root@magnolia etc]# c [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd / [root@magnolia etc]# cd / [root@magnolia etc]# cd /v [root@magnolia etc]# cd /v [root@magnolia etc]# cd /va [root@magnolia etc]# cd /va [root@magnolia etc]# cd /var [root@magnolia etc]# cd /var [root@magnolia etc]# cd /var/ [root@magnolia etc]# cd /var/ [root@magnolia etc]# cd /var/l [root@magnolia etc]# cd /var/l [root@magnolia etc]# cd /var/lo [root@magnolia etc]# cd /var/lo [root@magnolia etc]# cd /var/log [root@magnolia etc]# cd /var/log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# l [root@magnolia log]# l [root@magnolia log]# ls [root@magnolia log]# ls boot.log cron.4 ksyms.4 messages rpmpkgs.4 spooler.1 vbox boot.log.1 cups ksyms.5 messages.1 samba spooler.2 wtmp boot.log.2 dmesg ksyms.6 messages.2 scrollkeeper.log spooler.3 wtmp.1 boot.log.3 gdm lastlog messages.3 secure spooler.4 XFree86.0.log boot.log.4 httpd maillog messages.4 secure.1 up2date cron ksyms.0 maillog.1 rpmpkgs secure.2 up2date.1 cron.1 ksyms.1 maillog.2 rpmpkgs.1 secure.3 up2date.2 cron.2 ksyms.2 maillog.3 rpmpkgs.2 secure.4 up2date.3 cron.3 ksyms.3 maillog.4 rpmpkgs.3 spooler up2date.4 ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# m [root@magnolia log]# m [root@magnolia log]# mo [root@magnolia log]# mo [root@magnolia log]# mor [root@magnolia log]# mor [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more c [root@magnolia log]# more c [root@magnolia log]# more  [root@magnolia log]# more [root@magnolia log]# more w [root@magnolia log]# more w [root@magnolia log]# more wt [root@magnolia log]# more wt [root@magnolia log]# more wtm [root@magnolia log]# more wtm [root@magnolia log]# more wtmp [root@magnolia log]# more wtmp 03~~~runlevel2.4.18-14 :Å=ÒÚÛtty112.4.18-14 :Å=®Ù Ütty222.4.18-14 :Å=ÚÝtty332.4.18-14 :Å=}Ú Þtty442.4.18-14 :Å=äÚßtty552.4.18-14 :Å=NÛ àtty662.4.18-14 :Å=¾Ûtty112.4.18-14 :Å=aÜ tty222.4.18-14 :Å=ÂÜtty332.4.18-14 :Å=&Ý tty442.4.18-14 :Å=ŒÝtty552.4.18-14 :Å=Þ tty662.4.18-14 :Å=ƒÞ¿l02.4.18-14 :Å=lß ~~~~shutdown2.4.18-14 :Å=·­  si2.4.18-14 G²Å=]ø ~~~reboot2.4.18-14 G²Å=&3N~~~runlevel2.4.18-14 --More--(2%) ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# l [root@magnolia log]# l [root@magnolia log]# ls [root@magnolia log]# ls boot.log cron.4 ksyms.4 messages rpmpkgs.4 spooler.1 vbox boot.log.1 cups ksyms.5 messages.1 samba spooler.2 wtmp boot.log.2 dmesg ksyms.6 messages.2 scrollkeeper.log spooler.3 wtmp.1 boot.log.3 gdm lastlog messages.3 secure spooler.4 XFree86.0.log boot.log.4 httpd maillog messages.4 secure.1 up2date cron ksyms.0 maillog.1 rpmpkgs secure.2 up2date.1 cron.1 ksyms.1 maillog.2 rpmpkgs.1 secure.3 up2date.2 cron.2 ksyms.2 maillog.3 rpmpkgs.2 secure.4 up2date.3 cron.3 ksyms.3 maillog.4 rpmpkgs.3 spooler up2date.4 ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# p [root@magnolia log]# p [root@magnolia log]# pw [root@magnolia log]# pw [root@magnolia log]# pwd [root@magnolia log]# pwd /var/log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# c [root@magnolia log]# c [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd . [root@magnolia log]# cd . [root@magnolia log]# cd  [root@magnolia log]# cd [root@magnolia log]# cd / [root@magnolia log]# cd / [root@magnolia log]# cd /e [root@magnolia log]# cd /e [root@magnolia log]# cd /et [root@magnolia log]# cd /et [root@magnolia log]# cd /etc [root@magnolia log]# cd /etc [root@magnolia log]# cd /etc/ [root@magnolia log]# cd /etc/ [root@magnolia log]# cd /etc/w [root@magnolia log]# cd /etc/w [root@magnolia log]# cd /etc/we [root@magnolia log]# cd /etc/we [root@magnolia log]# cd /etc/wee [root@magnolia log]# cd /etc/wee [root@magnolia log]# cd /etc/week [root@magnolia log]# cd /etc/week [root@magnolia log]# cd /etc/weekl [root@magnolia log]# cd /etc/weekl [root@magnolia log]# cd /etc/weekly [root@magnolia log]# cd /etc/weekly [root@magnolia log]# cd /etc/weekly. [root@magnolia log]# cd /etc/weekly. [root@magnolia log]# cd /etc/weekly.c [root@magnolia log]# cd /etc/weekly.c [root@magnolia log]# cd /etc/weekly. [root@magnolia log]# cd /etc/weekly. [root@magnolia log]# cd /etc/weekly [root@magnolia log]# cd /etc/weekly [root@magnolia log]# cd /etc/weekl [root@magnolia log]# cd /etc/weekl [root@magnolia log]# cd /etc/week [root@magnolia log]# cd /etc/week [root@magnolia log]# cd /etc/wee [root@magnolia log]# cd /etc/wee [root@magnolia log]# cd /etc/we [root@magnolia log]# cd /etc/we [root@magnolia log]# cd /etc/w [root@magnolia log]# cd /etc/w [root@magnolia log]# cd /etc/ [root@magnolia log]# cd /etc/ [root@magnolia log]# cd /etc/c [root@magnolia log]# cd /etc/c [root@magnolia log]# cd /etc/cr [root@magnolia log]# cd /etc/cr [root@magnolia log]# cd /etc/cro [root@magnolia log]# cd /etc/cro [root@magnolia log]# cd /etc/cron [root@magnolia log]# cd /etc/cron [root@magnolia log]# cd /etc/cron. [root@magnolia log]# cd /etc/cron. [root@magnolia log]# cd /etc/cron.w [root@magnolia log]# cd /etc/cron.w [root@magnolia log]# cd /etc/cron.we [root@magnolia log]# cd /etc/cron.we [root@magnolia log]# cd /etc/cron.wee [root@magnolia log]# cd /etc/cron.wee [root@magnolia log]# cd /etc/cron.week [root@magnolia log]# cd /etc/cron.week [root@magnolia log]# cd /etc/cron.weekl [root@magnolia log]# cd /etc/cron.weekl [root@magnolia log]# cd /etc/cron.weekly [root@magnolia log]# cd /etc/cron.weekly ]0;barrie@magnolia:/etc/cron.weekly [root@magnolia cron.weekly]# [root@magnolia cron.weekly]# [root@magnolia cron.weekly]# l [root@magnolia cron.weekly]# l [root@magnolia cron.weekly]# ls [root@magnolia cron.weekly]# ls 0anacron makewhatis.cron ]0;barrie@magnolia:/etc/cron.weekly [root@magnolia cron.weekly]# [root@magnolia cron.weekly]# [root@magnolia cron.weekly]# c [root@magnolia cron.weekly]# c [root@magnolia cron.weekly]# cd [root@magnolia cron.weekly]# cd [root@magnolia cron.weekly]# cd [root@magnolia cron.weekly]# cd [root@magnolia cron.weekly]# cd . [root@magnolia cron.weekly]# cd . [root@magnolia cron.weekly]# cd .. [root@magnolia cron.weekly]# cd .. [root@magnolia cron.weekly]# cd ../ [root@magnolia cron.weekly]# cd ../ [root@magnolia cron.weekly]# cd ../c [root@magnolia cron.weekly]# cd ../c [root@magnolia cron.weekly]# cd ../cr [root@magnolia cron.weekly]# cd ../cr [root@magnolia cron.weekly]# cd ../cro [root@magnolia cron.weekly]# cd ../cro [root@magnolia cron.weekly]# cd ../cron [root@magnolia cron.weekly]# cd ../cron [root@magnolia cron.weekly]# cd ../cron. [root@magnolia cron.weekly]# cd ../cron. [root@magnolia cron.weekly]# cd ../cron.m [root@magnolia cron.weekly]# cd ../cron.m [root@magnolia cron.weekly]# cd ../cron.mo [root@magnolia cron.weekly]# cd ../cron.mo [root@magnolia cron.weekly]# cd ../cron.mon [root@magnolia cron.weekly]# cd ../cron.mon [root@magnolia cron.weekly]# cd ../cron.mont [root@magnolia cron.weekly]# cd ../cron.mont [root@magnolia cron.weekly]# cd ../cron.month [root@magnolia cron.weekly]# cd ../cron.month [root@magnolia cron.weekly]# cd ../cron.monthl [root@magnolia cron.weekly]# cd ../cron.monthl [root@magnolia cron.weekly]# cd ../cron.monthly [root@magnolia cron.weekly]# cd ../cron.monthly ]0;barrie@magnolia:/etc/cron.monthly [root@magnolia cron.monthly]# [root@magnolia cron.monthly]# [root@magnolia cron.monthly]# l [root@magnolia cron.monthly]# l [root@magnolia cron.monthly]# ls [root@magnolia cron.monthly]# ls 0anacron ]0;barrie@magnolia:/etc/cron.monthly [root@magnolia cron.monthly]# [root@magnolia cron.monthly]# [root@magnolia cron.monthly]# c [root@magnolia cron.monthly]# c [root@magnolia cron.monthly]#  [root@magnolia cron.monthly]# [root@magnolia cron.monthly]# c [root@magnolia cron.monthly]# c [root@magnolia cron.monthly]# cd [root@magnolia cron.monthly]# cd [root@magnolia cron.monthly]# cd [root@magnolia cron.monthly]# cd [root@magnolia cron.monthly]# cd / [root@magnolia cron.monthly]# cd / [root@magnolia cron.monthly]# cd /e [root@magnolia cron.monthly]# cd /e [root@magnolia cron.monthly]# cd /et [root@magnolia cron.monthly]# cd /et [root@magnolia cron.monthly]# cd /etc [root@magnolia cron.monthly]# cd /etc ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# v [root@magnolia etc]# v [root@magnolia etc]# vi [root@magnolia etc]# vi [root@magnolia etc]# vi [root@magnolia etc]# vi [root@magnolia etc]# vi l [root@magnolia etc]# vi l [root@magnolia etc]# vi lo [root@magnolia etc]# vi lo [root@magnolia etc]# vi log [root@magnolia etc]# vi log [root@magnolia etc]# vi logr [root@magnolia etc]# vi logr [root@magnolia etc]# vi logro [root@magnolia etc]# vi logro [root@magnolia etc]# vi logrot [root@magnolia etc]# vi logrot [root@magnolia etc]# vi logrota [root@magnolia etc]# vi logrota [root@magnolia etc]# vi logrotat [root@magnolia etc]# vi logrotat [root@magnolia etc]# vi logrotate [root@magnolia etc]# vi logrotate [root@magnolia etc]# vi logrotate. [root@magnolia etc]# vi logrotate. [root@magnolia etc]# vi logrotate.c [root@magnolia etc]# vi logrotate.c [root@magnolia etc]# vi logrotate.co [root@magnolia etc]# vi logrotate.co [root@magnolia etc]# vi logrotate.con [root@magnolia etc]# vi logrotate.con [root@magnolia etc]# vi logrotate.conf [root@magnolia etc]# vi logrotate.conf [?1048h[?1047h[?1h=[?25h[?25h[?25l"logrotate.conf" 24L, 505C# see "man logrotate" for details # rotate log files weekly weekly # keep 4 weeks worth of backlogs rotate 4 # create new (empty) log files after rotating old ones create # uncomment this if you want your log files compressed #compress # RPM packages drop log rotation information into this directory include /etc/logrotate.d # no packages own wtmp -- we'll rotate them here /var/log/wtmp { monthly create 0664 root utmp rotate 1 } # system-specific logs may be also be configured here. ~ ~ ~ 1,1All[?25h[?25l2[?25h[?25l3[?25h[?25l4,0-1[?25h[?25l5,1 [?25h[?25l6[?25h[?25l7,0-1[?25h[?25l8,1 [?25h[?25l9[?25h[?25l10,0-1[?25h[?25l1,1 [?25h[?25l2[?25h[?25l3,0-1[?25h[?25l4,1 [?25h[?25l5[?25h[?25l6,0-1[?25h[?25l7,1 [?25h[?25l8[?25h[?25l9[?25h[?25l20[?25h[?25l-- INSERT --20,1All[?25h[?25l# create 0664 root utmp2[?25h[?25l1[?25h[?25l1[?25h[?25l2[?25h[?25l3[?25h[?25l4[?25h[?25l5[?25h[?25lrotate 12,1[?25h[?25l rotate 12-9[?25h[?25l rotate 11 [?25h[?25l1[?25h[?25l2[?25h[?25l3[?25h[?25l4[?25h[?25l5[?25h[?25l21,4All[?25h[?25l:[?25hq! [?25l[?1l>[?25h[?1047l[?1048l]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# p [root@magnolia etc]# p [root@magnolia etc]# pi [root@magnolia etc]# pi [root@magnolia etc]# pic [root@magnolia etc]# pic [root@magnolia etc]# pico [root@magnolia etc]# pico [root@magnolia etc]# pico [root@magnolia etc]# pico [root@magnolia etc]# pico l [root@magnolia etc]# pico l [root@magnolia etc]# pico lo [root@magnolia etc]# pico lo [root@magnolia etc]# pico log [root@magnolia etc]# pico log [root@magnolia etc]# pico logr [root@magnolia etc]# pico logr [root@magnolia etc]# pico logro [root@magnolia etc]# pico logro [root@magnolia etc]# pico logroa [root@magnolia etc]# pico logroa [root@magnolia etc]# pico logroat [root@magnolia etc]# pico logroat [root@magnolia etc]# pico logroate [root@magnolia etc]# pico logroate [root@magnolia etc]# pico logroat [root@magnolia etc]# pico logroat [root@magnolia etc]# pico logroa [root@magnolia etc]# pico logroa [root@magnolia etc]# pico logro [root@magnolia etc]# pico logro [root@magnolia etc]# pico logrot [root@magnolia etc]# pico logrot [root@magnolia etc]# pico logrota [root@magnolia etc]# pico logrota [root@magnolia etc]# pico logrotat [root@magnolia etc]# pico logrotat [root@magnolia etc]# pico logrotate [root@magnolia etc]# pico logrotate [root@magnolia etc]# pico logrotate. [root@magnolia etc]# pico logrotate. [root@magnolia etc]# pico logrotate.c [root@magnolia etc]# pico logrotate.c [root@magnolia etc]# pico logrotate.co [root@magnolia etc]# pico logrotate.co [root@magnolia etc]# pico logrotate.con [root@magnolia etc]# pico logrotate.con [root@magnolia etc]# pico logrotate.conf [root@magnolia etc]# pico logrotate.conf [?1048h[?1047h UW PICO(tm) 4.2 New Buffer ^G Get Help ^O WriteOut ^R Read File ^Y Prev Pg ^K Cut Text ^C Cur Pos ^X Exit ^J Justify ^W Where is ^V Next Pg ^U UnCut Text ^T To Spell [ Reading file ][ Read 24 lines ]File: logrotate.conf# see "man logrotate" for details# rotate log files weeklyweekly# keep 4 weeks worth of backlogsrotate 4# create new (empty) log files after rotating old onescreate# uncomment this if you want your log files compressed#compress# RPM packages drop log rotation information into this directoryinclude /etc/logrotate.d# no packages own wtmp -- we'll rotate them here/var/log/wtmp {monthlycreate 0664 root utmprotate 1}Modifiedrotate 1} # system-specific logs may be also be configured here.create 0664 root utmp rotate 1}create 0664 root utmp rotate 1}#00File Name to write : logrotate.confT To Files C Cancel TAB Complete [ Writing... ][ Wrote 25 lines ] ^G Get Help ^O WriteOut ^R Read File ^Y Prev Pg ^K Cut Text ^C Cur Pos ^X Exit ^J Justify ^W Where is ^V Next Pg ^U UnCut Text ^T To Spell File Name to write : logrotate.confT To Files C Cancel TAB Complete [ Writing... ][ Wrote 25 lines ]^G Get Help ^O WriteOut ^R Read File ^Y Prev Pg ^K Cut Text ^C Cur Pos ^X Exit ^J Justify ^W Where is ^V Next Pg ^U UnCut Text ^T To Spell [?1047l[?1048l]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# c [root@magnolia etc]# c [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd / [root@magnolia etc]# cd / [root@magnolia etc]# cd /u [root@magnolia etc]# cd /u [root@magnolia etc]# cd /ur [root@magnolia etc]# cd /ur [root@magnolia etc]# cd /ur/ [root@magnolia etc]# cd /ur/ [root@magnolia etc]# cd /ur/l [root@magnolia etc]# cd /ur/l [root@magnolia etc]# cd /ur/lo [root@magnolia etc]# cd /ur/lo [root@magnolia etc]# cd /ur/loc [root@magnolia etc]# cd /ur/loc [root@magnolia etc]# cd /ur/loca [root@magnolia etc]# cd /ur/loca [root@magnolia etc]# cd /ur/loca; [root@magnolia etc]# cd /ur/loca; [root@magnolia etc]# cd /ur/loca [root@magnolia etc]# cd /ur/loca [root@magnolia etc]# cd /ur/loc [root@magnolia etc]# cd /ur/loc [root@magnolia etc]# cd /ur/lo [root@magnolia etc]# cd /ur/lo [root@magnolia etc]# cd /ur/l [root@magnolia etc]# cd /ur/l [root@magnolia etc]# cd /ur/ [root@magnolia etc]# cd /ur/ [root@magnolia etc]# cd /ur [root@magnolia etc]# cd /ur [root@magnolia etc]# cd /u [root@magnolia etc]# cd /u [root@magnolia etc]# cd /us [root@magnolia etc]# cd /us [root@magnolia etc]# cd /usr [root@magnolia etc]# cd /usr [root@magnolia etc]# cd /usr/ [root@magnolia etc]# cd /usr/ [root@magnolia etc]# cd /usr/l [root@magnolia etc]# cd /usr/l [root@magnolia etc]# cd /usr/lo [root@magnolia etc]# cd /usr/lo [root@magnolia etc]# cd /usr/loc [root@magnolia etc]# cd /usr/loc [root@magnolia etc]# cd /usr/loca [root@magnolia etc]# cd /usr/loca [root@magnolia etc]# cd /usr/local [root@magnolia etc]# cd /usr/local [root@magnolia etc]# cd /usr/local/ [root@magnolia etc]# cd /usr/local/ [root@magnolia etc]# cd /usr/local/l [root@magnolia etc]# cd /usr/local/l [root@magnolia etc]# cd /usr/local/lo [root@magnolia etc]# cd /usr/local/lo [root@magnolia etc]# cd /usr/local/l [root@magnolia etc]# cd /usr/local/l [root@magnolia etc]# cd /usr/local/ [root@magnolia etc]# cd /usr/local/ ]0;barrie@magnolia:/usr/local [root@magnolia local]# [root@magnolia local]# [root@magnolia local]# l [root@magnolia local]# l [root@magnolia local]# ls [root@magnolia local]# ls apache2 etc lib mysql share bin games libexec mysql-max-4.0.3-beta-pc-linux-gnu-i686 src CorporateTime httpd-2.0.43 logcheck-1.1.1 php-4.2.3 doc include logsentry-1.1.1.tar sbin ]0;barrie@magnolia:/usr/local [root@magnolia local]# [root@magnolia local]# [root@magnolia local]# c [root@magnolia local]# c [root@magnolia local]# cd [root@magnolia local]# cd [root@magnolia local]# cd [root@magnolia local]# cd [root@magnolia local]# cd l [root@magnolia local]# cd l [root@magnolia local]# cd lo [root@magnolia local]# cd lo [root@magnolia local]# cd log [root@magnolia local]# cd log [root@magnolia local]# cd logc [root@magnolia local]# cd logc [root@magnolia local]# cd logch [root@magnolia local]# cd logch [root@magnolia local]# cd logche [root@magnolia local]# cd logche [root@magnolia local]# cd logchec [root@magnolia local]# cd logchec [root@magnolia local]# cd logcheck [root@magnolia local]# cd logcheck [root@magnolia local]# cd logcheck- [root@magnolia local]# cd logcheck- [root@magnolia local]# cd logcheck-1 [root@magnolia local]# cd logcheck-1 [root@magnolia local]# cd logcheck-1. [root@magnolia local]# cd logcheck-1. [root@magnolia local]# cd logcheck-1.1 [root@magnolia local]# cd logcheck-1.1 [root@magnolia local]# cd logcheck-1.1. [root@magnolia local]# cd logcheck-1.1. [root@magnolia local]# cd logcheck-1.1.1 [root@magnolia local]# cd logcheck-1.1.1 ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# l [root@magnolia logcheck-1.1.1]# l [root@magnolia logcheck-1.1.1]# ls [root@magnolia logcheck-1.1.1]# ls CHANGES INSTALL Makefile README.how.to.interpret src CREDITS LICENSE README README.keywords systems ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# l [root@magnolia logcheck-1.1.1]# l [root@magnolia logcheck-1.1.1]# lo [root@magnolia logcheck-1.1.1]# lo [root@magnolia logcheck-1.1.1]# loc [root@magnolia logcheck-1.1.1]# loc [root@magnolia logcheck-1.1.1]# loca [root@magnolia logcheck-1.1.1]# loca [root@magnolia logcheck-1.1.1]# local [root@magnolia logcheck-1.1.1]# local [root@magnolia logcheck-1.1.1]# loca [root@magnolia logcheck-1.1.1]# loca [root@magnolia logcheck-1.1.1]# locae [root@magnolia logcheck-1.1.1]# locae [root@magnolia logcheck-1.1.1]# locae [root@magnolia logcheck-1.1.1]# locae [root@magnolia logcheck-1.1.1]# locae [root@magnolia logcheck-1.1.1]# locae [root@magnolia logcheck-1.1.1]# loca [root@magnolia logcheck-1.1.1]# loca [root@magnolia logcheck-1.1.1]# locat [root@magnolia logcheck-1.1.1]# locat [root@magnolia logcheck-1.1.1]# locate [root@magnolia logcheck-1.1.1]# locate [root@magnolia logcheck-1.1.1]# locat [root@magnolia logcheck-1.1.1]# locat [root@magnolia logcheck-1.1.1]# loca [root@magnolia logcheck-1.1.1]# loca [root@magnolia logcheck-1.1.1]# loc [root@magnolia logcheck-1.1.1]# loc [root@magnolia logcheck-1.1.1]# lo [root@magnolia logcheck-1.1.1]# lo [root@magnolia logcheck-1.1.1]# l [root@magnolia logcheck-1.1.1]# l [root@magnolia logcheck-1.1.1]#  [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more I [root@magnolia logcheck-1.1.1]# more I [root@magnolia logcheck-1.1.1]# more IN [root@magnolia logcheck-1.1.1]# more IN [root@magnolia logcheck-1.1.1]# more INS [root@magnolia logcheck-1.1.1]# more INS [root@magnolia logcheck-1.1.1]# more INST [root@magnolia logcheck-1.1.1]# more INST [root@magnolia logcheck-1.1.1]# more INSTA [root@magnolia logcheck-1.1.1]# more INSTA [root@magnolia logcheck-1.1.1]# more INSTAL [root@magnolia logcheck-1.1.1]# more INSTAL [root@magnolia logcheck-1.1.1]# more INSTALL [root@magnolia logcheck-1.1.1]# more INSTALL INSTALLATION: Please read the entire file!! Operation --------- Logcheck contains several files: logcheck.sh -- The main script. This file controls all processing and looks at log files with simple grep commands. This file is executed on a timed basis from cron and reports findings to the sysadmin. logtail -- A custom executable that remembers the last position of a text file. This program is used by logcheck to parse out information from the last time the log was opened, this prevents reviewing old material twice. All log files will be processed with this program and will have a file named "########.offset" put in the same directory, where ####### is the name of the log file checked. This file contains the decimal offset information for logtail to work. If you delete it, logtail will parse the file from the beginning again. Logcheck tracks the size and inode of log files to enable it to tell when a log file has been rotated. If the inode of the log changes, or the file size is smaller than the last run, logtail will reset the counter and parse the entire file. logcheck.hacking -- This file contains keywords that are certifiable attacks on your system. I leave this file sparse, unless I know what a certain pattern of attack looks like (The default keywords are almost always --More--(9%) generated by Internet Security Scanner attacks, or sendmail(8) if it is being fed illegal syntax in address lines). Any keyword in a log file that matches here will generate a report with a more obnoxious header to grab your attention faster: "ACTIVE SYSTEM ATTACK" logcheck.violations -- This file contains keywords of system events that are usually seen as negative. Words such as "denied", "refused", etc. Positive words such as 'su' successes are also put in here. This file is of course not all inclusive and is heavily biased towards FWTK messages and BSDish messages with TCP wrappers installed. Violations here are reported under the heading "Security Violations" in the reports. logcheck.violations.ignore -- This file contains words that are reverse searched against the logcheck.violations file. If these words are found, that entry is not reported. An example of this are the following log entries: Feb 28 21:00:08 nemesis sendmail[5475]: VAA05473: to=crowland, ctladdr=root (0/0), delay=00:00:02, xdelay=00:00:01, mailer=local, stat=refused Feb 28 22:13:53 nemesis rshd: refused connect from hacker@evil.com:1490 The top entry is from sendmail and is a fairly common error, the stat line indicates that the remote host refused connections (stat=refused). This can happen for a variety of reasons and generally is not a problem. The bottom line however indicates that a person (hacker@evil.com) has tried --More--(18%) unsuccessfully to start an rsh session on my machine, this is bad (of course you shouldn't be running rshd to begin with). The logcheck.violations file will find the word 'refused' and will flag it to be logged, however this will report both instances as being bad and you will get false alarms from sendmail (both had the word refused). By putting the following in the logcheck.violations.ignore file you tell logcheck to ignore the sendmail problem and it will only report to you the bad rsh connection: (in logcheck.violations.ignore) mailer=local, stat=refused This will prevent reports from any line that contains "refused" but has the rest of the keywords "mailer=local, stat=refused." This is of course pretty basic, and not very intelligent, however you must remember that by forcing you to be specific in what you ignore, you will not overlook something important. A word of caution though, if you don't pick a long enough string to put in the logcheck.violations.ignore file then you could ignore significant events. Be very very careful what you put in here. The default file has only one entry in it to allow grep to run. Tune it to your system carefully! If the above did not make sense at all, leave the file as it is. logcheck.ignore -- This file is the catch-all file for words to look for in the logs and to NOT REPORT. Again be specific with what you want to ignore --More--(28%) and go easy on the wildcards. Anything that does not match what is in this file is reported (so you don't risk missing anything) as "Unusual System Activity." The default is again BSDish and biased towards FWTK and TCP Wrappers. To preserve integrity of the scans the following search order and rules are kept: 1) Active System Attacks are reported first. 2) Security Violations are reported second. 3) Unusual System Events are reported last. Keyword searches on the logcheck.hacking and logcheck.violations file are CASE INSENSITIVE to ensure we don't miss anything. Keyword searches on the logcheck.violations.ignore and logcheck.ignore files are CASE SENSITIVE to ensure again that we don't miss anything. The *.ignore files REQUIRE you to put in the exact text as part of the contents. The more sensitive logcheck.violations and logcheck.hacking files will report on any word, regardless of case, that is found as a match. The whole process follows the following structure: logcheck.sh executes hourly ----> logcheck.sh executes logtail on log files ----> logtail parses off any text from the last time it was run ---> logcheck greps text for system attack messages ---> --More--(36%) logcheck greps text for security violations ---> logcheck greps text for security violations to ignore ---> logcheck greps text for all messages to ignore. ---> any messages found are mailed to system admin. Overall it's a very simple process and is surprisingly good at telling you information about your system you were never aware of, but probably should have been. Installation ------------ If you know what a syslog.conf file is, know you have it set up to log as much information as possible, AND HAVE SECURED THE LOGS, go to step TWO, otherwise you should read step ONE. Step ONE: Configuring syslog daemon and SECURING your log files. Before setting up logcheck, you should ensure that your system is not only running syslog, but that you have it configured for maximum logging. On most all systems I recommend that you send all syslog messages to ONE file for logcheck to parse through. This configuration ensures that messages will not be missed. On BSDish systems this involves editing the file syslog.conf located in /etc. This file contains parameters for syslogd and if you don't understand them, PLEASE check: --More--(44%)  man syslog.conf - OR - A book. Many syslog.conf files are sensitive to using tabs instead of spaces for your entries and you will mysteriously hose syslogd daemon if you put in spaces so be careful. In the syslog.conf file you should put in an entry like this: *.info /var/log/messages Which will log EVERYTHING to the file "messages" located in /var/log. Obviously you should substitute /var/log to the directory typically found on your system. For BSDI and most variants this is /var/log for Linux this is /var/adm. Your syslog.conf file for your site will have the default in it. Remember this will log everything, if you have a very high volume server (for instance: mail) you may want to cut back on the logging to prevent over running of disk space. You can do this in the following way: *.info;mail.none /var/log/messages mail.notice /var/log/messages --More--(50%) This will only log non-standard mail messages, I don't recommend this however as it will make it hard to track mail into and out of your system if someone attempts, or succeeds, to gain entry. Many systems have separate log files for different system services, configuring syslog to do this could look like the following *.info;mail,ftp,daemon,authpriv.none /var/log/messages mail.info /var/log/mail.log ftp.info /var/log/ftp.log daemon.info /var/log/daemon.log authpriv.* /var/log/secure.log This configuration will have separate logs for the general system messages, mail, ftp, daemon and security messages. Logcheck can be setup to check for all of them. Again please see your syslog.conf man page for more information. Now that you have edited your syslog.conf file you need to re-start syslogd by sending the HUP signal to it. IMPORTANT: You must now go to your log directory (/var/log in the example above) and change the log file to owner root, group wheel and mode 600 on file permissions. First check if the file exists if it doesn't, you should make it. For example if your log files is simply called 'messages' you would do the following: --More--(58%) touch /var/log/messages Now you must ensure that you change the permissions in the following way: chown root.wheel /var/log/messages chmod 600 /var/log/messages I also recommend that any other log files have their permissions set in a similar way (at least to mode 600 if you can't change the owner/group). Log files contain very sensitive data about system operations and could contain passwords, system errors, and other data that can reveal vulnerabilites if you are not careful. I personally feel that these files should never be readable by any person other than root. BSD and FreeBSD: You should go to the /etc directory and edit the /etc/daily, /etc/weekly, and /etc/monthly scripts and change the 'rotate()' script function to change the log permissions on rotation. Simply change the line: cp /dev/null "$file"; chmod 644 "$file" To: cp /dev/null "$file"; chmod 600 "$file" (The above is for BSDI 2.x, BSDI 3.x uses an external rotate --More--(65%) function now, just change the mode sent to it from 644 to 600 and you'll be OK. FreeBSD will be similiar to the BSDI 2.x script) When logs are auto-rotated they will have the permissions set automatically. Once these steps have been completed you can move onto step TWO: Step TWO: Logcheck and logtail installation. Logcheck requires the following files to run: logcheck.sh logtail.c logcheck.hacking logcheck.violations logcheck.violations.ignore logcheck.ignore Pull logcheck.sh into your favorite editor and find the section entitled: CONFIGURATION SECTION. Change the name of the SYSADMIN variable to one of your liking. You can use local names (default is root), or e-mail addresses for remote logging. Go to the section entitled: LOG FILE CONFIGURATION SECTION and either uncomment the log files that apply to you, or add your own. Be sure --More--(71%) you know the difference between the > and >> operators before you do this. If you have one of the default system types (Linux, BSDI, FreeBSD, SunOS, Digital) you can simply type "make " and it will install for you at this point. If you are using an alternate path for the files (i.e NOT in /usr/local/whatever), you need to change the path entries for logcheck.hacking, logcheck.violations, logcheck.ignore, logcheck.violations.ignore, and logtail in the main logcheck.sh script. I don't recommend you do this unless you have to. If you changed the default paths /usr/local/etc and /usr/local/bin in the logcheck.sh file you need to edit the Makefile and change INSTALLDIR and INSTALLDIR_BIN to point to the same directories. Note that the Makefile will create a directory called /usr/local/etc/tmp by default. This is the scratch area for logcheck to handle it's files. I do NOT recommend that you use /tmp for any reason as it is publically accessible and may pose a danger if a user creates symbolic links to trick the logcheck script into overwriting an important system file. I would also change all automated system scripts to use this directory instead of /tmp which is notoriously unsafe. Editing Cron --More--(79%) ------------ After installing logcheck, you should edit your local crontab file for root and set logcheck to run once per hour (recommended, although you can do it more frequently, or less frequently, although the absolute minimum in my opinion is once every few hours or so). Examples are the following: Hourly check (BSD Systems and Redhat /etc/crontab): 00 * * * * root /bin/sh /usr/local/etc/logcheck.sh 15 Minute check (Linux Slackware Systems /var/spool/cron/crontabs/root): 00,15,30,45 * * * * /usr/local/etc/logcheck.sh The 15 minute check I would recommend for firewalls that generally don't produce messages unless they are in trouble. Remember, logcheck does not report anything if it has nothing useful to say (only if the rest of USENET could do this). So running it every 15 minutes will have no impact on your mailbox if the system being watched is quiet. Busier systems can be addressed by less frequent reporting, however longer reports mean you must spend more time analyzing them, and you may not like this either. Again I recommend hourly. --More--(87%) ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# c [root@magnolia logcheck-1.1.1]# c [root@magnolia logcheck-1.1.1]# cc [root@magnolia logcheck-1.1.1]# cc [root@magnolia logcheck-1.1.1]# c [root@magnolia logcheck-1.1.1]# c [root@magnolia logcheck-1.1.1]#  [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# l [root@magnolia logcheck-1.1.1]# l [root@magnolia logcheck-1.1.1]# ls [root@magnolia logcheck-1.1.1]# ls CHANGES INSTALL Makefile README.how.to.interpret src CREDITS LICENSE README README.keywords systems ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# c [root@magnolia logcheck-1.1.1]# c [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd s [root@magnolia logcheck-1.1.1]# cd s [root@magnolia logcheck-1.1.1]# cd sy [root@magnolia logcheck-1.1.1]# cd sy [root@magnolia logcheck-1.1.1]# cd sys [root@magnolia logcheck-1.1.1]# cd sys [root@magnolia logcheck-1.1.1]# cd syst [root@magnolia logcheck-1.1.1]# cd syst [root@magnolia logcheck-1.1.1]# cd syste [root@magnolia logcheck-1.1.1]# cd syste [root@magnolia logcheck-1.1.1]# cd system [root@magnolia logcheck-1.1.1]# cd system [root@magnolia logcheck-1.1.1]# cd systems [root@magnolia logcheck-1.1.1]# cd systems ]0;barrie@magnolia:/usr/local/logcheck-1.1.1/systems [root@magnolia systems]# [root@magnolia systems]# [root@magnolia systems]# l [root@magnolia systems]# l [root@magnolia systems]# ls [root@magnolia systems]# ls bsdos digital freebsd generic hpux linux sun ]0;barrie@magnolia:/usr/local/logcheck-1.1.1/systems [root@magnolia systems]# [root@magnolia systems]# [root@magnolia systems]# c [root@magnolia systems]# c [root@magnolia systems]# cd [root@magnolia systems]# cd [root@magnolia systems]# cd [root@magnolia systems]# cd [root@magnolia systems]# cd l [root@magnolia systems]# cd l [root@magnolia systems]# cd li [root@magnolia systems]# cd li [root@magnolia systems]# cd lin [root@magnolia systems]# cd lin [root@magnolia systems]# cd linu [root@magnolia systems]# cd linu [root@magnolia systems]# cd linux [root@magnolia systems]# cd linux ]0;barrie@magnolia:/usr/local/logcheck-1.1.1/systems/linux [root@magnolia linux]# [root@magnolia linux]# [root@magnolia linux]# l [root@magnolia linux]# l [root@magnolia linux]# ls [root@magnolia linux]# ls logcheck.hacking logcheck.sh logcheck.violations.ignore README.linux.IMPORTANT logcheck.ignore logcheck.violations README.linux ]0;barrie@magnolia:/usr/local/logcheck-1.1.1/systems/linux [root@magnolia linux]# [root@magnolia linux]# [root@magnolia linux]# m [root@magnolia linux]# m [root@magnolia linux]# mo [root@magnolia linux]# mo [root@magnolia linux]# mor [root@magnolia linux]# mor [root@magnolia linux]# more [root@magnolia linux]# more [root@magnolia linux]# more [root@magnolia linux]# more [root@magnolia linux]# more R [root@magnolia linux]# more R [root@magnolia linux]# more RE [root@magnolia linux]# more RE [root@magnolia linux]# more REA [root@magnolia linux]# more REA [root@magnolia linux]# more READ [root@magnolia linux]# more READ [root@magnolia linux]# more READM [root@magnolia linux]# more READM [root@magnolia linux]# more README [root@magnolia linux]# more README [root@magnolia linux]# more README> [root@magnolia linux]# more README> [root@magnolia linux]# more README [root@magnolia linux]# more README [root@magnolia linux]# more README. [root@magnolia linux]# more README. [root@magnolia linux]# more README.l [root@magnolia linux]# more README.l [root@magnolia linux]# more README.li [root@magnolia linux]# more README.li [root@magnolia linux]# more README.lin [root@magnolia linux]# more README.lin [root@magnolia linux]# more README.linu [root@magnolia linux]# more README.linu [root@magnolia linux]# more README.linux [root@magnolia linux]# more README.linux These files will work well with Linux Slackware and Redhat releases and perhaps others (not tested). Type "make install" as root to install them on your system. Edit the cron to run them once per hour. The default account to mail reports to is root. -- Craig ]0;barrie@magnolia:/usr/local/logcheck-1.1.1/systems/linux [root@magnolia linux]# [root@magnolia linux]# [root@magnolia linux]# l [root@magnolia linux]# l [root@magnolia linux]# ls [root@magnolia linux]# ls logcheck.hacking logcheck.sh logcheck.violations.ignore README.linux.IMPORTANT logcheck.ignore logcheck.violations README.linux ]0;barrie@magnolia:/usr/local/logcheck-1.1.1/systems/linux [root@magnolia linux]# [root@magnolia linux]# [root@magnolia linux]# m [root@magnolia linux]# m [root@magnolia linux]# mo [root@magnolia linux]# mo [root@magnolia linux]# mor [root@magnolia linux]# mor [root@magnolia linux]# more [root@magnolia linux]# more [root@magnolia linux]# more [root@magnolia linux]# more [root@magnolia linux]# more R [root@magnolia linux]# more R [root@magnolia linux]# more RE [root@magnolia linux]# more RE [root@magnolia linux]# more REA [root@magnolia linux]# more REA [root@magnolia linux]# more READ [root@magnolia linux]# more READ [root@magnolia linux]# more READM [root@magnolia linux]# more READM [root@magnolia linux]# more README [root@magnolia linux]# more README [root@magnolia linux]# more README. [root@magnolia linux]# more README. [root@magnolia linux]# more README.l [root@magnolia linux]# more README.l [root@magnolia linux]# more README.li [root@magnolia linux]# more README.li [root@magnolia linux]# more README.lin [root@magnolia linux]# more README.lin [root@magnolia linux]# more README.linu [root@magnolia linux]# more README.linu [root@magnolia linux]# more README.linux [root@magnolia linux]# more README.linux [root@magnolia linux]# more README.linux. [root@magnolia linux]# more README.linux. [root@magnolia linux]# more README.linux.I [root@magnolia linux]# more README.linux.I [root@magnolia linux]# more README.linux.IM [root@magnolia linux]# more README.linux.IM [root@magnolia linux]# more README.linux.IMP [root@magnolia linux]# more README.linux.IMP [root@magnolia linux]# more README.linux.IMPO [root@magnolia linux]# more README.linux.IMPO [root@magnolia linux]# more README.linux.IMPOR [root@magnolia linux]# more README.linux.IMPOR [root@magnolia linux]# more README.linux.IMPORT [root@magnolia linux]# more README.linux.IMPORT [root@magnolia linux]# more README.linux.IMPORTA [root@magnolia linux]# more README.linux.IMPORTA [root@magnolia linux]# more README.linux.IMPORTAN [root@magnolia linux]# more README.linux.IMPORTAN [root@magnolia linux]# more README.linux.IMPORTANT [root@magnolia linux]# more README.linux.IMPORTANT These files will work well with Linux Slackware release 3.0 and Red Hat release 3.0.3 and 4.x Type "make install" as root to install them on your system. Edit the cron to run them once per hour. The default account to mail reports to is root. There is also a quirky bug that I've only seen on Linux systems that will sometimes report the following under "Unusual System Events": 1 I can only speculate that sendmail is adding a newline to the end of the status line to make this entry appear to be separate. Usually the message will look like: Unusual System Events =-=-=-=-=-=-=-=-=-=- root 1 127 Where the first part is the user of the person running logcheck, and the last entry is the size of the total message in bytes. This is fixed by putting in the entry "root 1" in the logcheck.ignore file. I've already done this. If you run logcheck under another account you'll --More--(55%) have to add your own line. If anyone has a better solution let me know, it appears to only be a problem on Linux boxes. Lastly, many Linux releases do not rotate log files and save the old logs. I recommend that you enable log rotating to save space. On Red Hat Linux Systems, the log files are trimmed down nightly with the size command and the resulting file contains the same inode. This causes logtail to issue a warning because the log file appears to be *shorter* than the last time checked (smaller size, but the same inode) and logtail thinks that the log has been tampered with. You can circumvent this by making sure the logfile is moved to another name and a new empty file is made in its place. Look at the logrotate(8) command for more information. -- Craig ]0;barrie@magnolia:/usr/local/logcheck-1.1.1/systems/linux [root@magnolia linux]# [root@magnolia linux]# [root@magnolia linux]# p [root@magnolia linux]# p [root@magnolia linux]# pw [root@magnolia linux]# pw [root@magnolia linux]# pwd [root@magnolia linux]# pwd /usr/local/logcheck-1.1.1/systems/linux ]0;barrie@magnolia:/usr/local/logcheck-1.1.1/systems/linux [root@magnolia linux]# [root@magnolia linux]# [root@magnolia linux]# l [root@magnolia linux]# l [root@magnolia linux]# ls [root@magnolia linux]# ls logcheck.hacking logcheck.sh logcheck.violations.ignore README.linux.IMPORTANT logcheck.ignore logcheck.violations README.linux ]0;barrie@magnolia:/usr/local/logcheck-1.1.1/systems/linux [root@magnolia linux]# [root@magnolia linux]# [root@magnolia linux]# m [root@magnolia linux]# m [root@magnolia linux]# mo [root@magnolia linux]# mo [root@magnolia linux]# mor [root@magnolia linux]# mor [root@magnolia linux]# more [root@magnolia linux]# more [root@magnolia linux]# more [root@magnolia linux]# more [root@magnolia linux]# more l [root@magnolia linux]# more l [root@magnolia linux]# more lo [root@magnolia linux]# more lo [root@magnolia linux]# more lon [root@magnolia linux]# more lon [root@magnolia linux]# more long [root@magnolia linux]# more long [root@magnolia linux]# more lon [root@magnolia linux]# more lon [root@magnolia linux]# more lo [root@magnolia linux]# more lo [root@magnolia linux]# more log [root@magnolia linux]# more log [root@magnolia linux]# more logc [root@magnolia linux]# more logc [root@magnolia linux]# more logch [root@magnolia linux]# more logch [root@magnolia linux]# more logche [root@magnolia linux]# more logche [root@magnolia linux]# more logchec [root@magnolia linux]# more logchec [root@magnolia linux]# more logcheck [root@magnolia linux]# more logcheck [root@magnolia linux]# more logcheck. [root@magnolia linux]# more logcheck. [root@magnolia linux]# more logcheck.s [root@magnolia linux]# more logcheck.s [root@magnolia linux]# more logcheck.sh [root@magnolia linux]# more logcheck.sh #!/bin/sh # # logcheck.sh: Log file checker # Written by Craig Rowland # # This file needs the program logtail.c to run # # This script checks logs for unusual activity and blatant # attempts at hacking. All items are mailed to administrators # for review. This script and the logtail.c program are based upon # the frequentcheck.sh script idea from the Gauntlet(tm) Firewall # (c)Trusted Information Systems Inc. The original authors are # Marcus J. Ranum and Fred Avolio. # # Default search files are tuned towards the TIS Firewall toolkit # the TCP Wrapper program. Custom daemons and reporting facilites # can be accounted for as well...read the rest of the script for # details. # # Version Information # # 1.0 9/29/96 -- Initial Release # 1.01 11/01/96 -- Added working /tmp directory for symlink protection # (Thanks Richard Bullington (rbulling@obscure.org) # 1.1 1/03/97 -- Made this script more portable for Sun's. # 1/03/97 -- Made this script work on HPUX --More--(9%) # 5/14/97 -- Added Digital OSF/1 logging support. Big thanks # to Jay Vassos-Libove for # his changes. # CONFIGURATION SECTION PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/ucb:/usr/local/bin # Logcheck is pre-configured to work on most BSD like systems, however it # is a rather dumb program and may need some help to work on other # systems. Please check the following command paths to ensure they are # correct. # Person to send log activity to. SYSADMIN=root # Full path to logtail program. # This program is required to run this script and comes with the package. LOGTAIL=/usr/local/bin/logtail # Full path to SECURED (non public writable) /tmp directory. # Prevents Race condition and potential symlink problems. I highly # recommend you do NOT make this a publically writable/readable directory. # You would also be well advised to make sure all your system/cron scripts --More--(18%) ]0;barrie@magnolia:/usr/local/logcheck-1.1.1/systems/linux [root@magnolia linux]# [root@magnolia linux]# [root@magnolia linux]# v [root@magnolia linux]# v [root@magnolia linux]# vi [root@magnolia linux]# vi [root@magnolia linux]# vi! [root@magnolia linux]# vi! [root@magnolia linux]# vi!$ [root@magnolia linux]# vi!$ [root@magnolia linux]# vi! [root@magnolia linux]# vi! [root@magnolia linux]# vi [root@magnolia linux]# vi [root@magnolia linux]# vi [root@magnolia linux]# vi [root@magnolia linux]# vi ! [root@magnolia linux]# vi ! [root@magnolia linux]# vi !$ [root@magnolia linux]# vi !$ vi logcheck.sh [?1048h[?1047h[?1h=[?25h[?25h[?25l"logcheck.sh" 272L, 10633C#!/bin/sh # # logcheck.sh: Log file checker # Written by Craig Rowland # # This file needs the program logtail.c to run # # This script checks logs for unusual activity and blatant # attempts at hacking. All items are mailed to administrators # for review. This script and the logtail.c program are based upon # the frequentcheck.sh script idea from the Gauntlet(tm) Firewall # (c)Trusted Information Systems Inc. The original authors are # Marcus J. Ranum and Fred Avolio. # # Default search files are tuned towards the TIS Firewall toolkit # the TCP Wrapper program. Custom daemons and reporting facilites # can be accounted for as well...read the rest of the script for # details. # # Version Information # # 1.0 9/29/96 -- Initial Release # 1.01 11/01/96 -- Added working /tmp directory for symlink protection # (Thanks Richard Bullington (rbulling@obscure.org) # 1.1 1/03/97 -- Made this script more portable for Sun's. # 1/03/97 -- Made this script work on HPUX # 5/14/97 -- Added Digital OSF/1 logging support. Big thanks1,1Top[?25h[?25l2[?25h[?25l3[?25h[?25l4[?25h[?25l5[?25h[?25l6[?25h[?25l7[?25h[?25l8[?25h[?25l9[?25h[?25l10,1[?25h[?25l1[?25h[?25l2[?25h[?25l3[?25h[?25l4[?25h[?25l5[?25h[?25l6[?25h[?25l7[?25h[?25l8[?25h[?25l9[?25h[?25l20[?25h[?25l1[?25h[?25l2[?25h[?25l3[?25h[?25l4[?25h[?25l5[?25h[?25l6[?25h[?25l7[?25h[?25l # to Jay Vassos-Libove for8 0%[?25h[?25l # his changes.9[?25h[?25l 301[?25h[?25l 1,0-1[?25h[?25l # CONFIGURATION SECTION2,1 2[?25h[?25l 3,0-1[?25h[?25l PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/ucb:/usr/local/bin4,1 [?25h[?25l 5,0-13[?25h[?25l # Logcheck is pre-configured to work on most BSD like systems, however it6,1 [?25h[?25l # is a rather dumb program and may need some help to work on other74[?25h[?25l # systems. Please check the following command paths to ensure they are 8[?25h[?25l # correct.9[?25h[?25l 40,0-15[?25h[?25l # Person to send log activity to.1,1 [?25h[?25l SYSADMIN=root26[?25h[?25l 3,0-1[?25h[?25l # Full path to logtail program.4,1 [?25h[?25l # This program is required to run this script and comes with the package.57[?25h[?25l 6,0-1[?25h[?25l LOGTAIL=/usr/local/bin/logtail7,1 8[?25h[?25l 8,0-1[?25h[?25l # Full path to SECURED (non public writable) /tmp directory.9,1 [?25h[?25l # Prevents Race condition and potential symlink problems. I highly509[?25h[?25l # recommend you do NOT make this a publically writable/readable directory.1[?25h[?25l # You would also be well advised to make sure all your system/cron scripts210[?25h[?25l # use this directory for their "scratch" area. 3[?25h[?25l 4,0-11[?25h[?25l TMPDIR=/usr/local/etc/tmp5,1 [?25h[?25l 6,0-1[?25h[?25l # The 'grep' command. This command MUST support the7,1 2[?25h[?25l # '-i' '-v' and '-f' flags!! The GNU grep does this by default (that's8[?25h[?25l # good GNUs for you Linux/FreeBSD/BSDI people :) ). The Sun grep I'm told93[?25h[?25l # does not support these switches, but the 'egrep' command does (Thanks60[?25h[?25l # Jason ). Since grep and egrep are usually the GNU 1[?25h[?25l # variety on most systems (well most Linux, FreeBSD, BSDI, etc) and just24[?25h[?25l # hard links to each other we'll just specify egrep here. Change this if 3[?25h[?25l # you get errors.45[?25h[?25l 5,0-1[?25h[?25l # Linux, FreeBSD, BSDI, Sun, HPUX, etc.6,1 [?25h[?25l GREP=egrep76[?25h[?25l 8,0-1[?25h[?25l # The 'mail' command. Most systems this should be OK to leave as is.9,1 7[?25h[?25l # If your default mail command does not support the '-s' (subject) command70[?25h[?25l # line switch you will need to change this command one one that does.1[?25h[?25l # The only system I've seen this to be a problem on are HPUX boxes. 28[?25h[?25l # Naturally, the HPUX is so superior to the rest of UNIX OS's that they3[?25h[?25l # feel they need to do everything differently to remind the rest that49[?25h[?25l # they are the best ;).5[?25h[?25l 6,0-120[?25h[?25l # Linux, FreeBSD, BSDI, Sun, etc.7,1 [?25h[?25l MAIL=mail8[?25h[?25l # HPUX 10.x and others(?)91[?25h[?25l #MAIL=mailx80[?25h[?25l # Digital OSF/1, Irix12[?25h[?25l #MAIL=Mail2[?25h[?25l 3,0-1[?25h[?25l # File of known active hacking attack messages to look for.4,1 3[?25h[?25l # Only put messages in here if you are sure they won't cause5[?25h[?25l # false alarms. This is a rather generic way of checking for 64[?25h[?25l # malicious activity and can be inaccurate unless you know7[?25h[?25l # what past hacking activity looks like. The default is to8[?25h[?25l # look for generic ISS probes (who the hell else looks for 95[?25h[?25l # "WIZ" besides ISS?), and obvious sendmail attacks/probes.90[?25h[?25l 1,0-16[?25h[?25l HACKING_FILE=/usr/local/etc/logcheck.hacking2,1 [?25h[?25l 3,0-1[?25h[?25l # File of security violation patterns to specifically look for.4,1 7[?25h[?25l # This file should contain keywords of information administrators should5[?25h[?25l # probably be aware of. May or may not cause false alarms sometimes.68[?25h[?25l # Generally, anything that is "negative" is put in this file. It may miss7[?25h[?25l # some items, but these will be caught by the next check. Move suspicious8[?25h[?25l # items into this file to have them reported regularly.99[?25h[?25l 100,0-1[?25h[?25l VIOLATIONS_FILE=/usr/local/etc/logcheck.violations1,1 30[?25h[?25l 2,0-1[?25h[?25l # File that contains more complete sentences that have keywords from3,1 1[?25h[?25l # the violations file. These keywords are normal and are not cause for 4[?25h[?25l # concern but could cause a false alarm. An example of this is the word 5[?25h[?25l # "refused" which is often reported by sendmail if a message cannot be 62[?25h[?25l # delivered or can be a more serious security violation of a system 7[?25h[?25l # attaching to illegal ports. Obviously you would put the sendmail 83[?25h[?25l # warning as part of this file. Use your judgement before putting words 9[?25h[?25l # in here or you can miss really important events. The default is to leave10[?25h[?25l # this file with only a couple entries. DO NOT LEAVE THE FILE EMPTY. Some 14[?25h[?25l # grep's will assume that an EMPTY file means a wildcard and will ignore 2[?25h[?25l # everything! The basic configuration allows for the more frequent sendmail35[?25h[?25l # error.4[?25h[?25l #5[?25h[?25l # Again, be careful what you put in here and DO NOT LEAVE IT EMPTY!66[?25h[?25l 7,0-1[?25h[?25l VIOLATIONS_IGNORE_FILE=/usr/local/etc/logcheck.violations.ignore8,1 7[?25h[?25l 9,0-1[?25h[?25l # This is the name of a file that contains patterns that we should20,1 [?25h[?25l # ignore if found in a log file. If you have repeated false alarms18[?25h[?25l # or want specific errors ignored, you should put them in here.2[?25h[?25l # Once again, be as specific as possible, and go easy on the wildcards39[?25h[?25l 4,0-1[?25h[?25l IGNORE_FILE=/usr/local/etc/logcheck.ignore5,1 40[?25h[?25l 6,0-1[?25h[?25l # The files are reported in the order of hacking, security 7,1 [?25h[?25l # violations, and unusual system events. Notice that this81[?25h[?25l # script uses the principle of "That which is not explicitely9[?25h[?25l # ignored is reported" in that the script will report all items302[?25h[?25l # that you do not tell it to ignore specificially. Be careful1[?25h[?25l # how you use wildcards in the logcheck.ignore file or you 2[?25h[?25l # may miss important entries.33[?25h[?25l 4,0-1[?25h[?25l # Make sure we really did clean up from the last run.5,1 4[?25h[?25l # Also this ensures that people aren't trying to trick us into6[?25h[?25l # overwriting files that we aren't supposed to. This is still a race7[?25h[?25l # condition, but if you are in a temp directory that does not have85[?25h[?25l # generic luser access it is not a problem. Do not allow this program9[?25h[?25l # to write to a generic /tmp directory where others can watch and/or406[?25h[?25l # create files!!1[?25h[?25l 2,0-1[?25h[?25l # Shouldn't need to touch these...3,1 7[?25h[?25l HOSTNAME=`hostname`4[?25h[?25l DATE=`date +%m/%d/%y:%H.%M`58[?25h[?25l 6,0-1[?25h[?25l umask 0777,1 [?25h[?25l rm -f $TMPDIR/check.$$ $TMPDIR/checkoutput.$$ $TMPDIR/checkreport.$$89[?25h[?25l if [ -f $TMPDIR/check.$$ -o -f $TMPDIR/checkoutput.$$ -o -f $TMPDIR/checkreport.$$ ]; then9[?25h[?25l echo "Log files exist in $TMPDIR directory that cannot be removed. This 50,1-850[?25h[?25l may be an attempt to spoof the log checker." \1,1 [?25h[?25l  | $MAIL -s "$HOSTNAME $DATE ACTIVE SYSTEM ATTACK!" $SYSADMIN2,1-81[?25h[?25l exit 13[?25h[?25l fi4,1 [?25h[?25l 5,0-12[?25h[?25l # LOG FILE CONFIGURATION SECTION6,1 [?25h[?25l # You might have to customize these entries depending on how 73[?25h[?25l # you have syslogd configured. Be sure you check all relevant logs.8[?25h[?25l # The logtail utility is required to read and mark log files.9[?25h[?25l # See INSTALL for more information. Again, using one log file604[?25h[?25l # is preferred and is easier to manage. Be sure you know what the1[?25h[?25l # > and >> operators do before you change them. LOG FILES SHOULD25[?25h[?25l # ALWAYS BE chmod 600 OWNER root!!3[?25h[?25l 4,0-1[?25h[?25l # Generic and Linux Slackware 3.x5,1 6[?25h[?25l #$LOGTAIL /var/log/messages > $TMPDIR/check.$$6[?25h[?25l 7,0-17[?25h[?25l # Linux Red Hat Version 3.x, 4.x8,1 [?25h[?25l $LOGTAIL /var/log/messages > $TMPDIR/check.$$9[?25h[?25l $LOGTAIL /var/log/secure >> $TMPDIR/check.$$708[?25h[?25l $LOGTAIL /var/log/maillog >> $TMPDIR/check.$$1[?25h[?25l 2,0-19[?25h[?25l # FreeBSD 2.x3,1 [?25h[?25l #$LOGTAIL /var/log/messages > $TMPDIR/check.$$460[?25h[?25l #$LOGTAIL /var/log/maillog >> $TMPDIR/check.$$5[?25h[?25l 6,0-1[?25h[?25l # BSDI 2.x7,1 1[?25h[?25l #$LOGTAIL /var/log/messages > $TMPDIR/check.$$8[?25h[?25l #$LOGTAIL /var/log/secure >> $TMPDIR/check.$$92[?25h[?25l #$LOGTAIL /var/log/maillog >> $TMPDIR/check.$$80[?25h[?25l #$LOGTAIL /var/log/ftp.log >> $TMPDIR/check.$$1[?25h[?25l # Un-comment out the line below if you are using BSDI 2.123[?25h[?25l #$LOGTAIL /var/log/daemon.log >> $TMPDIR/check.$$3[?25h[?25l 4,0-14[?25h[?25l # SunOS, Sun Solaris 2.55,1 [?25h[?25l #$LOGTAIL /var/log/syslog > $TMPDIR/check.$$6[?25h[?25l #$LOGTAIL /var/adm/messages >> $TMPDIR/check.$$75[?25h[?25l 8,0-1[?25h[?25l # HPUX 10.x and others(?)9,1 6[?25h[?25l #$LOGTAIL /var/adm/syslog/syslog.log > $TMPDIR/check.$$90[?25h[?25l 1,0-1[?25h[?25l # Digital OSF/12,1 7[?25h[?25l # OSF/1 - uses rotating log directory with date & time in name3[?25h[?25l # LOGDIRS=`find /var/adm/syslog.dated/* -type d -prune -print`48[?25h[?25l # LOGDIR=`ls -dtr1 $LOGDIRS | tail -1` 5[?25h[?25l # if [ ! -d "$LOGDIR" ]6[?25h[?25l # then79[?25h[?25l # echo "Can't identify current log directory." >> $TMPDIR/checkrepo$8[?25h[?25l # else970[?25h[?25l # $LOGTAIL $LOGDIR/auth.log >> $TMPDIR/check.$$200[?25h[?25l # $LOGTAIL $LOGDIR/daemon.log >> $TMPDIR/check.$$11[?25h[?25l # $LOGTAIL $LOGDIR/kern.log >> $TMPDIR/check.$$2[?25h[?25l # $LOGTAIL $LOGDIR/lpr.log >> $TMPDIR/check.$$3[?25h[?25l # $LOGTAIL $LOGDIR/mail.log >> $TMPDIR/check.$$42[?25h[?25l # $LOGTAIL $LOGDIR/syslog.log >> $TMPDIR/check.$$5[?25h[?25l # $LOGTAIL $LOGDIR/user.log >> $TMPDIR/check.$$63[?25h[?25l # fi7[?25h[?25l #8[?25h[?25l 9,0-14[?25h[?25l 10[?25h[?25l # END CONFIGURATION SECTION. YOU SHOULDN'T HAVE TO EDIT ANYTHING1,1 5[?25h[?25l # BELOW THIS LINE.2[?25h[?25l 3,0-1[?25h[?25l # Set the flag variables4,1 6[?25h[?25l FOUND=05[?25h[?25l ATTACK=067[?25h[?25l 7,0-1[?25h[?25l # See if the tmp file exists and actually has data to check, 8,1 [?25h[?25l # if it doesn't we should erase it and exit as our job is done.98[?25h[?25l 20[?25h[?25l if [ ! -s $TMPDIR/check.$$ ]; then19[?25h[?25l rm -f $TMPDIR/check.$$2,1-8[?25h[?25l exit 0380[?25h[?25l fi4,1 [?25h[?25l 5,0-1[?25h[?25l # Perform Searches6,1 1[?25h[?25l 7,0-1[?25h[?25l # Check for blatant hacking attempts8,1 2[?25h[?25l if [ -f "$HACKING_FILE" ]; then9[?25h[?25l if $GREP -i -f $HACKING_FILE $TMPDIR/check.$$ > $TMPDIR/checkoutput.$$; then30,1-8[?25h[?25l echo >> $TMPDIR/checkreport.$$13[?25h[?25l echo "Active System Attack Alerts" >> $TMPDIR/checkreport.$$2[?25h[?25l echo "=-=-=-=-=-=-=-=-=-=-=-=-=-=" >> $TMPDIR/checkreport.$$34[?25h[?25l cat $TMPDIR/checkoutput.$$ >> $TMPDIR/checkreport.$$4[?25h[?25l FOUND=15[?25h[?25l ATTACK=165[?25h[?25l fi7[?25h[?25l fi8,1 6[?25h[?25l 9,0-1[?25h[?25l:[?25hq [?25l[?1l>[?25h[?1047l[?1048l]0;barrie@magnolia:/usr/local/logcheck-1.1.1/systems/linux [root@magnolia linux]# [root@magnolia linux]# [root@magnolia linux]# c [root@magnolia linux]# c [root@magnolia linux]# cd [root@magnolia linux]# cd [root@magnolia linux]# cd [root@magnolia linux]# cd [root@magnolia linux]# cd . [root@magnolia linux]# cd . [root@magnolia linux]# cd .. [root@magnolia linux]# cd .. ]0;barrie@magnolia:/usr/local/logcheck-1.1.1/systems [root@magnolia systems]# [root@magnolia systems]# [root@magnolia systems]# c [root@magnolia systems]# c [root@magnolia systems]# cd [root@magnolia systems]# cd [root@magnolia systems]# cd [root@magnolia systems]# cd [root@magnolia systems]# cd . [root@magnolia systems]# cd . [root@magnolia systems]# cd .. [root@magnolia systems]# cd .. ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# l [root@magnolia logcheck-1.1.1]# l [root@magnolia logcheck-1.1.1]# ls [root@magnolia logcheck-1.1.1]# ls CHANGES INSTALL Makefile README.how.to.interpret src CREDITS LICENSE README README.keywords systems ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# c [root@magnolia logcheck-1.1.1]# c [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd s [root@magnolia logcheck-1.1.1]# cd s [root@magnolia logcheck-1.1.1]# cd sr [root@magnolia logcheck-1.1.1]# cd sr [root@magnolia logcheck-1.1.1]# cd src [root@magnolia logcheck-1.1.1]# cd src ]0;barrie@magnolia:/usr/local/logcheck-1.1.1/src [root@magnolia src]# [root@magnolia src]# [root@magnolia src]# l [root@magnolia src]# l [root@magnolia src]# ls [root@magnolia src]# ls logtail.c ]0;barrie@magnolia:/usr/local/logcheck-1.1.1/src [root@magnolia src]# [root@magnolia src]# [root@magnolia src]# c [root@magnolia src]# c [root@magnolia src]# cd [root@magnolia src]# cd [root@magnolia src]# cd [root@magnolia src]# cd [root@magnolia src]# cd . [root@magnolia src]# cd . [root@magnolia src]# cd .. [root@magnolia src]# cd .. ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# ma [root@magnolia logcheck-1.1.1]# ma [root@magnolia logcheck-1.1.1]# mak [root@magnolia logcheck-1.1.1]# mak [root@magnolia logcheck-1.1.1]# make [root@magnolia logcheck-1.1.1]# make [root@magnolia logcheck-1.1.1]# make [root@magnolia logcheck-1.1.1]# make [root@magnolia logcheck-1.1.1]# make l [root@magnolia logcheck-1.1.1]# make l [root@magnolia logcheck-1.1.1]# make li [root@magnolia logcheck-1.1.1]# make li [root@magnolia logcheck-1.1.1]# make lin [root@magnolia logcheck-1.1.1]# make lin [root@magnolia logcheck-1.1.1]# make linu [root@magnolia logcheck-1.1.1]# make linu [root@magnolia logcheck-1.1.1]# make linux [root@magnolia logcheck-1.1.1]# make linux make install SYSTYPE=linux make[1]: Entering directory `/usr/local/logcheck-1.1.1' Making linux cc -O -o ./src/logtail ./src/logtail.c src/logtail.c: In function `main': src/logtail.c:51: warning: return type of `main' is not `int' Creating temp directory /usr/local/etc/tmp Setting temp directory permissions chmod 700 /usr/local/etc/tmp Copying files cp ./systems/linux/logcheck.hacking /usr/local/etc cp ./systems/linux/logcheck.violations /usr/local/etc cp ./systems/linux/logcheck.violations.ignore /usr/local/etc cp ./systems/linux/logcheck.ignore /usr/local/etc cp ./systems/linux/logcheck.sh /usr/local/etc cp ./src/logtail /usr/local/bin Setting permissions chmod 700 /usr/local/etc/logcheck.sh chmod 700 /usr/local/bin/logtail chmod 600 /usr/local/etc/logcheck.violations.ignore chmod 600 /usr/local/etc/logcheck.violations chmod 600 /usr/local/etc/logcheck.hacking chmod 600 /usr/local/etc/logcheck.ignore Done. Don't forget to set your crontab. make[1]: Leaving directory `/usr/local/logcheck-1.1.1' ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# l [root@magnolia logcheck-1.1.1]# l [root@magnolia logcheck-1.1.1]# ls [root@magnolia logcheck-1.1.1]# ls CHANGES INSTALL Makefile README.how.to.interpret src CREDITS LICENSE README README.keywords systems ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mot [root@magnolia logcheck-1.1.1]# mot [root@magnolia logcheck-1.1.1]# motr [root@magnolia logcheck-1.1.1]# motr [root@magnolia logcheck-1.1.1]# motr [root@magnolia logcheck-1.1.1]# motr [root@magnolia logcheck-1.1.1]# motr s [root@magnolia logcheck-1.1.1]# motr s [root@magnolia logcheck-1.1.1]# motr sk [root@magnolia logcheck-1.1.1]# motr sk [root@magnolia logcheck-1.1.1]# motr skr [root@magnolia logcheck-1.1.1]# motr skr [root@magnolia logcheck-1.1.1]# motr skrg [root@magnolia logcheck-1.1.1]# motr skrg [root@magnolia logcheck-1.1.1]# motr skrgl [root@magnolia logcheck-1.1.1]# motr skrgl [root@magnolia logcheck-1.1.1]# motr skrglr [root@magnolia logcheck-1.1.1]# motr skrglr [root@magnolia logcheck-1.1.1]# motr skrgl [root@magnolia logcheck-1.1.1]# motr skrgl [root@magnolia logcheck-1.1.1]# motr skrg [root@magnolia logcheck-1.1.1]# motr skrg [root@magnolia logcheck-1.1.1]# motr skr [root@magnolia logcheck-1.1.1]# motr skr [root@magnolia logcheck-1.1.1]# motr sk [root@magnolia logcheck-1.1.1]# motr sk [root@magnolia logcheck-1.1.1]# motr s [root@magnolia logcheck-1.1.1]# motr s [root@magnolia logcheck-1.1.1]# motr  [root@magnolia logcheck-1.1.1]# motr [root@magnolia logcheck-1.1.1]# motr [root@magnolia logcheck-1.1.1]# motr [root@magnolia logcheck-1.1.1]# mot [root@magnolia logcheck-1.1.1]# mot [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mot [root@magnolia logcheck-1.1.1]# mot [root@magnolia logcheck-1.1.1]# motr [root@magnolia logcheck-1.1.1]# motr [root@magnolia logcheck-1.1.1]# motr [root@magnolia logcheck-1.1.1]# motr [root@magnolia logcheck-1.1.1]# motr [root@magnolia logcheck-1.1.1]# motr [root@magnolia logcheck-1.1.1]# mot [root@magnolia logcheck-1.1.1]# mot [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mot [root@magnolia logcheck-1.1.1]# mot [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more M [root@magnolia logcheck-1.1.1]# more M [root@magnolia logcheck-1.1.1]# more Ma [root@magnolia logcheck-1.1.1]# more Ma [root@magnolia logcheck-1.1.1]# more Mak [root@magnolia logcheck-1.1.1]# more Mak [root@magnolia logcheck-1.1.1]# more Make [root@magnolia logcheck-1.1.1]# more Make [root@magnolia logcheck-1.1.1]# more MakeF [root@magnolia logcheck-1.1.1]# more MakeF [root@magnolia logcheck-1.1.1]# more MakeFi [root@magnolia logcheck-1.1.1]# more MakeFi [root@magnolia logcheck-1.1.1]# more MakeFil [root@magnolia logcheck-1.1.1]# more MakeFil [root@magnolia logcheck-1.1.1]# more MakeFile [root@magnolia logcheck-1.1.1]# more MakeFile MakeFile: No such file or directory ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# l [root@magnolia logcheck-1.1.1]# l [root@magnolia logcheck-1.1.1]# ls [root@magnolia logcheck-1.1.1]# ls CHANGES INSTALL Makefile README.how.to.interpret src CREDITS LICENSE README README.keywords systems ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# c [root@magnolia logcheck-1.1.1]# c [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd . [root@magnolia logcheck-1.1.1]# cd . [root@magnolia logcheck-1.1.1]# cd .. [root@magnolia logcheck-1.1.1]# cd .. ]0;barrie@magnolia:/usr/local [root@magnolia local]# [root@magnolia local]# [root@magnolia local]# l [root@magnolia local]# l [root@magnolia local]# ls [root@magnolia local]# ls apache2 etc lib mysql share bin games libexec mysql-max-4.0.3-beta-pc-linux-gnu-i686 src CorporateTime httpd-2.0.43 logcheck-1.1.1 php-4.2.3 doc include logsentry-1.1.1.tar sbin ]0;barrie@magnolia:/usr/local [root@magnolia local]# [root@magnolia local]# [root@magnolia local]# c [root@magnolia local]# c [root@magnolia local]# cd [root@magnolia local]# cd [root@magnolia local]# cd [root@magnolia local]# cd [root@magnolia local]# cd b [root@magnolia local]# cd b [root@magnolia local]# cd bi [root@magnolia local]# cd bi [root@magnolia local]# cd bin [root@magnolia local]# cd bin ]0;barrie@magnolia:/usr/local/bin [root@magnolia bin]# [root@magnolia bin]# [root@magnolia bin]# l [root@magnolia bin]# l [root@magnolia bin]# ls [root@magnolia bin]# ls cisco_cert_mgr ipseclog pear php-config phpize vpnclient cvpnd logtail pearize phpextdist phptar ]0;barrie@magnolia:/usr/local/bin [root@magnolia bin]# [root@magnolia bin]# [root@magnolia bin]# l [root@magnolia bin]# l [root@magnolia bin]# ll [root@magnolia bin]# ll total 2760 -rwxr-xr-x 1 root root 1070248 Nov 17 19:40 cisco_cert_mgr -rws--x--x 1 root root 1375024 Nov 17 19:40 cvpnd -rwxr-xr-x 1 root root 121280 Nov 17 19:40 ipseclog -rwx------ 1 root root 15154 Nov 24 21:46 logtail -rwxr-xr-x 1 root root 5957 Oct 28 17:10 pear -rwxr-xr-x 1 root root 4326 Oct 28 17:10 pearize -rwxr-xr-x 1 root root 524 Oct 28 17:10 php-config -rwxr-xr-x 1 root root 593 Oct 28 17:10 phpextdist -rwxr-xr-x 1 root root 700 Oct 28 17:10 phpize -rwxr-xr-x 1 root root 5088 Oct 28 17:10 phptar -rwx--x--x 1 root root 184144 Nov 17 19:40 vpnclient ]0;barrie@magnolia:/usr/local/bin [root@magnolia bin]# [root@magnolia bin]# [root@magnolia bin]# l [root@magnolia bin]# l [root@magnolia bin]# ll [root@magnolia bin]# ll [root@magnolia bin]# l [root@magnolia bin]# l [root@magnolia bin]# ls [root@magnolia bin]# ls [root@magnolia bin]# ls [root@magnolia bin]# ls [root@magnolia bin]# ls - [root@magnolia bin]# ls - [root@magnolia bin]# ls -l [root@magnolia bin]# ls -l [root@magnolia bin]# ls -lt [root@magnolia bin]# ls -lt total 2760 -rwx------ 1 root root 15154 Nov 24 21:46 logtail -rwxr-xr-x 1 root root 1070248 Nov 17 19:40 cisco_cert_mgr -rws--x--x 1 root root 1375024 Nov 17 19:40 cvpnd -rwxr-xr-x 1 root root 121280 Nov 17 19:40 ipseclog -rwx--x--x 1 root root 184144 Nov 17 19:40 vpnclient -rwxr-xr-x 1 root root 5957 Oct 28 17:10 pear -rwxr-xr-x 1 root root 4326 Oct 28 17:10 pearize -rwxr-xr-x 1 root root 524 Oct 28 17:10 php-config -rwxr-xr-x 1 root root 593 Oct 28 17:10 phpextdist -rwxr-xr-x 1 root root 700 Oct 28 17:10 phpize -rwxr-xr-x 1 root root 5088 Oct 28 17:10 phptar ]0;barrie@magnolia:/usr/local/bin [root@magnolia bin]# [root@magnolia bin]# [root@magnolia bin]# c [root@magnolia bin]# c [root@magnolia bin]# cd [root@magnolia bin]# cd [root@magnolia bin]# cd [root@magnolia bin]# cd [root@magnolia bin]# cd . [root@magnolia bin]# cd . [root@magnolia bin]# cd .. [root@magnolia bin]# cd .. [root@magnolia bin]# cd ../ [root@magnolia bin]# cd ../ [root@magnolia bin]# cd ../e [root@magnolia bin]# cd ../e [root@magnolia bin]# cd ../et [root@magnolia bin]# cd ../et [root@magnolia bin]# cd ../etc [root@magnolia bin]# cd ../etc [root@magnolia bin]# cd ../etc/ [root@magnolia bin]# cd ../etc/ ]0;barrie@magnolia:/usr/local/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# l [root@magnolia etc]# l [root@magnolia etc]# ls [root@magnolia etc]# ls logcheck.hacking logcheck.sh logcheck.violations.ignore logcheck.ignore logcheck.violations tmp ]0;barrie@magnolia:/usr/local/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# c [root@magnolia etc]# c [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd t [root@magnolia etc]# cd t [root@magnolia etc]# cd tm [root@magnolia etc]# cd tm [root@magnolia etc]# cd tmp [root@magnolia etc]# cd tmp ]0;barrie@magnolia:/usr/local/etc/tmp [root@magnolia tmp]# [root@magnolia tmp]# [root@magnolia tmp]# l [root@magnolia tmp]# l [root@magnolia tmp]# ls [root@magnolia tmp]# ls ]0;barrie@magnolia:/usr/local/etc/tmp [root@magnolia tmp]# [root@magnolia tmp]# [root@magnolia tmp]# c [root@magnolia tmp]# c [root@magnolia tmp]# cd [root@magnolia tmp]# cd [root@magnolia tmp]# cd [root@magnolia tmp]# cd [root@magnolia tmp]# cd . [root@magnolia tmp]# cd . [root@magnolia tmp]# cd .. [root@magnolia tmp]# cd .. ]0;barrie@magnolia:/usr/local/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# m [root@magnolia etc]# m [root@magnolia etc]# mo [root@magnolia etc]# mo [root@magnolia etc]# mor [root@magnolia etc]# mor [root@magnolia etc]# more [root@magnolia etc]# more [root@magnolia etc]# more [root@magnolia etc]# more [root@magnolia etc]# more l [root@magnolia etc]# more l [root@magnolia etc]# more lo [root@magnolia etc]# more lo [root@magnolia etc]# more log [root@magnolia etc]# more log [root@magnolia etc]# more logc [root@magnolia etc]# more logc [root@magnolia etc]# more logch [root@magnolia etc]# more logch [root@magnolia etc]# more logche [root@magnolia etc]# more logche [root@magnolia etc]# more logchec [root@magnolia etc]# more logchec [root@magnolia etc]# more logcheck [root@magnolia etc]# more logcheck [root@magnolia etc]# more logcheck. [root@magnolia etc]# more logcheck. [root@magnolia etc]# more logcheck.v [root@magnolia etc]# more logcheck.v [root@magnolia etc]# more logcheck.vi [root@magnolia etc]# more logcheck.vi [root@magnolia etc]# more logcheck.vio [root@magnolia etc]# more logcheck.vio [root@magnolia etc]# more logcheck.viol [root@magnolia etc]# more logcheck.viol [root@magnolia etc]# more logcheck.violo [root@magnolia etc]# more logcheck.violo [root@magnolia etc]# more logcheck.violoa [root@magnolia etc]# more logcheck.violoa [root@magnolia etc]# more logcheck.violoat [root@magnolia etc]# more logcheck.violoat [root@magnolia etc]# more logcheck.violoati [root@magnolia etc]# more logcheck.violoati [root@magnolia etc]# more logcheck.violoatio [root@magnolia etc]# more logcheck.violoatio [root@magnolia etc]# more logcheck.violoation [root@magnolia etc]# more logcheck.violoation [root@magnolia etc]# more logcheck.violoatio [root@magnolia etc]# more logcheck.violoatio [root@magnolia etc]# more logcheck.violoati [root@magnolia etc]# more logcheck.violoati [root@magnolia etc]# more logcheck.violoat [root@magnolia etc]# more logcheck.violoat [root@magnolia etc]# more logcheck.violoa [root@magnolia etc]# more logcheck.violoa [root@magnolia etc]# more logcheck.violo [root@magnolia etc]# more logcheck.violo [root@magnolia etc]# more logcheck.viol [root@magnolia etc]# more logcheck.viol [root@magnolia etc]# more logcheck.viola [root@magnolia etc]# more logcheck.viola [root@magnolia etc]# more logcheck.violat [root@magnolia etc]# more logcheck.violat [root@magnolia etc]# more logcheck.violati [root@magnolia etc]# more logcheck.violati [root@magnolia etc]# more logcheck.violatio [root@magnolia etc]# more logcheck.violatio [root@magnolia etc]# more logcheck.violation [root@magnolia etc]# more logcheck.violation [root@magnolia etc]# more logcheck.violations [root@magnolia etc]# more logcheck.violations != -ERR Password ATTACK BAD CWD etc DEBUG EXPN FAILURE ILLEGAL LOGIN FAILURE LOGIN REFUSED PERMITTED REFUSED RETR group RETR passwd RETR pwd.db ROOT LOGIN SITE EXEC VRFY "WIZ" admin alias database debug denied deny deny host --More--(55%) expn failed illegal kernel: Oversized packet received from nested permitted reject rexec rshd securityalert setsender shutdown smrsh su root su: sucked unapproved vrfy attackalert ]0;barrie@magnolia:/usr/local/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# c [root@magnolia etc]# c [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd / [root@magnolia etc]# cd / [root@magnolia etc]# cd /t [root@magnolia etc]# cd /t [root@magnolia etc]# cd / [root@magnolia etc]# cd / [root@magnolia etc]# cd /e [root@magnolia etc]# cd /e [root@magnolia etc]# cd /et [root@magnolia etc]# cd /et [root@magnolia etc]# cd /etc [root@magnolia etc]# cd /etc ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# v [root@magnolia etc]# v [root@magnolia etc]# vi [root@magnolia etc]# vi [root@magnolia etc]# vi [root@magnolia etc]# vi [root@magnolia etc]# vi c [root@magnolia etc]# vi c [root@magnolia etc]# vi cr [root@magnolia etc]# vi cr [root@magnolia etc]# vi cro [root@magnolia etc]# vi cro [root@magnolia etc]# vi cron [root@magnolia etc]# vi cron [root@magnolia etc]# vi cront [root@magnolia etc]# vi cront [root@magnolia etc]# vi cronta [root@magnolia etc]# vi cronta [root@magnolia etc]# vi crontab [root@magnolia etc]# vi crontab [root@magnolia etc]#  [root@magnolia etc]# [root@magnolia etc]# c [root@magnolia etc]# c [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd / [root@magnolia etc]# cd / [root@magnolia etc]# cd /u [root@magnolia etc]# cd /u [root@magnolia etc]# cd /us [root@magnolia etc]# cd /us [root@magnolia etc]# cd /usr [root@magnolia etc]# cd /usr [root@magnolia etc]# cd /usr/ [root@magnolia etc]# cd /usr/ [root@magnolia etc]# cd /usr/b [root@magnolia etc]# cd /usr/b [root@magnolia etc]# cd /usr/ [root@magnolia etc]# cd /usr/ [root@magnolia etc]# cd /usr/l [root@magnolia etc]# cd /usr/l [root@magnolia etc]# cd /usr/lc [root@magnolia etc]# cd /usr/lc [root@magnolia etc]# cd /usr/l [root@magnolia etc]# cd /usr/l [root@magnolia etc]# cd /usr/lo [root@magnolia etc]# cd /usr/lo [root@magnolia etc]# cd /usr/loc [root@magnolia etc]# cd /usr/loc [root@magnolia etc]# cd /usr/loca [root@magnolia etc]# cd /usr/loca [root@magnolia etc]# cd /usr/local [root@magnolia etc]# cd /usr/local [root@magnolia etc]# cd /usr/local/ [root@magnolia etc]# cd /usr/local/ [root@magnolia etc]# cd /usr/local/b [root@magnolia etc]# cd /usr/local/b [root@magnolia etc]# cd /usr/local/bn [root@magnolia etc]# cd /usr/local/bn [root@magnolia etc]# cd /usr/local/b [root@magnolia etc]# cd /usr/local/b [root@magnolia etc]# cd /usr/local/bi [root@magnolia etc]# cd /usr/local/bi [root@magnolia etc]# cd /usr/local/bin [root@magnolia etc]# cd /usr/local/bin ]0;barrie@magnolia:/usr/local/bin [root@magnolia bin]# [root@magnolia bin]# [root@magnolia bin]# l [root@magnolia bin]# l [root@magnolia bin]# ls [root@magnolia bin]# ls cisco_cert_mgr ipseclog pear php-config phpize vpnclient cvpnd logtail pearize phpextdist phptar ]0;barrie@magnolia:/usr/local/bin [root@magnolia bin]# [root@magnolia bin]# [root@magnolia bin]# c [root@magnolia bin]# c [root@magnolia bin]# cd [root@magnolia bin]# cd [root@magnolia bin]# cd [root@magnolia bin]# cd [root@magnolia bin]# cd . [root@magnolia bin]# cd . [root@magnolia bin]# cd .. [root@magnolia bin]# cd .. [root@magnolia bin]# cd ../ [root@magnolia bin]# cd ../ ]0;barrie@magnolia:/usr/local [root@magnolia local]# [root@magnolia local]# [root@magnolia local]# c [root@magnolia local]# c [root@magnolia local]#  [root@magnolia local]# [root@magnolia local]# l [root@magnolia local]# l [root@magnolia local]# ls [root@magnolia local]# ls apache2 etc lib mysql share bin games libexec mysql-max-4.0.3-beta-pc-linux-gnu-i686 src CorporateTime httpd-2.0.43 logcheck-1.1.1 php-4.2.3 doc include logsentry-1.1.1.tar sbin ]0;barrie@magnolia:/usr/local [root@magnolia local]# [root@magnolia local]# [root@magnolia local]# c [root@magnolia local]# c [root@magnolia local]# cd [root@magnolia local]# cd [root@magnolia local]# cd [root@magnolia local]# cd [root@magnolia local]# cd e [root@magnolia local]# cd e [root@magnolia local]# cd et [root@magnolia local]# cd et [root@magnolia local]# cd etc [root@magnolia local]# cd etc ]0;barrie@magnolia:/usr/local/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# l [root@magnolia etc]# l [root@magnolia etc]# ls [root@magnolia etc]# ls logcheck.hacking logcheck.sh logcheck.violations.ignore logcheck.ignore logcheck.violations tmp ]0;barrie@magnolia:/usr/local/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# p [root@magnolia etc]# p [root@magnolia etc]# pw [root@magnolia etc]# pw [root@magnolia etc]# pwd [root@magnolia etc]# pwd /usr/local/etc ]0;barrie@magnolia:/usr/local/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# c [root@magnolia etc]# c [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd / [root@magnolia etc]# cd / [root@magnolia etc]# cd /e [root@magnolia etc]# cd /e [root@magnolia etc]# cd /et [root@magnolia etc]# cd /et [root@magnolia etc]# cd /etc [root@magnolia etc]# cd /etc ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# v [root@magnolia etc]# v [root@magnolia etc]# vi [root@magnolia etc]# vi [root@magnolia etc]# vi [root@magnolia etc]# vi [root@magnolia etc]# vi c [root@magnolia etc]# vi c [root@magnolia etc]# vi cr [root@magnolia etc]# vi cr [root@magnolia etc]# vi cro [root@magnolia etc]# vi cro [root@magnolia etc]# vi cron [root@magnolia etc]# vi cron [root@magnolia etc]# vi cront [root@magnolia etc]# vi cront [root@magnolia etc]# vi cronta [root@magnolia etc]# vi cronta [root@magnolia etc]# vi crontab [root@magnolia etc]# vi crontab [root@magnolia etc]# vi crontab. [root@magnolia etc]# vi crontab. [root@magnolia etc]# vi crontab [root@magnolia etc]# vi crontab [?1048h[?1047h[?1h=[?25h[?25h[?25l"crontab" 10L, 255CSHELL=/bin/bash PATH=/sbin:/bin:/usr/sbin:/usr/bin MAILTO=root HOME=/ # run-parts 01 * * * * root run-parts /etc/cron.hourly 02 4 * * * root run-parts /etc/cron.daily 22 4 * * 0 root run-parts /etc/cron.weekly 42 4 1 * * root run-parts /etc/cron.monthly ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ 1,1All[?25h[?25l:[?25hw crontab.lasst[?25l[?25h[?25l[?25ht021123[?25l[?25h4 [?25l"crontab.last021124" [New] 10L, 255C written1,1All1,1All[?25h[?25l[?25h[?25l:[?25hw crontab [?25l"crontab" 10L, 255C written1,1All1,1All[?25h[?25l2[?25h[?25l3[?25h[?25l4[?25h[?25l5,0-1[?25h[?25l6,1 [?25h[?25l7[?25h[?25l8[?25h[?25l9[?25h[?25l10,1[?25h[?25l-- INSERT --10,1All[?25h[?25l2[?25h[?25l3[?25h[?25l4[?25h[?25l5[?25h[?25l6[?25h[?25l7[?25h[?25l8[?25h[?25l9[?25h[?25l10[?25h[?25l1[?25h[?25l2[?25h[?25l3[?25h[?25l4[?25h[?25l5[?25h[?25l6[?25h[?25l7[?25h[?25l8[?25h[?25l9[?25h[?25l20[?25h[?25l1[?25h[?25l2[?25h[?25l3[?25h[?25l4[?25h[?25l5[?25h[?25l6[?25h[?25l7[?25h[?25l8[?25h[?25l9[?25h[?25l30[?25h[?25l1[?25h[?25l2[?25h[?25l3[?25h[?25l4[?25h[?25l5[?25h[?25l6[?25h[?25l7[?25h[?25l8[?25h[?25l9[?25h[?25l40[?25h[?25l1[?25h[?25l2[?25h[?25l3[?25h[?25l4[?25h[?25l1,1 [?25h[?25l2[?25h[?25l#2[?25h[?25l3[?25h[?25lr4[?25h[?25lu5[?25h[?25ln6[?25h[?25l7[?25h[?25ll8[?25h[?25lo9[?25h[?25lg10[?25h[?25lc1[?25h[?25lh2[?25h[?25le3[?25h[?25lc4[?25h[?25lk5[?25h[?25l6[?25h[?25lh7[?25h[?25lo8[?25h[?25lu9[?25h[?25lr20[?25h[?25ll1[?25h[?25ly2[?25h[?25l3,1 [?25h[?25l02[?25h[?25l03[?25h[?25l4[?25h[?25l*5[?25h[?25l6[?25h[?25l*7[?25h[?25l8[?25h[?25l*9[?25h[?25l10[?25h[?25l*1[?25h[?25l2[?25h[?25lr3[?25h[?25lo4[?25h[?25lo5[?25h[?25lt6[?25h[?25l7[?25h[?25l/8[?25h[?25lb9[?25h[?25li20[?25h[?25ln1[?25h[?25l/2[?25h[?25ls3[?25h[?25lh4[?25h[?25l5[?25h[?25l6[?25h[?25l7[?25h[?25l/8[?25h[?25lu9[?25h[?25ls30[?25h[?25lr1[?25h[?25l/2[?25h[?25ll3[?25h[?25lo4[?25h[?25lc5[?25h[?25la6[?25h[?25ll7[?25h[?25l/8[?25h[?25le9[?25h[?25lt40[?25h[?25lc1[?25h[?25l/2[?25h[?25ll3[?25h[?25lo4[?25h[?25lg5[?25h[?25lc6[?25h[?25lh7[?25h[?25le8[?25h[?25lc9[?25h[?25lk50[?25h[?25l.1[?25h[?25ls2[?25h[?25lh3[?25h[?25l13,52All[?25h[?25l:[?25hwq [?25l"crontab" 13L, 331C written [?1l>[?25h[?1047l[?1048l]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# m [root@magnolia etc]# m [root@magnolia etc]# ma [root@magnolia etc]# ma [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man H [root@magnolia etc]# man H [root@magnolia etc]# man HP [root@magnolia etc]# man HP [root@magnolia etc]# man H [root@magnolia etc]# man H [root@magnolia etc]# man HU [root@magnolia etc]# man HU [root@magnolia etc]# man HUP [root@magnolia etc]# man HUP No manual entry for HUP ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# p [root@magnolia etc]# p [root@magnolia etc]# ps [root@magnolia etc]# ps [root@magnolia etc]# ps [root@magnolia etc]# ps [root@magnolia etc]# ps - [root@magnolia etc]# ps - [root@magnolia etc]# ps -e [root@magnolia etc]# ps -e [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | g [root@magnolia etc]# ps -ef | g [root@magnolia etc]# ps -ef | gr [root@magnolia etc]# ps -ef | gr [root@magnolia etc]# ps -ef | gre [root@magnolia etc]# ps -ef | gre [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep c [root@magnolia etc]# ps -ef | grep c [root@magnolia etc]# ps -ef | grep cr [root@magnolia etc]# ps -ef | grep cr [root@magnolia etc]# ps -ef | grep cro [root@magnolia etc]# ps -ef | grep cro [root@magnolia etc]# ps -ef | grep cron [root@magnolia etc]# ps -ef | grep cron [root@magnolia etc]# ps -ef | grep crond [root@magnolia etc]# ps -ef | grep crond root 907 1 0 12:06 ? 00:00:00 crond ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# H [root@magnolia etc]# H [root@magnolia etc]# HU [root@magnolia etc]# HU [root@magnolia etc]# HUP [root@magnolia etc]# HUP [root@magnolia etc]# HUP [root@magnolia etc]# HUP [root@magnolia etc]# HUP c [root@magnolia etc]# HUP c [root@magnolia etc]# HUP cr [root@magnolia etc]# HUP cr [root@magnolia etc]# HUP cro [root@magnolia etc]# HUP cro [root@magnolia etc]# HUP cron [root@magnolia etc]# HUP cron [root@magnolia etc]# HUP crond [root@magnolia etc]# HUP crond [root@magnolia etc]# HUP cron [root@magnolia etc]# HUP cron [root@magnolia etc]# HUP cro [root@magnolia etc]# HUP cro [root@magnolia etc]# HUP cr [root@magnolia etc]# HUP cr [root@magnolia etc]# HUP c [root@magnolia etc]# HUP c [root@magnolia etc]# HUP  [root@magnolia etc]# HUP [root@magnolia etc]# HUP [root@magnolia etc]# HUP [root@magnolia etc]# HU [root@magnolia etc]# HU [root@magnolia etc]# H [root@magnolia etc]# H [root@magnolia etc]#  [root@magnolia etc]# [root@magnolia etc]# w [root@magnolia etc]# w [root@magnolia etc]# wh [root@magnolia etc]# wh [root@magnolia etc]# whi [root@magnolia etc]# whi [root@magnolia etc]# whic [root@magnolia etc]# whic [root@magnolia etc]# which [root@magnolia etc]# which [root@magnolia etc]# which [root@magnolia etc]# which [root@magnolia etc]# which c [root@magnolia etc]# which c [root@magnolia etc]# which cr [root@magnolia etc]# which cr [root@magnolia etc]# which cro [root@magnolia etc]# which cro [root@magnolia etc]# which cron [root@magnolia etc]# which cron [root@magnolia etc]# which crond [root@magnolia etc]# which crond /usr/sbin/crond ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# H [root@magnolia etc]# H [root@magnolia etc]# HU [root@magnolia etc]# HU [root@magnolia etc]# HUP [root@magnolia etc]# HUP [root@magnolia etc]# HUP [root@magnolia etc]# HUP [root@magnolia etc]# HUP i [root@magnolia etc]# HUP i [root@magnolia etc]# HUP in [root@magnolia etc]# HUP in [root@magnolia etc]# HUP inf [root@magnolia etc]# HUP inf [root@magnolia etc]# HUP info [root@magnolia etc]# HUP info bash: HUP: command not found ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# H [root@magnolia etc]# H [root@magnolia etc]# HU [root@magnolia etc]# HU [root@magnolia etc]# HUP [root@magnolia etc]# HUP [root@magnolia etc]# HU [root@magnolia etc]# HU [root@magnolia etc]# H [root@magnolia etc]# H [root@magnolia etc]#  [root@magnolia etc]# [root@magnolia etc]# m [root@magnolia etc]# m [root@magnolia etc]# ma [root@magnolia etc]# ma [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man u [root@magnolia etc]# man u [root@magnolia etc]# man up [root@magnolia etc]# man up [root@magnolia etc]# man u [root@magnolia etc]# man u [root@magnolia etc]# man  [root@magnolia etc]# man [root@magnolia etc]# man h [root@magnolia etc]# man h [root@magnolia etc]# man hu [root@magnolia etc]# man hu [root@magnolia etc]# man hup [root@magnolia etc]# man hup No manual entry for hup ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# k [root@magnolia etc]# k [root@magnolia etc]# ki [root@magnolia etc]# ki [root@magnolia etc]# kil [root@magnolia etc]# kil [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill - [root@magnolia etc]# kill - [root@magnolia etc]# kill -H [root@magnolia etc]# kill -H [root@magnolia etc]# kill -HU [root@magnolia etc]# kill -HU [root@magnolia etc]# kill -HUP [root@magnolia etc]# kill -HUP [root@magnolia etc]# kill -HUP [root@magnolia etc]# kill -HUP [root@magnolia etc]# kill -HUP c [root@magnolia etc]# kill -HUP c [root@magnolia etc]# kill -HUP cr [root@magnolia etc]# kill -HUP cr [root@magnolia etc]# kill -HUP cro [root@magnolia etc]# kill -HUP cro [root@magnolia etc]# kill -HUP cron [root@magnolia etc]# kill -HUP cron [root@magnolia etc]# kill -HUP crond [root@magnolia etc]# kill -HUP crond bash: kill: crond: no such pid ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# k [root@magnolia etc]# k [root@magnolia etc]# ki [root@magnolia etc]# ki [root@magnolia etc]# kil [root@magnolia etc]# kil [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill - [root@magnolia etc]# kill - [root@magnolia etc]# kill -H [root@magnolia etc]# kill -H [root@magnolia etc]# kill -HU [root@magnolia etc]# kill -HU [root@magnolia etc]# kill -HUP [root@magnolia etc]# kill -HUP [root@magnolia etc]# kill -HUP [root@magnolia etc]# kill -HUP [root@magnolia etc]# kill -HUP 9 [root@magnolia etc]# kill -HUP 9 [root@magnolia etc]# kill -HUP 90 [root@magnolia etc]# kill -HUP 90 [root@magnolia etc]# kill -HUP 907 [root@magnolia etc]# kill -HUP 907 ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# p [root@magnolia etc]# p [root@magnolia etc]# ps [root@magnolia etc]# ps [root@magnolia etc]# ps [root@magnolia etc]# ps [root@magnolia etc]# ps - [root@magnolia etc]# ps - [root@magnolia etc]# ps -e [root@magnolia etc]# ps -e [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | g [root@magnolia etc]# ps -ef | g [root@magnolia etc]# ps -ef | gr [root@magnolia etc]# ps -ef | gr [root@magnolia etc]# ps -ef | gre [root@magnolia etc]# ps -ef | gre [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep c [root@magnolia etc]# ps -ef | grep c [root@magnolia etc]# ps -ef | grep cr [root@magnolia etc]# ps -ef | grep cr [root@magnolia etc]# ps -ef | grep cro [root@magnolia etc]# ps -ef | grep cro [root@magnolia etc]# ps -ef | grep cron [root@magnolia etc]# ps -ef | grep cron [root@magnolia etc]# ps -ef | grep crond [root@magnolia etc]# ps -ef | grep crond root 907 1 0 12:06 ? 00:00:00 crond root 7416 7126 0 21:58 pts/3 00:00:00 grep crond ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# m [root@magnolia etc]# m [root@magnolia etc]# ma [root@magnolia etc]# ma [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man k [root@magnolia etc]# man k [root@magnolia etc]# man ki [root@magnolia etc]# man ki [root@magnolia etc]# man kil [root@magnolia etc]# man kil [root@magnolia etc]# man kill [root@magnolia etc]# man kill [?1048h[?1047h[?1h=KILL(1) Linux Programmer’s Manual KILL(1) NAME kill − terminate a process SYNOPSIS kill [ −s signal | −p ] [ −a ] [ −− ] pid ... kill â€l [ signal ] DESCRIPTION The command kill sends the specified signal to the specified process or process group. If no signal is specified, the TERM signal is sent. The TERM signal will kill processes which do not catch this signal. For other processes, it may be necessary to use the KILL (9) signal, since this signal cannot be caught. Most modern shells have a builtin kill function, with a usage rather similar to that of the command described here. The ‘â€a’ and ‘â€p’ options, and the possibility to specify pids by command name is a local extension. OPTIONS pid... Specify the list of processes that kill should signal. Each pid can be one of five things: n where n is larger than 0. The process with pid n will be signaled. : 0 All processes in the current process group are signaled. â€1 All processes with pid larger than 1 will be signaled. â€n where n is larger than 1. All processes in process group n are signaled. When an argument of the form ‘â€n’ is given, and it is meant to denote a process group, either the signal must be specified first, or the argument must be preceded by a ‘â€â€â€™ option, otherwise it will be taken as the signal to send. commandname All processes invoked using that name will be signaled. −s signal Specify the signal to send. The signal may be given as a signal name or number. −l Print a list of signal names. These are found in /usr/include/linux/signal.h −a Do not restrict the commandnameâ€toâ€pid conversion to processes with the same uid as the present process. −p Specify that kill should only print the process id (pid) of the named processes, and not send any signals. : SEE ALSO bash(1), tcsh(1), kill(2), sigvec(2), signal(7) AUTHOR Taken from BSD 4.4. The ability to translate process names to process ids was added by Salvatore Valente . Linux Utilities 14 October 1994 KILL(1) (END) (END) [?1l>[?1047l[?1048l]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# m [root@magnolia etc]# m [root@magnolia etc]# ma [root@magnolia etc]# ma [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man k [root@magnolia etc]# man k [root@magnolia etc]# man ki [root@magnolia etc]# man ki [root@magnolia etc]# man kil [root@magnolia etc]# man kil [root@magnolia etc]# man kill [root@magnolia etc]# man kill [root@magnolia etc]# man kill [root@magnolia etc]# man kill [root@magnolia etc]# man kill ( [root@magnolia etc]# man kill ( [root@magnolia etc]# man kill (@ [root@magnolia etc]# man kill (@ [root@magnolia etc]# man kill (@) [root@magnolia etc]# man kill (@) [root@magnolia etc]# man kill (@ [root@magnolia etc]# man kill (@ [root@magnolia etc]# man kill ( [root@magnolia etc]# man kill ( [root@magnolia etc]# man kill  [root@magnolia etc]# man kill [root@magnolia etc]# man kill [root@magnolia etc]# man kill [root@magnolia etc]# man kill( [root@magnolia etc]# man kill( [root@magnolia etc]# man kill(2 [root@magnolia etc]# man kill(2 [root@magnolia etc]# man kill(2) [root@magnolia etc]# man kill(2) bash: syntax error near unexpected token `(' ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# k [root@magnolia etc]# k [root@magnolia etc]# ki [root@magnolia etc]# ki [root@magnolia etc]# kil [root@magnolia etc]# kil [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill - [root@magnolia etc]# kill - [root@magnolia etc]# kill -H [root@magnolia etc]# kill -H [root@magnolia etc]# kill -HU [root@magnolia etc]# kill -HU [root@magnolia etc]# kill -HUP [root@magnolia etc]# kill -HUP [root@magnolia etc]# kill -HUP [root@magnolia etc]# kill -HUP [root@magnolia etc]# kill -HUP 9 [root@magnolia etc]# kill -HUP 9 [root@magnolia etc]# kill -HUP 90 [root@magnolia etc]# kill -HUP 90 [root@magnolia etc]# kill -HUP 907 [root@magnolia etc]# kill -HUP 907 ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# p [root@magnolia etc]# p [root@magnolia etc]# pw [root@magnolia etc]# pw [root@magnolia etc]# p [root@magnolia etc]# p [root@magnolia etc]# ps [root@magnolia etc]# ps [root@magnolia etc]# ps [root@magnolia etc]# ps [root@magnolia etc]# ps = [root@magnolia etc]# ps = [root@magnolia etc]# ps  [root@magnolia etc]# ps [root@magnolia etc]# ps - [root@magnolia etc]# ps - [root@magnolia etc]# ps -e [root@magnolia etc]# ps -e [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | g [root@magnolia etc]# ps -ef | g [root@magnolia etc]# ps -ef | gr [root@magnolia etc]# ps -ef | gr [root@magnolia etc]# ps -ef | gre [root@magnolia etc]# ps -ef | gre [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep h [root@magnolia etc]# ps -ef | grep h [root@magnolia etc]# ps -ef | grep ht [root@magnolia etc]# ps -ef | grep ht [root@magnolia etc]# ps -ef | grep htt [root@magnolia etc]# ps -ef | grep htt [root@magnolia etc]# ps -ef | grep http [root@magnolia etc]# ps -ef | grep http [root@magnolia etc]# ps -ef | grep httpd [root@magnolia etc]# ps -ef | grep httpd [root@magnolia etc]# ps -ef | grep http [root@magnolia etc]# ps -ef | grep http [root@magnolia etc]# ps -ef | grep htt [root@magnolia etc]# ps -ef | grep htt [root@magnolia etc]# ps -ef | grep ht [root@magnolia etc]# ps -ef | grep ht [root@magnolia etc]# ps -ef | grep h [root@magnolia etc]# ps -ef | grep h [root@magnolia etc]# ps -ef | grep  [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep c [root@magnolia etc]# ps -ef | grep c [root@magnolia etc]# ps -ef | grep cr [root@magnolia etc]# ps -ef | grep cr [root@magnolia etc]# ps -ef | grep cro [root@magnolia etc]# ps -ef | grep cro [root@magnolia etc]# ps -ef | grep cron [root@magnolia etc]# ps -ef | grep cron [root@magnolia etc]# ps -ef | grep crond [root@magnolia etc]# ps -ef | grep crond root 907 1 0 12:06 ? 00:00:00 crond ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# k [root@magnolia etc]# k [root@magnolia etc]# ki [root@magnolia etc]# ki [root@magnolia etc]# kil [root@magnolia etc]# kil [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill - [root@magnolia etc]# kill - [root@magnolia etc]# kill -l [root@magnolia etc]# kill -l [root@magnolia etc]#  [root@magnolia etc]# [root@magnolia etc]# m [root@magnolia etc]# m [root@magnolia etc]# ma [root@magnolia etc]# ma [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man [root@magnolia etc]# man k [root@magnolia etc]# man k [root@magnolia etc]# man ki [root@magnolia etc]# man ki [root@magnolia etc]# man kil [root@magnolia etc]# man kil [root@magnolia etc]# man kill [root@magnolia etc]# man kill [?1048h[?1047h[?1h=KILL(1) Linux Programmer’s Manual KILL(1) NAME kill − terminate a process SYNOPSIS kill [ −s signal | −p ] [ −a ] [ −− ] pid ... kill â€l [ signal ] DESCRIPTION The command kill sends the specified signal to the specified process or process group. If no signal is specified, the TERM signal is sent. The TERM signal will kill processes which do not catch this signal. For other processes, it may be necessary to use the KILL (9) signal, since this signal cannot be caught. Most modern shells have a builtin kill function, with a usage rather similar to that of the command described here. The ‘â€a’ and ‘â€p’ options, and the possibility to specify pids by command name is a local extension. OPTIONS pid... Specify the list of processes that kill should signal. Each pid can be one of five things: n where n is larger than 0. The process with pid n will be signaled. : 0 All processes in the current process group are signaled. â€1 All processes with pid larger than 1 will be signaled. â€n where n is larger than 1. All processes in process group n are signaled. When an argument of the form ‘â€n’ is given, and it is meant to denote a process group, either the signal must be specified first, or the argument must be preceded by a ‘â€â€â€™ option, otherwise it will be taken as the signal to send. commandname All processes invoked using that name will be signaled. −s signal Specify the signal to send. The signal may be given as a signal name or number. −l Print a list of signal names. These are found in /usr/include/linux/signal.h −a Do not restrict the commandnameâ€toâ€pid conversion to processes with the same uid as the present process. −p Specify that kill should only print the process id (pid) of the named processes, and not send any signals. : SEE ALSO bash(1), tcsh(1), kill(2), sigvec(2), signal(7) AUTHOR Taken from BSD 4.4. The ability to translate process names to process ids was added by Salvatore Valente . Linux Utilities 14 October 1994 KILL(1) (END) [?1l>[?1047l[?1048l]0;barrie@magnolia:/etcYou have new mail in /var/spool/mail/barrie [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# k [root@magnolia etc]# k [root@magnolia etc]# ki [root@magnolia etc]# ki [root@magnolia etc]# kil [root@magnolia etc]# kil [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill - [root@magnolia etc]# kill - [root@magnolia etc]# kill -l [root@magnolia etc]# kill -l [root@magnolia etc]# kill -l [root@magnolia etc]# kill -l [root@magnolia etc]# kill -l 9 [root@magnolia etc]# kill -l 9 [root@magnolia etc]# kill -l 90 [root@magnolia etc]# kill -l 90 [root@magnolia etc]# kill -l 907 [root@magnolia etc]# kill -l 907 bash: kill: 907: invalid signal specification ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# k [root@magnolia etc]# k [root@magnolia etc]# ki [root@magnolia etc]# ki [root@magnolia etc]# kil [root@magnolia etc]# kil [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill [root@magnolia etc]# kill - [root@magnolia etc]# kill - [root@magnolia etc]# kill -1 [root@magnolia etc]# kill -1 [root@magnolia etc]# kill -1 [root@magnolia etc]# kill -1 [root@magnolia etc]# kill -1 9 [root@magnolia etc]# kill -1 9 [root@magnolia etc]# kill -1 90 [root@magnolia etc]# kill -1 90 [root@magnolia etc]# kill -1 907 [root@magnolia etc]# kill -1 907 ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# p [root@magnolia etc]# p [root@magnolia etc]# ps [root@magnolia etc]# ps [root@magnolia etc]# ps [root@magnolia etc]# ps [root@magnolia etc]# ps - [root@magnolia etc]# ps - [root@magnolia etc]# ps -e [root@magnolia etc]# ps -e [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | g [root@magnolia etc]# ps -ef | g [root@magnolia etc]# ps -ef | gr [root@magnolia etc]# ps -ef | gr [root@magnolia etc]# ps -ef | gre [root@magnolia etc]# ps -ef | gre [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep c [root@magnolia etc]# ps -ef | grep c [root@magnolia etc]# ps -ef | grep cr [root@magnolia etc]# ps -ef | grep cr [root@magnolia etc]# ps -ef | grep cro [root@magnolia etc]# ps -ef | grep cro [root@magnolia etc]# ps -ef | grep cron [root@magnolia etc]# ps -ef | grep cron [root@magnolia etc]# ps -ef | grep crond [root@magnolia etc]# ps -ef | grep crond root 907 1 0 12:06 ? 00:00:00 crond root 7473 7126 0 22:02 pts/3 00:00:00 grep crond ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# / [root@magnolia etc]# / [root@magnolia etc]# /u [root@magnolia etc]# /u [root@magnolia etc]# /us [root@magnolia etc]# /us [root@magnolia etc]# /usr [root@magnolia etc]# /usr [root@magnolia etc]# /usr/ [root@magnolia etc]# /usr/ [root@magnolia etc]# /usr/l [root@magnolia etc]# /usr/l [root@magnolia etc]# /usr/lo [root@magnolia etc]# /usr/lo [root@magnolia etc]# /usr/loc [root@magnolia etc]# /usr/loc [root@magnolia etc]# /usr/loca [root@magnolia etc]# /usr/loca [root@magnolia etc]# /usr/local [root@magnolia etc]# /usr/local [root@magnolia etc]# /usr/local/ [root@magnolia etc]# /usr/local/ [root@magnolia etc]# /usr/local/e [root@magnolia etc]# /usr/local/e [root@magnolia etc]# /usr/local/et [root@magnolia etc]# /usr/local/et [root@magnolia etc]# /usr/local/etc [root@magnolia etc]# /usr/local/etc [root@magnolia etc]# /usr/local/etc/ [root@magnolia etc]# /usr/local/etc/ [root@magnolia etc]# /usr/local/etc/l [root@magnolia etc]# /usr/local/etc/l [root@magnolia etc]# /usr/local/etc/lo [root@magnolia etc]# /usr/local/etc/lo [root@magnolia etc]# /usr/local/etc/log [root@magnolia etc]# /usr/local/etc/log [root@magnolia etc]# /usr/local/etc/logc [root@magnolia etc]# /usr/local/etc/logc [root@magnolia etc]# /usr/local/etc/logch [root@magnolia etc]# /usr/local/etc/logch [root@magnolia etc]# /usr/local/etc/logche [root@magnolia etc]# /usr/local/etc/logche [root@magnolia etc]# /usr/local/etc/logchec [root@magnolia etc]# /usr/local/etc/logchec [root@magnolia etc]# /usr/local/etc/logcheck [root@magnolia etc]# /usr/local/etc/logcheck [root@magnolia etc]# /usr/local/etc/logcheck. [root@magnolia etc]# /usr/local/etc/logcheck. [root@magnolia etc]# /usr/local/etc/logcheck.s [root@magnolia etc]# /usr/local/etc/logcheck.s [root@magnolia etc]# /usr/local/etc/logcheck.sh [root@magnolia etc]# /usr/local/etc/logcheck.sh ]0;barrie@magnolia:/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# p [root@magnolia etc]# p [root@magnolia etc]# ps [root@magnolia etc]# ps [root@magnolia etc]# ps [root@magnolia etc]# ps [root@magnolia etc]# ps - [root@magnolia etc]# ps - [root@magnolia etc]# ps -e [root@magnolia etc]# ps -e [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | [root@magnolia etc]# ps -ef | g [root@magnolia etc]# ps -ef | g [root@magnolia etc]# ps -ef | gr [root@magnolia etc]# ps -ef | gr [root@magnolia etc]# ps -ef | gre [root@magnolia etc]# ps -ef | gre [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep [root@magnolia etc]# ps -ef | grep l [root@magnolia etc]# ps -ef | grep l [root@magnolia etc]# ps -ef | grep lo [root@magnolia etc]# ps -ef | grep lo [root@magnolia etc]# ps -ef | grep log [root@magnolia etc]# ps -ef | grep log [root@magnolia etc]# ps -ef | grep logc [root@magnolia etc]# ps -ef | grep logc [root@magnolia etc]# ps -ef | grep logch [root@magnolia etc]# ps -ef | grep logch [root@magnolia etc]# ps -ef | grep logche [root@magnolia etc]# ps -ef | grep logche [root@magnolia etc]# ps -ef | grep logchec [root@magnolia etc]# ps -ef | grep logchec [root@magnolia etc]# ps -ef | grep logcheck [root@magnolia etc]# ps -ef | grep logcheck barrie 7059 1188 0 15:24 pts/1 00:00:00 script logcheckinstall021123 barrie 7060 7059 0 15:24 pts/1 00:00:00 script logcheckinstall021123 root 7495 7126 0 22:03 pts/3 00:00:00 grep logcheck ]0;barrie@magnolia:/etcYou have new mail in /var/spool/mail/barrie [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# c [root@magnolia etc]# c [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd / [root@magnolia etc]# cd / [root@magnolia etc]# cd /v [root@magnolia etc]# cd /v [root@magnolia etc]# cd /va [root@magnolia etc]# cd /va [root@magnolia etc]# cd /var [root@magnolia etc]# cd /var [root@magnolia etc]# cd /var/ [root@magnolia etc]# cd /var/ [root@magnolia etc]# cd /var/s [root@magnolia etc]# cd /var/s [root@magnolia etc]# cd /var/sp [root@magnolia etc]# cd /var/sp [root@magnolia etc]# cd /var/spo [root@magnolia etc]# cd /var/spo [root@magnolia etc]# cd /var/spoo [root@magnolia etc]# cd /var/spoo [root@magnolia etc]# cd /var/spool [root@magnolia etc]# cd /var/spool [root@magnolia etc]# cd /var/spool/ [root@magnolia etc]# cd /var/spool/ [root@magnolia etc]# cd /var/spool/m [root@magnolia etc]# cd /var/spool/m [root@magnolia etc]# cd /var/spool/ma [root@magnolia etc]# cd /var/spool/ma [root@magnolia etc]# cd /var/spool/mai [root@magnolia etc]# cd /var/spool/mai [root@magnolia etc]# cd /var/spool/mail [root@magnolia etc]# cd /var/spool/mail [root@magnolia etc]# cd /var/spool/mail/ [root@magnolia etc]# cd /var/spool/mail/ [root@magnolia etc]# cd /var/spool/mail [root@magnolia etc]# cd /var/spool/mail ]0;barrie@magnolia:/var/spool/mail [root@magnolia mail]# [root@magnolia mail]# [root@magnolia mail]# m [root@magnolia mail]# m [root@magnolia mail]# mo [root@magnolia mail]# mo [root@magnolia mail]# mor [root@magnolia mail]# mor [root@magnolia mail]# more [root@magnolia mail]# more [root@magnolia mail]# more [root@magnolia mail]# more [root@magnolia mail]# more b [root@magnolia mail]# more b [root@magnolia mail]# more ba [root@magnolia mail]# more ba [root@magnolia mail]# more bar [root@magnolia mail]# more bar [root@magnolia mail]# more barr [root@magnolia mail]# more barr [root@magnolia mail]# more barri [root@magnolia mail]# more barri [root@magnolia mail]# more barrie [root@magnolia mail]# more barrie From root@magnolia.brighton.org Sun Oct 20 13:27:22 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9KHRMh8001433 for ; Sun, 20 Oct 2002 13:27:22 -0400 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9KHRMwi001430 for root; Sun, 20 Oct 2002 13:27:22 -0400 Date: Sun, 20 Oct 2002 13:27:22 -0400 From: root Message-Id: <200210201727.g9KHRMwi001430@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 1 Time(s) **Unmatched Entries** sudo: barrie : TTY=pts/2 ; PWD=/home ; USER=root ; COMMAND=/bin/mkdir htdocs --More--(6%) sudo: barrie : TTY=pts/0 ; PWD=/etc ; USER=root ; COMMAND=/usr/bin/newaliases sudo: barrie : TTY=pts/0 ; PWD=/etc ; USER=root ; COMMAND=/bin/vi aliases sudo: barrie : TTY=pts/0 ; PWD=/etc ; USER=root ; COMMAND=/usr/bin/newaliases sudo: barrie : TTY=pts/0 ; PWD=/home/htdocs ; USER=root ; COMMAND=/usr/bin/pico index.html sudo: barrie : TTY=pts/0 ; PWD=/home ; USER=root ; COMMAND=/usr/bin/locate apachect1 sudo: barrie : TTY=pts/0 ; PWD=/home ; USER=root ; COMMAND=/usr/bin/which apache sudo: barrie : TTY=pts/0 ; PWD=/usr ; USER=root ; COMMAND=/bin/ls ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Mon Oct 21 15:40:29 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9LJeTdg001474 for ; Mon, 21 Oct 2002 15:40:29 -0400 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9LJeT1u001471 for root; Mon, 21 Oct 2002 15:40:29 -0400 Date: Mon, 21 Oct 2002 15:40:29 -0400 From: root Message-Id: <200210211940.g9LJeT1u001471@magnolia.brighton.org> --More--(15%) To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 2 Time(s) **Unmatched Entries** sudo: barrie : TTY=pts/3 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND=/bin/gunzip mysql-4.0.4- beta-pc-linux-gnu-i6i6.tar.gz sudo: barrie : TTY=pts/3 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND=/bin/cp mysql-4.0.4-beta -pc-linux-gnu-i686.tar.gz /usr/local sudo: barrie : TTY=pts/3 ; PWD=/home/barrie ; USER=root ; COMMAND=/bin/tar xzf mysql-4.0.4-bet a-pc-linux-gnu-i686.tar.gz sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/tar xzf mysql-4.0.4-beta- pc-linux-gnu-i686.tar.gz sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/rm mysql-4.0.4-beta-pc-li nux-gnu-i686 sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/rmdir mysql-4.0.4-beta-pc -linux-gnu-i686 --More--(21%) sudo: barrie : TTY=pts/3 ; PWD=/usr/local/mysql-4.0.4-beta-pc-linux-gnu-i686 ; USER=root ; COM MAND=/bin/rm bin ChangeLog configure COPYING COPYING.LIB data include INSTALL-BINARY lib man man ual.html manual_toc.html manual.txt mysql-test README scripts share sql-bench support-files test s sudo: barrie : TTY=pts/3 ; PWD=/usr/local/mysql-4.0.4-beta-pc-linux-gnu-i686/bin ; USER=root ; COMMAND=/bin/rm comp_err isamchk msql2mysql myisamchk myisampack my_print_defaults mysql mysqla ccess mysqlaccess.conf mysqladmin mysqlbinlog mysqlbug mysqlcheck mysql_config mysql_convert_tab le_format mysqld mysqld_multi mysqld_safe mysqld.sym.gz mysqldump mysqldumpslow mysql_explain_lo g mysql_find_rows mysql_fix_extensions mysql_fix_privilege_tables mysqlhotcopy mysqlimport mysql manager mysqlmanagerc mysqlmanager-pwgen mysql_secure_installation mysql_setpermission mysqlshow mysql_tableinfo mysqltest mysql_zap pack_isam perror replace resolveip resolve_stack_dump safe_ mysqld sudo: barrie : TTY=pts/3 ; PWD=/usr/local/mysql-4.0.4-beta-pc-linux-gnu-i686 ; USER=root ; COM MAND=/bin/rmdir bin sudo: barrie : TTY=pts/4 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND=/bin/cp mysql-max-4.0.3- beta-pc-linux-gnu-i686.tar.gz /usr/local sudo: barrie : TTY=pts/4 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/gunzip mysql-max-4.0.3-be ta-pc-linux-gnu-i686.tar.gz sudo: barrie : TTY=pts/4 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/mv mysql-max-4.0.3-beta-p c-linux-gnu-i686.tar bin sudo: barrie : TTY=pts/4 ; PWD=/usr/local/bin ; USER=root ; COMMAND=/bin/tar xf mysql-max-4.0. 3-beta-pc-linux-gnu-i686.tar sudo: barrie : TTY=pts/0 ; PWD=/usr/local/bin ; USER=root ; COMMAND=/bin/gzip mysql-4.0.3-beta -pc-linux-gnu-i686.tar sudo: barrie : TTY=pts/0 ; PWD=/usr/local/bin ; USER=root ; COMMAND=/bin/gzip mysql-max-4.0.3- beta-pc-linux-gnu-i686.tar --More--(34%) groupadd[2491]: new group: name=mysql, gid=501 useradd[2493]: new user: name=mysql, uid=501, gid=501, home=/home/mysql, shell=/bin/bash sudo: barrie : TTY=pts/2 ; PWD=/etc ; USER=root ; COMMAND=/bin/vi passwd ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Tue Oct 22 20:58:39 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9N0wdYx001363 for ; Tue, 22 Oct 2002 20:58:39 -0400 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9N0wdAg001360 for root; Tue, 22 Oct 2002 20:58:39 -0400 Date: Tue, 22 Oct 2002 20:58:39 -0400 From: root Message-Id: <200210230058.g9N0wdAg001360@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org --More--(40%)  ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 1 Time(s) **Unmatched Entries** sudo: barrie : TTY=tty1 ; PWD=/home/barrie ; USER=root ; COMMAND=/bin/vi /etc/passwd sudo: barrie : TTY=tty1 ; PWD=/home/barrie ; USER=root ; COMMAND=/sbin/shutdown -h now sudo: barrie : TTY=pts/2 ; PWD=/home/barrie ; USER=root ; COMMAND=/usr/local/mysql/bin/mysqldu mp HSLTEST ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Sat Oct 26 16:35:23 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9QKZNMn001161 --More--(46%)  for ; Sat, 26 Oct 2002 16:35:23 -0400 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9QKZNVQ001158 for root; Sat, 26 Oct 2002 16:35:23 -0400 Date: Sat, 26 Oct 2002 16:35:23 -0400 From: root Message-Id: <200210262035.g9QKZNVQ001158@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 1 Time(s) ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### --More--(51%)  From root@magnolia.brighton.org Sun Oct 27 20:59:43 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9S1xgf5001430 for ; Sun, 27 Oct 2002 20:59:42 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9S1xgGW001427 for root; Sun, 27 Oct 2002 20:59:42 -0500 Date: Sun, 27 Oct 2002 20:59:42 -0500 From: root Message-Id: <200210280159.g9S1xgGW001427@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- **Unmatched Entries** sudo: barrie : TTY=tty1 ; PWD=/home/barrie ; USER=root ; COMMAND=/sbin/shutdown -h now ----------------- Connections (secure-log) End -------------------- --More--(58%)  ###################### LogWatch End ######################### From root@magnolia.brighton.org Mon Oct 28 07:19:55 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9SCJs5j001470 for ; Mon, 28 Oct 2002 07:19:54 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9SCJsnC001467 for root; Mon, 28 Oct 2002 07:19:54 -0500 Date: Mon, 28 Oct 2002 07:19:54 -0500 From: root Message-Id: <200210281219.g9SCJsnC001467@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- **Unmatched Entries** --More--(64%) sudo: barrie : TTY=pts/1 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND=/bin/cp php-4.2.3.tar.gz /usr/local sudo: barrie : TTY=pts/1 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/gunzip php-4.2.3.tar.gz sudo: barrie : TTY=pts/1 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/tar xvf php-4.2.3.tar sudo: barrie : TTY=pts/1 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND=/usr/bin/wget http://www .openssl.org/source/openssl-0.9.6g.tar.gz ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Sat Nov 9 17:58:50 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id gA9Mwo2s001508 for ; Sat, 9 Nov 2002 17:58:50 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id gA9MwnA3001505 for root; Sat, 9 Nov 2002 17:58:49 -0500 Date: Sat, 9 Nov 2002 17:58:49 -0500 From: root Message-Id: <200211092258.gA9MwnA3001505@magnolia.brighton.org> To: root@magnolia.brighton.org --More--(72%) Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 1 Time(s) ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Sun Nov 10 11:58:31 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id gAAGwVf9001283 for ; Sun, 10 Nov 2002 11:58:31 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id gAAGwUXl001280 --More--(77%)  for root; Sun, 10 Nov 2002 11:58:30 -0500 Date: Sun, 10 Nov 2002 11:58:30 -0500 From: root Message-Id: <200211101658.gAAGwUXl001280@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 2 Time(s) **Unmatched Entries** sudo: barrie : TTY=pts/0 ; PWD=/etc/rc.d/rc3.d ; USER=root ; COMMAND=/bin/cp S85gpm S85gpmBU sudo: barrie : TTY=pts/0 ; PWD=/etc/rc.d/rc5.d ; USER=root ; COMMAND=/bin/cp S85gpm S85gpmBU sudo: barrie : TTY=pts/2 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/rm php-4.2.3.tar.gz sudo: barrie : TTY=pts/3 ; PWD=/sbin ; USER=root ; COMMAND=/sbin/kernelversion sudo: barrie : TTY=pts/0 ; PWD=/home/barrie/tmp/kernel ; USER=root ; COMMAND=/bin/cp linux-2.4 .19.tar.gz /usr/src sudo: barrie : TTY=tty1 ; PWD=/etc ; USER=root ; COMMAND=/bin/vi grub.conf --More--(84%)  ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Sun Nov 24 22:00:01 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id gAP301ku007450 for ; Sun, 24 Nov 2002 22:00:01 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id gAP300pG007447 for root; Sun, 24 Nov 2002 22:00:00 -0500 Date: Sun, 24 Nov 2002 22:00:00 -0500 From: root Message-Id: <200211250300.gAP300pG007447@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: magnolia.brighton.org 11/24/02:22.00 system check Unusual System Events =-=-=-=-=-=-=-=-=-=-= Nov 24 13:11:42 magnolia syslogd 1.4.1: restart. Nov 24 16:10:33 magnolia su(pam_unix)[7123]: session opened for user root by (uid=500) --More--(91%) Nov 24 16:04:57 magnolia sudo: barrie : TTY=pts/3 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND =/bin/cp logsentry-1.1.1.tar.gz /usr/local Nov 24 16:07:44 magnolia sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/ gunzip logsentry-1.1.1.tar.gz Nov 24 16:08:18 magnolia sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/ tar tf logsentry-1.1.1.tar Nov 24 16:09:57 magnolia sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/ tar xvf logsentry-1.1.1.tar From root@magnolia.brighton.org Sun Nov 24 22:02:44 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id gAP32iku007491 for ; Sun, 24 Nov 2002 22:02:44 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id gAP32i7q007488 for root; Sun, 24 Nov 2002 22:02:44 -0500 Date: Sun, 24 Nov 2002 22:02:44 -0500 From: root Message-Id: <200211250302.gAP32i7q007488@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: magnolia.brighton.org 11/24/02:22.02 system check Unusual System Events =-=-=-=-=-=-=-=-=-=-= --More--(99%) Nov 24 22:00:01 magnolia sendmail[7451]: gAP301ku007450: forward /home/barrie/.forward: Group wr itable file ]0;barrie@magnolia:/var/spool/mail [root@magnolia mail]# [root@magnolia mail]# [root@magnolia mail]# [root@magnolia mail]# [root@magnolia mail]# e [root@magnolia mail]# e [root@magnolia mail]# ex [root@magnolia mail]# ex [root@magnolia mail]# exi [root@magnolia mail]# exi [root@magnolia mail]# exit [root@magnolia mail]# exit exit ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [barrie@magnolia logcheck-1.1.1]$ [barrie@magnolia logcheck-1.1.1]$ [barrie@magnolia logcheck-1.1.1]$ s [barrie@magnolia logcheck-1.1.1]$ s [barrie@magnolia logcheck-1.1.1]$ su [barrie@magnolia logcheck-1.1.1]$ su Password: ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# / [root@magnolia logcheck-1.1.1]# / [root@magnolia logcheck-1.1.1]# /u [root@magnolia logcheck-1.1.1]# /u [root@magnolia logcheck-1.1.1]# /us [root@magnolia logcheck-1.1.1]# /us [root@magnolia logcheck-1.1.1]# /usr [root@magnolia logcheck-1.1.1]# /usr [root@magnolia logcheck-1.1.1]# /usr/ [root@magnolia logcheck-1.1.1]# /usr/ [root@magnolia logcheck-1.1.1]# /usr/l [root@magnolia logcheck-1.1.1]# /usr/l [root@magnolia logcheck-1.1.1]# /usr/lo [root@magnolia logcheck-1.1.1]# /usr/lo [root@magnolia logcheck-1.1.1]# /usr/loc [root@magnolia logcheck-1.1.1]# /usr/loc [root@magnolia logcheck-1.1.1]# /usr/loca [root@magnolia logcheck-1.1.1]# /usr/loca [root@magnolia logcheck-1.1.1]# /usr/loca/ [root@magnolia logcheck-1.1.1]# /usr/loca/ [root@magnolia logcheck-1.1.1]# /usr/loca [root@magnolia logcheck-1.1.1]# /usr/loca [root@magnolia logcheck-1.1.1]# /usr/local [root@magnolia logcheck-1.1.1]# /usr/local [root@magnolia logcheck-1.1.1]# /usr/local/ [root@magnolia logcheck-1.1.1]# /usr/local/ [root@magnolia logcheck-1.1.1]# /usr/local/e [root@magnolia logcheck-1.1.1]# /usr/local/e [root@magnolia logcheck-1.1.1]# /usr/local/et [root@magnolia logcheck-1.1.1]# /usr/local/et [root@magnolia logcheck-1.1.1]# /usr/local/etc [root@magnolia logcheck-1.1.1]# /usr/local/etc [root@magnolia logcheck-1.1.1]# /usr/local/etc/ [root@magnolia logcheck-1.1.1]# /usr/local/etc/ [root@magnolia logcheck-1.1.1]# /usr/local/etc/l [root@magnolia logcheck-1.1.1]# /usr/local/etc/l [root@magnolia logcheck-1.1.1]# /usr/local/etc/lo [root@magnolia logcheck-1.1.1]# /usr/local/etc/lo [root@magnolia logcheck-1.1.1]# /usr/local/etc/log [root@magnolia logcheck-1.1.1]# /usr/local/etc/log [root@magnolia logcheck-1.1.1]# /usr/local/etc/logc [root@magnolia logcheck-1.1.1]# /usr/local/etc/logc [root@magnolia logcheck-1.1.1]# /usr/local/etc/logch [root@magnolia logcheck-1.1.1]# /usr/local/etc/logch [root@magnolia logcheck-1.1.1]# /usr/local/etc/logche [root@magnolia logcheck-1.1.1]# /usr/local/etc/logche [root@magnolia logcheck-1.1.1]# /usr/local/etc/logchec [root@magnolia logcheck-1.1.1]# /usr/local/etc/logchec [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck. [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck. [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck.s [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck.s [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck.sh [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck.sh ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]#  [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck.sh [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck.sh [root@magnolia logcheck-1.1.1]# exit [root@magnolia logcheck-1.1.1]# exit [root@magnolia logcheck-1.1.1]# more barrie [root@magnolia logcheck-1.1.1]# more barrie [root@magnolia logcheck-1.1.1]# cd /var/spool/mail [root@magnolia logcheck-1.1.1]# cd /var/spool/mail [root@magnolia logcheck-1.1.1]# cd /var/spool/mai [root@magnolia logcheck-1.1.1]# cd /var/spool/ma [root@magnolia logcheck-1.1.1]# cd /var/spool/m [root@magnolia logcheck-1.1.1]# cd /var/spool/ [root@magnolia logcheck-1.1.1]# cd /var/spool [root@magnolia logcheck-1.1.1]# cd /var/spoo [root@magnolia logcheck-1.1.1]# cd /var/spo [root@magnolia logcheck-1.1.1]# cd /var/sp [root@magnolia logcheck-1.1.1]# cd /var/s [root@magnolia logcheck-1.1.1]# cd /var/ [root@magnolia logcheck-1.1.1]# cd /var [root@magnolia logcheck-1.1.1]# cd /va [root@magnolia logcheck-1.1.1]# cd /v [root@magnolia logcheck-1.1.1]# cd / [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# c /var/spool/mail [root@magnolia logcheck-1.1.1]# c [root@magnolia logcheck-1.1.1]#  /var/spool/mail [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# m /var/spool/mail [root@magnolia logcheck-1.1.1]# m [root@magnolia logcheck-1.1.1]# mo /var/spool/mail [root@magnolia logcheck-1.1.1]# mo [root@magnolia logcheck-1.1.1]# mor /var/spool/mail [root@magnolia logcheck-1.1.1]# mor [root@magnolia logcheck-1.1.1]# more /var/spool/mail [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more [root@magnolia logcheck-1.1.1]# more / [root@magnolia logcheck-1.1.1]# more /v [root@magnolia logcheck-1.1.1]# more /va [root@magnolia logcheck-1.1.1]# more /var [root@magnolia logcheck-1.1.1]# more /var/ [root@magnolia logcheck-1.1.1]# more /var/s [root@magnolia logcheck-1.1.1]# more /var/sp [root@magnolia logcheck-1.1.1]# more /var/spo [root@magnolia logcheck-1.1.1]# more /var/spoo [root@magnolia logcheck-1.1.1]# more /var/spool [root@magnolia logcheck-1.1.1]# more /var/spool/ [root@magnolia logcheck-1.1.1]# more /var/spool/m [root@magnolia logcheck-1.1.1]# more /var/spool/ma [root@magnolia logcheck-1.1.1]# more /var/spool/mai [root@magnolia logcheck-1.1.1]# more /var/spool/mail [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ [root@magnolia logcheck-1.1.1]# more /var/spool/mail/b [root@magnolia logcheck-1.1.1]# more /var/spool/mail/b [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ba [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ba [root@magnolia logcheck-1.1.1]# more /var/spool/mail/bar [root@magnolia logcheck-1.1.1]# more /var/spool/mail/bar [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barr [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barr [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barri [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barri [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barrie [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barrie [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barri [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barri [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barr [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barr [root@magnolia logcheck-1.1.1]# more /var/spool/mail/bar [root@magnolia logcheck-1.1.1]# more /var/spool/mail/bar [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ba [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ba [root@magnolia logcheck-1.1.1]# more /var/spool/mail/b [root@magnolia logcheck-1.1.1]# more /var/spool/mail/b [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ [root@magnolia logcheck-1.1.1]# more /var/spool/mail/r [root@magnolia logcheck-1.1.1]# more /var/spool/mail/r [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ro [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ro [root@magnolia logcheck-1.1.1]# more /var/spool/mail/roo [root@magnolia logcheck-1.1.1]# more /var/spool/mail/roo [root@magnolia logcheck-1.1.1]# more /var/spool/mail/root [root@magnolia logcheck-1.1.1]# more /var/spool/mail/root /var/spool/mail/root: No such file or directory ]0;barrie@magnolia:/usr/local/logcheck-1.1.1You have new mail in /var/spool/mail/barrie [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# more /var/spool/mail/root [root@magnolia logcheck-1.1.1]# more /var/spool/mail/root [root@magnolia logcheck-1.1.1]# more /var/spool/mail/roo [root@magnolia logcheck-1.1.1]# more /var/spool/mail/roo [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ro [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ro [root@magnolia logcheck-1.1.1]# more /var/spool/mail/r [root@magnolia logcheck-1.1.1]# more /var/spool/mail/r [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ [root@magnolia logcheck-1.1.1]# more /var/spool/mail/b [root@magnolia logcheck-1.1.1]# more /var/spool/mail/b [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ba [root@magnolia logcheck-1.1.1]# more /var/spool/mail/ba [root@magnolia logcheck-1.1.1]# more /var/spool/mail/bar [root@magnolia logcheck-1.1.1]# more /var/spool/mail/bar [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barr [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barr [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barri [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barri [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barrie [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barrie From root@magnolia.brighton.org Sun Oct 20 13:27:22 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9KHRMh8001433 for ; Sun, 20 Oct 2002 13:27:22 -0400 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9KHRMwi001430 for root; Sun, 20 Oct 2002 13:27:22 -0400 Date: Sun, 20 Oct 2002 13:27:22 -0400 From: root Message-Id: <200210201727.g9KHRMwi001430@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 1 Time(s) **Unmatched Entries** sudo: barrie : TTY=pts/2 ; PWD=/home ; USER=root ; COMMAND=/bin/mkdir htdocs --More--(6%) sudo: barrie : TTY=pts/0 ; PWD=/etc ; USER=root ; COMMAND=/usr/bin/newaliases sudo: barrie : TTY=pts/0 ; PWD=/etc ; USER=root ; COMMAND=/bin/vi aliases sudo: barrie : TTY=pts/0 ; PWD=/etc ; USER=root ; COMMAND=/usr/bin/newaliases sudo: barrie : TTY=pts/0 ; PWD=/home/htdocs ; USER=root ; COMMAND=/usr/bin/pico index.html sudo: barrie : TTY=pts/0 ; PWD=/home ; USER=root ; COMMAND=/usr/bin/locate apachect1 sudo: barrie : TTY=pts/0 ; PWD=/home ; USER=root ; COMMAND=/usr/bin/which apache sudo: barrie : TTY=pts/0 ; PWD=/usr ; USER=root ; COMMAND=/bin/ls ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Mon Oct 21 15:40:29 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9LJeTdg001474 for ; Mon, 21 Oct 2002 15:40:29 -0400 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9LJeT1u001471 for root; Mon, 21 Oct 2002 15:40:29 -0400 Date: Mon, 21 Oct 2002 15:40:29 -0400 From: root Message-Id: <200210211940.g9LJeT1u001471@magnolia.brighton.org> --More--(14%) To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 2 Time(s) **Unmatched Entries** sudo: barrie : TTY=pts/3 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND=/bin/gunzip mysql-4.0.4- beta-pc-linux-gnu-i6i6.tar.gz sudo: barrie : TTY=pts/3 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND=/bin/cp mysql-4.0.4-beta -pc-linux-gnu-i686.tar.gz /usr/local sudo: barrie : TTY=pts/3 ; PWD=/home/barrie ; USER=root ; COMMAND=/bin/tar xzf mysql-4.0.4-bet a-pc-linux-gnu-i686.tar.gz sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/tar xzf mysql-4.0.4-beta- pc-linux-gnu-i686.tar.gz sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/rm mysql-4.0.4-beta-pc-li nux-gnu-i686 sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/rmdir mysql-4.0.4-beta-pc -linux-gnu-i686 --More--(20%) sudo: barrie : TTY=pts/3 ; PWD=/usr/local/mysql-4.0.4-beta-pc-linux-gnu-i686 ; USER=root ; COM MAND=/bin/rm bin ChangeLog configure COPYING COPYING.LIB data include INSTALL-BINARY lib man man ual.html manual_toc.html manual.txt mysql-test README scripts share sql-bench support-files test s sudo: barrie : TTY=pts/3 ; PWD=/usr/local/mysql-4.0.4-beta-pc-linux-gnu-i686/bin ; USER=root ; COMMAND=/bin/rm comp_err isamchk msql2mysql myisamchk myisampack my_print_defaults mysql mysqla ccess mysqlaccess.conf mysqladmin mysqlbinlog mysqlbug mysqlcheck mysql_config mysql_convert_tab le_format mysqld mysqld_multi mysqld_safe mysqld.sym.gz mysqldump mysqldumpslow mysql_explain_lo g mysql_find_rows mysql_fix_extensions mysql_fix_privilege_tables mysqlhotcopy mysqlimport mysql manager mysqlmanagerc mysqlmanager-pwgen mysql_secure_installation mysql_setpermission mysqlshow mysql_tableinfo mysqltest mysql_zap pack_isam perror replace resolveip resolve_stack_dump safe_ mysqld sudo: barrie : TTY=pts/3 ; PWD=/usr/local/mysql-4.0.4-beta-pc-linux-gnu-i686 ; USER=root ; COM MAND=/bin/rmdir bin sudo: barrie : TTY=pts/4 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND=/bin/cp mysql-max-4.0.3- beta-pc-linux-gnu-i686.tar.gz /usr/local sudo: barrie : TTY=pts/4 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/gunzip mysql-max-4.0.3-be ta-pc-linux-gnu-i686.tar.gz sudo: barrie : TTY=pts/4 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/mv mysql-max-4.0.3-beta-p c-linux-gnu-i686.tar bin sudo: barrie : TTY=pts/4 ; PWD=/usr/local/bin ; USER=root ; COMMAND=/bin/tar xf mysql-max-4.0. 3-beta-pc-linux-gnu-i686.tar sudo: barrie : TTY=pts/0 ; PWD=/usr/local/bin ; USER=root ; COMMAND=/bin/gzip mysql-4.0.3-beta -pc-linux-gnu-i686.tar sudo: barrie : TTY=pts/0 ; PWD=/usr/local/bin ; USER=root ; COMMAND=/bin/gzip mysql-max-4.0.3- beta-pc-linux-gnu-i686.tar --More--(31%) groupadd[2491]: new group: name=mysql, gid=501 useradd[2493]: new user: name=mysql, uid=501, gid=501, home=/home/mysql, shell=/bin/bash sudo: barrie : TTY=pts/2 ; PWD=/etc ; USER=root ; COMMAND=/bin/vi passwd ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Tue Oct 22 20:58:39 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9N0wdYx001363 for ; Tue, 22 Oct 2002 20:58:39 -0400 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9N0wdAg001360 for root; Tue, 22 Oct 2002 20:58:39 -0400 Date: Tue, 22 Oct 2002 20:58:39 -0400 From: root Message-Id: <200210230058.g9N0wdAg001360@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org --More--(38%)  ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 1 Time(s) **Unmatched Entries** sudo: barrie : TTY=tty1 ; PWD=/home/barrie ; USER=root ; COMMAND=/bin/vi /etc/passwd sudo: barrie : TTY=tty1 ; PWD=/home/barrie ; USER=root ; COMMAND=/sbin/shutdown -h now sudo: barrie : TTY=pts/2 ; PWD=/home/barrie ; USER=root ; COMMAND=/usr/local/mysql/bin/mysqldu mp HSLTEST ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Sat Oct 26 16:35:23 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9QKZNMn001161 --More--(43%)  for ; Sat, 26 Oct 2002 16:35:23 -0400 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9QKZNVQ001158 for root; Sat, 26 Oct 2002 16:35:23 -0400 Date: Sat, 26 Oct 2002 16:35:23 -0400 From: root Message-Id: <200210262035.g9QKZNVQ001158@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 1 Time(s) ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### --More--(48%)  From root@magnolia.brighton.org Sun Oct 27 20:59:43 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9S1xgf5001430 for ; Sun, 27 Oct 2002 20:59:42 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9S1xgGW001427 for root; Sun, 27 Oct 2002 20:59:42 -0500 Date: Sun, 27 Oct 2002 20:59:42 -0500 From: root Message-Id: <200210280159.g9S1xgGW001427@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- **Unmatched Entries** sudo: barrie : TTY=tty1 ; PWD=/home/barrie ; USER=root ; COMMAND=/sbin/shutdown -h now ----------------- Connections (secure-log) End -------------------- --More--(54%)  ###################### LogWatch End ######################### From root@magnolia.brighton.org Mon Oct 28 07:19:55 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9SCJs5j001470 for ; Mon, 28 Oct 2002 07:19:54 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9SCJsnC001467 for root; Mon, 28 Oct 2002 07:19:54 -0500 Date: Mon, 28 Oct 2002 07:19:54 -0500 From: root Message-Id: <200210281219.g9SCJsnC001467@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- **Unmatched Entries** --More--(60%) sudo: barrie : TTY=pts/1 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND=/bin/cp php-4.2.3.tar.gz /usr/local sudo: barrie : TTY=pts/1 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/gunzip php-4.2.3.tar.gz sudo: barrie : TTY=pts/1 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/tar xvf php-4.2.3.tar sudo: barrie : TTY=pts/1 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND=/usr/bin/wget http://www .openssl.org/source/openssl-0.9.6g.tar.gz ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Sat Nov 9 17:58:50 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id gA9Mwo2s001508 for ; Sat, 9 Nov 2002 17:58:50 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id gA9MwnA3001505 for root; Sat, 9 Nov 2002 17:58:49 -0500 Date: Sat, 9 Nov 2002 17:58:49 -0500 From: root Message-Id: <200211092258.gA9MwnA3001505@magnolia.brighton.org> To: root@magnolia.brighton.org --More--(67%) Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 1 Time(s) ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Sun Nov 10 11:58:31 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id gAAGwVf9001283 for ; Sun, 10 Nov 2002 11:58:31 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id gAAGwUXl001280 --More--(72%)  for root; Sun, 10 Nov 2002 11:58:30 -0500 Date: Sun, 10 Nov 2002 11:58:30 -0500 From: root Message-Id: <200211101658.gAAGwUXl001280@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 2 Time(s) **Unmatched Entries** sudo: barrie : TTY=pts/0 ; PWD=/etc/rc.d/rc3.d ; USER=root ; COMMAND=/bin/cp S85gpm S85gpmBU sudo: barrie : TTY=pts/0 ; PWD=/etc/rc.d/rc5.d ; USER=root ; COMMAND=/bin/cp S85gpm S85gpmBU sudo: barrie : TTY=pts/2 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/rm php-4.2.3.tar.gz sudo: barrie : TTY=pts/3 ; PWD=/sbin ; USER=root ; COMMAND=/sbin/kernelversion sudo: barrie : TTY=pts/0 ; PWD=/home/barrie/tmp/kernel ; USER=root ; COMMAND=/bin/cp linux-2.4 .19.tar.gz /usr/src sudo: barrie : TTY=tty1 ; PWD=/etc ; USER=root ; COMMAND=/bin/vi grub.conf --More--(79%)  ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Sun Nov 24 22:00:01 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id gAP301ku007450 for ; Sun, 24 Nov 2002 22:00:01 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id gAP300pG007447 for root; Sun, 24 Nov 2002 22:00:00 -0500 Date: Sun, 24 Nov 2002 22:00:00 -0500 From: root Message-Id: <200211250300.gAP300pG007447@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: magnolia.brighton.org 11/24/02:22.00 system check Unusual System Events =-=-=-=-=-=-=-=-=-=-= Nov 24 13:11:42 magnolia syslogd 1.4.1: restart. Nov 24 16:10:33 magnolia su(pam_unix)[7123]: session opened for user root by (uid=500) --More--(85%) Nov 24 16:04:57 magnolia sudo: barrie : TTY=pts/3 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND =/bin/cp logsentry-1.1.1.tar.gz /usr/local Nov 24 16:07:44 magnolia sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/ gunzip logsentry-1.1.1.tar.gz Nov 24 16:08:18 magnolia sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/ tar tf logsentry-1.1.1.tar Nov 24 16:09:57 magnolia sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/ tar xvf logsentry-1.1.1.tar From root@magnolia.brighton.org Sun Nov 24 22:02:44 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id gAP32iku007491 for ; Sun, 24 Nov 2002 22:02:44 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id gAP32i7q007488 for root; Sun, 24 Nov 2002 22:02:44 -0500 Date: Sun, 24 Nov 2002 22:02:44 -0500 From: root Message-Id: <200211250302.gAP32i7q007488@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: magnolia.brighton.org 11/24/02:22.02 system check Unusual System Events =-=-=-=-=-=-=-=-=-=-= --More--(93%) Nov 24 22:00:01 magnolia sendmail[7451]: gAP301ku007450: forward /home/barrie/.forward: Group wr itable file From root@magnolia.brighton.org Sun Nov 24 22:09:41 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id gAP39fku007546 for ; Sun, 24 Nov 2002 22:09:41 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id gAP39fFx007543 for root; Sun, 24 Nov 2002 22:09:41 -0500 Date: Sun, 24 Nov 2002 22:09:41 -0500 From: root Message-Id: <200211250309.gAP39fFx007543@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: magnolia.brighton.org 11/24/02:22.09 system check Unusual System Events =-=-=-=-=-=-=-=-=-=-= Nov 24 22:09:19 magnolia su(pam_unix)[7123]: session closed for user root Nov 24 22:09:28 magnolia su(pam_unix)[7500]: session opened for user root by (uid=500) Nov 24 22:02:44 magnolia sendmail[7492]: gAP32iku007491: forward /home/barrie/.forward: Group wr itable file ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# p [root@magnolia logcheck-1.1.1]# p [root@magnolia logcheck-1.1.1]# ps [root@magnolia logcheck-1.1.1]# ps [root@magnolia logcheck-1.1.1]# ps [root@magnolia logcheck-1.1.1]# ps [root@magnolia logcheck-1.1.1]# ps - [root@magnolia logcheck-1.1.1]# ps - [root@magnolia logcheck-1.1.1]# ps -e [root@magnolia logcheck-1.1.1]# ps -e [root@magnolia logcheck-1.1.1]# ps -ef [root@magnolia logcheck-1.1.1]# ps -ef [root@magnolia logcheck-1.1.1]# ps -ef [root@magnolia logcheck-1.1.1]# ps -ef [root@magnolia logcheck-1.1.1]# ps -ef c [root@magnolia logcheck-1.1.1]# ps -ef c [root@magnolia logcheck-1.1.1]# ps -ef cr [root@magnolia logcheck-1.1.1]# ps -ef cr [root@magnolia logcheck-1.1.1]# ps -ef cro [root@magnolia logcheck-1.1.1]# ps -ef cro [root@magnolia logcheck-1.1.1]# ps -ef cron [root@magnolia logcheck-1.1.1]# ps -ef cron [root@magnolia logcheck-1.1.1]# ps -ef crond [root@magnolia logcheck-1.1.1]# ps -ef crond [root@magnolia logcheck-1.1.1]# ps -ef cron [root@magnolia logcheck-1.1.1]# ps -ef cron [root@magnolia logcheck-1.1.1]# ps -ef cro [root@magnolia logcheck-1.1.1]# ps -ef cro [root@magnolia logcheck-1.1.1]# ps -ef cr [root@magnolia logcheck-1.1.1]# ps -ef cr [root@magnolia logcheck-1.1.1]# ps -ef c [root@magnolia logcheck-1.1.1]# ps -ef c [root@magnolia logcheck-1.1.1]# ps -ef  [root@magnolia logcheck-1.1.1]# ps -ef [root@magnolia logcheck-1.1.1]# ps -ef | [root@magnolia logcheck-1.1.1]# ps -ef | [root@magnolia logcheck-1.1.1]# ps -ef | [root@magnolia logcheck-1.1.1]# ps -ef | [root@magnolia logcheck-1.1.1]# ps -ef | g [root@magnolia logcheck-1.1.1]# ps -ef | g [root@magnolia logcheck-1.1.1]# ps -ef | gr [root@magnolia logcheck-1.1.1]# ps -ef | gr [root@magnolia logcheck-1.1.1]# ps -ef | gre [root@magnolia logcheck-1.1.1]# ps -ef | gre [root@magnolia logcheck-1.1.1]# ps -ef | grep [root@magnolia logcheck-1.1.1]# ps -ef | grep [root@magnolia logcheck-1.1.1]# ps -ef | grep [root@magnolia logcheck-1.1.1]# ps -ef | grep [root@magnolia logcheck-1.1.1]# ps -ef | grep c [root@magnolia logcheck-1.1.1]# ps -ef | grep c [root@magnolia logcheck-1.1.1]# ps -ef | grep cr [root@magnolia logcheck-1.1.1]# ps -ef | grep cr [root@magnolia logcheck-1.1.1]# ps -ef | grep cro [root@magnolia logcheck-1.1.1]# ps -ef | grep cro [root@magnolia logcheck-1.1.1]# ps -ef | grep cron [root@magnolia logcheck-1.1.1]# ps -ef | grep cron [root@magnolia logcheck-1.1.1]# ps -ef | grep crond [root@magnolia logcheck-1.1.1]# ps -ef | grep crond root 907 1 0 12:06 ? 00:00:00 crond root 7558 7503 0 22:39 pts/3 00:00:00 grep crond ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# p [root@magnolia logcheck-1.1.1]# p [root@magnolia logcheck-1.1.1]# pr [root@magnolia logcheck-1.1.1]# pr [root@magnolia logcheck-1.1.1]# p [root@magnolia logcheck-1.1.1]# p [root@magnolia logcheck-1.1.1]# ps [root@magnolia logcheck-1.1.1]# ps [root@magnolia logcheck-1.1.1]# ps [root@magnolia logcheck-1.1.1]# ps [root@magnolia logcheck-1.1.1]# ps - [root@magnolia logcheck-1.1.1]# ps - [root@magnolia logcheck-1.1.1]# ps -e [root@magnolia logcheck-1.1.1]# ps -e [root@magnolia logcheck-1.1.1]# ps -ef [root@magnolia logcheck-1.1.1]# ps -ef [root@magnolia logcheck-1.1.1]# ps -ef [root@magnolia logcheck-1.1.1]# ps -ef [root@magnolia logcheck-1.1.1]# ps -ef | [root@magnolia logcheck-1.1.1]# ps -ef | [root@magnolia logcheck-1.1.1]# ps -ef | [root@magnolia logcheck-1.1.1]# ps -ef | [root@magnolia logcheck-1.1.1]# ps -ef | g [root@magnolia logcheck-1.1.1]# ps -ef | g [root@magnolia logcheck-1.1.1]# ps -ef | gr [root@magnolia logcheck-1.1.1]# ps -ef | gr [root@magnolia logcheck-1.1.1]# ps -ef | gre [root@magnolia logcheck-1.1.1]# ps -ef | gre [root@magnolia logcheck-1.1.1]# ps -ef | grep [root@magnolia logcheck-1.1.1]# ps -ef | grep [root@magnolia logcheck-1.1.1]# ps -ef | grep [root@magnolia logcheck-1.1.1]# ps -ef | grep [root@magnolia logcheck-1.1.1]# ps -ef | grep l [root@magnolia logcheck-1.1.1]# ps -ef | grep l [root@magnolia logcheck-1.1.1]# ps -ef | grep lo [root@magnolia logcheck-1.1.1]# ps -ef | grep lo [root@magnolia logcheck-1.1.1]# ps -ef | grep loc [root@magnolia logcheck-1.1.1]# ps -ef | grep loc [root@magnolia logcheck-1.1.1]# ps -ef | grep lo [root@magnolia logcheck-1.1.1]# ps -ef | grep lo [root@magnolia logcheck-1.1.1]# ps -ef | grep log [root@magnolia logcheck-1.1.1]# ps -ef | grep log [root@magnolia logcheck-1.1.1]# ps -ef | grep logc [root@magnolia logcheck-1.1.1]# ps -ef | grep logc [root@magnolia logcheck-1.1.1]# ps -ef | grep logch [root@magnolia logcheck-1.1.1]# ps -ef | grep logch [root@magnolia logcheck-1.1.1]# ps -ef | grep logche [root@magnolia logcheck-1.1.1]# ps -ef | grep logche [root@magnolia logcheck-1.1.1]# ps -ef | grep logchec [root@magnolia logcheck-1.1.1]# ps -ef | grep logchec [root@magnolia logcheck-1.1.1]# ps -ef | grep logcheck [root@magnolia logcheck-1.1.1]# ps -ef | grep logcheck barrie 7059 1188 0 15:24 pts/1 00:00:00 script logcheckinstall021123 barrie 7060 7059 0 15:24 pts/1 00:00:00 script logcheckinstall021123 root 7556 7158 0 22:26 pts/4 00:00:00 more logcheck.sh root 7560 7503 0 22:39 pts/3 00:00:00 grep logcheck ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# c [root@magnolia logcheck-1.1.1]# c [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd [root@magnolia logcheck-1.1.1]# cd / [root@magnolia logcheck-1.1.1]# cd / [root@magnolia logcheck-1.1.1]# cd /v [root@magnolia logcheck-1.1.1]# cd /v [root@magnolia logcheck-1.1.1]# cd /va [root@magnolia logcheck-1.1.1]# cd /va [root@magnolia logcheck-1.1.1]# cd /var [root@magnolia logcheck-1.1.1]# cd /var [root@magnolia logcheck-1.1.1]# cd /var/ [root@magnolia logcheck-1.1.1]# cd /var/ [root@magnolia logcheck-1.1.1]# cd /var/l [root@magnolia logcheck-1.1.1]# cd /var/l [root@magnolia logcheck-1.1.1]# cd /var/lo [root@magnolia logcheck-1.1.1]# cd /var/lo [root@magnolia logcheck-1.1.1]# cd /var/log [root@magnolia logcheck-1.1.1]# cd /var/log ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# l [root@magnolia log]# l [root@magnolia log]# ls [root@magnolia log]# ls boot.log cron.4 ksyms.4 maillog.offset rpmpkgs.2 secure.4 up2date.2 boot.log.1 cups ksyms.5 messages rpmpkgs.3 secure.offset up2date.3 boot.log.2 dmesg ksyms.6 messages.1 rpmpkgs.4 spooler up2date.4 boot.log.3 gdm lastlog messages.2 samba spooler.1 vbox boot.log.4 httpd maillog messages.3 scrollkeeper.log spooler.2 wtmp cron ksyms.0 maillog.1 messages.4 secure spooler.3 wtmp.1 cron.1 ksyms.1 maillog.2 messages.offset secure.1 spooler.4 XFree86.0.log cron.2 ksyms.2 maillog.3 rpmpkgs secure.2 up2date cron.3 ksyms.3 maillog.4 rpmpkgs.1 secure.3 up2date.1 ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# m [root@magnolia log]# m [root@magnolia log]# mo [root@magnolia log]# mo [root@magnolia log]# mor [root@magnolia log]# mor [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more [root@magnolia log]# more m [root@magnolia log]# more m [root@magnolia log]# more me [root@magnolia log]# more me [root@magnolia log]# more mes [root@magnolia log]# more mes [root@magnolia log]# more mess [root@magnolia log]# more mess [root@magnolia log]# more messa [root@magnolia log]# more messa [root@magnolia log]# more messag [root@magnolia log]# more messag [root@magnolia log]# more message [root@magnolia log]# more message [root@magnolia log]# more messages [root@magnolia log]# more messages [root@magnolia log]# more messages. [root@magnolia log]# more messages. [root@magnolia log]# more messages.o [root@magnolia log]# more messages.o [root@magnolia log]# more messages.of [root@magnolia log]# more messages.of [root@magnolia log]# more messages.off [root@magnolia log]# more messages.off [root@magnolia log]# more messages.offs [root@magnolia log]# more messages.offs [root@magnolia log]# more messages.offse [root@magnolia log]# more messages.offse [root@magnolia log]# more messages.offset [root@magnolia log]# more messages.offset 882248 297 ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]# [root@magnolia log]# c [root@magnolia log]# c [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd , [root@magnolia log]# cd , [root@magnolia log]# cd ,e [root@magnolia log]# cd ,e [root@magnolia log]# cd ,es [root@magnolia log]# cd ,es [root@magnolia log]# cd ,e [root@magnolia log]# cd ,e [root@magnolia log]# cd , [root@magnolia log]# cd , [root@magnolia log]# cd  [root@magnolia log]# cd [root@magnolia log]# cd m [root@magnolia log]# cd m [root@magnolia log]# cd me [root@magnolia log]# cd me [root@magnolia log]# cd mes [root@magnolia log]# cd mes [root@magnolia log]# cd mess [root@magnolia log]# cd mess [root@magnolia log]# cd messa [root@magnolia log]# cd messa [root@magnolia log]# cd messag [root@magnolia log]# cd messag [root@magnolia log]# cd message [root@magnolia log]# cd message [root@magnolia log]# cd messages [root@magnolia log]# cd messages bash: cd: messages: Not a directory ]0;barrie@magnolia:/var/log [root@magnolia log]# [root@magnolia log]#  [root@magnolia log]# [root@magnolia log]# c [root@magnolia log]# c [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd [root@magnolia log]# cd / [root@magnolia log]# cd / [root@magnolia log]# cd /u [root@magnolia log]# cd /u [root@magnolia log]# cd /us [root@magnolia log]# cd /us [root@magnolia log]# cd /usr [root@magnolia log]# cd /usr [root@magnolia log]# cd /usr/ [root@magnolia log]# cd /usr/ [root@magnolia log]# cd /usr/l [root@magnolia log]# cd /usr/l [root@magnolia log]# cd /usr/lo [root@magnolia log]# cd /usr/lo [root@magnolia log]# cd /usr/loc [root@magnolia log]# cd /usr/loc [root@magnolia log]# cd /usr/loca [root@magnolia log]# cd /usr/loca [root@magnolia log]# cd /usr/local [root@magnolia log]# cd /usr/local [root@magnolia log]# cd /usr/local/ [root@magnolia log]# cd /usr/local/ [root@magnolia log]# cd /usr/local/e [root@magnolia log]# cd /usr/local/e [root@magnolia log]# cd /usr/local/et [root@magnolia log]# cd /usr/local/et [root@magnolia log]# cd /usr/local/etc [root@magnolia log]# cd /usr/local/etc ]0;barrie@magnolia:/usr/local/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# l [root@magnolia etc]# l [root@magnolia etc]# ls [root@magnolia etc]# ls logcheck.hacking logcheck.sh logcheck.violations.ignore logcheck.ignore logcheck.violations tmp ]0;barrie@magnolia:/usr/local/etc [root@magnolia etc]# [root@magnolia etc]# [root@magnolia etc]# c [root@magnolia etc]# c [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd [root@magnolia etc]# cd t [root@magnolia etc]# cd t [root@magnolia etc]# cd tm [root@magnolia etc]# cd tm [root@magnolia etc]# cd tmp [root@magnolia etc]# cd tmp ]0;barrie@magnolia:/usr/local/etc/tmp [root@magnolia tmp]# [root@magnolia tmp]# [root@magnolia tmp]# l [root@magnolia tmp]# l [root@magnolia tmp]# ls [root@magnolia tmp]# ls ]0;barrie@magnolia:/usr/local/etc/tmp [root@magnolia tmp]# [root@magnolia tmp]# [root@magnolia tmp]# / [root@magnolia tmp]# / [root@magnolia tmp]# /u [root@magnolia tmp]# /u [root@magnolia tmp]# /us [root@magnolia tmp]# /us [root@magnolia tmp]# /usr [root@magnolia tmp]# /usr [root@magnolia tmp]# /usr/ [root@magnolia tmp]# /usr/ [root@magnolia tmp]# /usr [root@magnolia tmp]# /usr [root@magnolia tmp]# /us [root@magnolia tmp]# /us [root@magnolia tmp]# /u [root@magnolia tmp]# /u [root@magnolia tmp]# / [root@magnolia tmp]# / [root@magnolia tmp]#  [root@magnolia tmp]# [root@magnolia tmp]# e [root@magnolia tmp]# e [root@magnolia tmp]# ex [root@magnolia tmp]# ex [root@magnolia tmp]# exi [root@magnolia tmp]# exi [root@magnolia tmp]# exit [root@magnolia tmp]# exit [root@magnolia tmp]# exit/ [root@magnolia tmp]# exit/ [root@magnolia tmp]# exit [root@magnolia tmp]# exit exit ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [barrie@magnolia logcheck-1.1.1]$ [barrie@magnolia logcheck-1.1.1]$ [barrie@magnolia logcheck-1.1.1]$ s [barrie@magnolia logcheck-1.1.1]$ s [barrie@magnolia logcheck-1.1.1]$ su [barrie@magnolia logcheck-1.1.1]$ su Password: ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# / [root@magnolia logcheck-1.1.1]# / [root@magnolia logcheck-1.1.1]# /u [root@magnolia logcheck-1.1.1]# /u [root@magnolia logcheck-1.1.1]# /us [root@magnolia logcheck-1.1.1]# /us [root@magnolia logcheck-1.1.1]# /usr [root@magnolia logcheck-1.1.1]# /usr [root@magnolia logcheck-1.1.1]# /usr/ [root@magnolia logcheck-1.1.1]# /usr/ [root@magnolia logcheck-1.1.1]# /usr/l [root@magnolia logcheck-1.1.1]# /usr/l [root@magnolia logcheck-1.1.1]# /usr/lo [root@magnolia logcheck-1.1.1]# /usr/lo [root@magnolia logcheck-1.1.1]# /usr/loc [root@magnolia logcheck-1.1.1]# /usr/loc [root@magnolia logcheck-1.1.1]# /usr/loca [root@magnolia logcheck-1.1.1]# /usr/loca [root@magnolia logcheck-1.1.1]# /usr/local [root@magnolia logcheck-1.1.1]# /usr/local [root@magnolia logcheck-1.1.1]# /usr/local/ [root@magnolia logcheck-1.1.1]# /usr/local/ [root@magnolia logcheck-1.1.1]# /usr/local/e [root@magnolia logcheck-1.1.1]# /usr/local/e [root@magnolia logcheck-1.1.1]# /usr/local/et [root@magnolia logcheck-1.1.1]# /usr/local/et [root@magnolia logcheck-1.1.1]# /usr/local/etc [root@magnolia logcheck-1.1.1]# /usr/local/etc [root@magnolia logcheck-1.1.1]# /usr/local/etc/ [root@magnolia logcheck-1.1.1]# /usr/local/etc/ [root@magnolia logcheck-1.1.1]# /usr/local/etc/l [root@magnolia logcheck-1.1.1]# /usr/local/etc/l [root@magnolia logcheck-1.1.1]# /usr/local/etc/lo [root@magnolia logcheck-1.1.1]# /usr/local/etc/lo [root@magnolia logcheck-1.1.1]# /usr/local/etc/log [root@magnolia logcheck-1.1.1]# /usr/local/etc/log [root@magnolia logcheck-1.1.1]# /usr/local/etc/logc [root@magnolia logcheck-1.1.1]# /usr/local/etc/logc [root@magnolia logcheck-1.1.1]# /usr/local/etc/logch [root@magnolia logcheck-1.1.1]# /usr/local/etc/logch [root@magnolia logcheck-1.1.1]# /usr/local/etc/logche [root@magnolia logcheck-1.1.1]# /usr/local/etc/logche [root@magnolia logcheck-1.1.1]# /usr/local/etc/logchec [root@magnolia logcheck-1.1.1]# /usr/local/etc/logchec [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck. [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck. [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck.s [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck.s [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck.sh [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck.sh ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# e [root@magnolia logcheck-1.1.1]# e [root@magnolia logcheck-1.1.1]# ex [root@magnolia logcheck-1.1.1]# ex [root@magnolia logcheck-1.1.1]# exi [root@magnolia logcheck-1.1.1]# exi [root@magnolia logcheck-1.1.1]# exit [root@magnolia logcheck-1.1.1]# exit exit ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [barrie@magnolia logcheck-1.1.1]$ [barrie@magnolia logcheck-1.1.1]$ [barrie@magnolia logcheck-1.1.1]$ s [barrie@magnolia logcheck-1.1.1]$ s [barrie@magnolia logcheck-1.1.1]$ su [barrie@magnolia logcheck-1.1.1]$ su Password: ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# exit [root@magnolia logcheck-1.1.1]# exit [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck.sh [root@magnolia logcheck-1.1.1]# /usr/local/etc/logcheck.sh [root@magnolia logcheck-1.1.1]# exit [root@magnolia logcheck-1.1.1]# exit [root@magnolia logcheck-1.1.1]# ls [root@magnolia logcheck-1.1.1]# ls [root@magnolia logcheck-1.1.1]# cd tmp [root@magnolia logcheck-1.1.1]# cd tmp [root@magnolia logcheck-1.1.1]# ls [root@magnolia logcheck-1.1.1]# ls [root@magnolia logcheck-1.1.1]# cd /usr/local/etc [root@magnolia logcheck-1.1.1]# cd /usr/local/etc [root@magnolia logcheck-1.1.1]# cd messages [root@magnolia logcheck-1.1.1]# cd messages [root@magnolia logcheck-1.1.1]# more messages.offset [root@magnolia logcheck-1.1.1]# more messages.offset [root@magnolia logcheck-1.1.1]# ls [root@magnolia logcheck-1.1.1]# ls [root@magnolia logcheck-1.1.1]# cd /var/log [root@magnolia logcheck-1.1.1]# cd /var/log [root@magnolia logcheck-1.1.1]# ps -ef | grep logcheck [root@magnolia logcheck-1.1.1]# ps -ef | grep logcheck [root@magnolia logcheck-1.1.1]# ps -ef | grep crond [root@magnolia logcheck-1.1.1]# ps -ef | grep crond [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barrie [root@magnolia logcheck-1.1.1]# more /var/spool/mail/barrie From root@magnolia.brighton.org Sun Oct 20 13:27:22 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9KHRMh8001433 for ; Sun, 20 Oct 2002 13:27:22 -0400 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9KHRMwi001430 for root; Sun, 20 Oct 2002 13:27:22 -0400 Date: Sun, 20 Oct 2002 13:27:22 -0400 From: root Message-Id: <200210201727.g9KHRMwi001430@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 1 Time(s) **Unmatched Entries** sudo: barrie : TTY=pts/2 ; PWD=/home ; USER=root ; COMMAND=/bin/mkdir htdocs --More--(5%) sudo: barrie : TTY=pts/0 ; PWD=/etc ; USER=root ; COMMAND=/usr/bin/newaliases sudo: barrie : TTY=pts/0 ; PWD=/etc ; USER=root ; COMMAND=/bin/vi aliases sudo: barrie : TTY=pts/0 ; PWD=/etc ; USER=root ; COMMAND=/usr/bin/newaliases sudo: barrie : TTY=pts/0 ; PWD=/home/htdocs ; USER=root ; COMMAND=/usr/bin/pico index.html sudo: barrie : TTY=pts/0 ; PWD=/home ; USER=root ; COMMAND=/usr/bin/locate apachect1 sudo: barrie : TTY=pts/0 ; PWD=/home ; USER=root ; COMMAND=/usr/bin/which apache sudo: barrie : TTY=pts/0 ; PWD=/usr ; USER=root ; COMMAND=/bin/ls ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Mon Oct 21 15:40:29 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9LJeTdg001474 for ; Mon, 21 Oct 2002 15:40:29 -0400 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9LJeT1u001471 for root; Mon, 21 Oct 2002 15:40:29 -0400 Date: Mon, 21 Oct 2002 15:40:29 -0400 From: root Message-Id: <200210211940.g9LJeT1u001471@magnolia.brighton.org> --More--(13%) To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 2 Time(s) **Unmatched Entries** sudo: barrie : TTY=pts/3 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND=/bin/gunzip mysql-4.0.4- beta-pc-linux-gnu-i6i6.tar.gz sudo: barrie : TTY=pts/3 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND=/bin/cp mysql-4.0.4-beta -pc-linux-gnu-i686.tar.gz /usr/local sudo: barrie : TTY=pts/3 ; PWD=/home/barrie ; USER=root ; COMMAND=/bin/tar xzf mysql-4.0.4-bet a-pc-linux-gnu-i686.tar.gz sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/tar xzf mysql-4.0.4-beta- pc-linux-gnu-i686.tar.gz sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/rm mysql-4.0.4-beta-pc-li nux-gnu-i686 sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/rmdir mysql-4.0.4-beta-pc -linux-gnu-i686 --More--(19%) sudo: barrie : TTY=pts/3 ; PWD=/usr/local/mysql-4.0.4-beta-pc-linux-gnu-i686 ; USER=root ; COM MAND=/bin/rm bin ChangeLog configure COPYING COPYING.LIB data include INSTALL-BINARY lib man man ual.html manual_toc.html manual.txt mysql-test README scripts share sql-bench support-files test s sudo: barrie : TTY=pts/3 ; PWD=/usr/local/mysql-4.0.4-beta-pc-linux-gnu-i686/bin ; USER=root ; COMMAND=/bin/rm comp_err isamchk msql2mysql myisamchk myisampack my_print_defaults mysql mysqla ccess mysqlaccess.conf mysqladmin mysqlbinlog mysqlbug mysqlcheck mysql_config mysql_convert_tab le_format mysqld mysqld_multi mysqld_safe mysqld.sym.gz mysqldump mysqldumpslow mysql_explain_lo g mysql_find_rows mysql_fix_extensions mysql_fix_privilege_tables mysqlhotcopy mysqlimport mysql manager mysqlmanagerc mysqlmanager-pwgen mysql_secure_installation mysql_setpermission mysqlshow mysql_tableinfo mysqltest mysql_zap pack_isam perror replace resolveip resolve_stack_dump safe_ mysqld sudo: barrie : TTY=pts/3 ; PWD=/usr/local/mysql-4.0.4-beta-pc-linux-gnu-i686 ; USER=root ; COM MAND=/bin/rmdir bin sudo: barrie : TTY=pts/4 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND=/bin/cp mysql-max-4.0.3- beta-pc-linux-gnu-i686.tar.gz /usr/local sudo: barrie : TTY=pts/4 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/gunzip mysql-max-4.0.3-be ta-pc-linux-gnu-i686.tar.gz sudo: barrie : TTY=pts/4 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/mv mysql-max-4.0.3-beta-p c-linux-gnu-i686.tar bin sudo: barrie : TTY=pts/4 ; PWD=/usr/local/bin ; USER=root ; COMMAND=/bin/tar xf mysql-max-4.0. 3-beta-pc-linux-gnu-i686.tar sudo: barrie : TTY=pts/0 ; PWD=/usr/local/bin ; USER=root ; COMMAND=/bin/gzip mysql-4.0.3-beta -pc-linux-gnu-i686.tar sudo: barrie : TTY=pts/0 ; PWD=/usr/local/bin ; USER=root ; COMMAND=/bin/gzip mysql-max-4.0.3- beta-pc-linux-gnu-i686.tar --More--(29%) groupadd[2491]: new group: name=mysql, gid=501 useradd[2493]: new user: name=mysql, uid=501, gid=501, home=/home/mysql, shell=/bin/bash sudo: barrie : TTY=pts/2 ; PWD=/etc ; USER=root ; COMMAND=/bin/vi passwd ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Tue Oct 22 20:58:39 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9N0wdYx001363 for ; Tue, 22 Oct 2002 20:58:39 -0400 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9N0wdAg001360 for root; Tue, 22 Oct 2002 20:58:39 -0400 Date: Tue, 22 Oct 2002 20:58:39 -0400 From: root Message-Id: <200210230058.g9N0wdAg001360@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org --More--(35%)  ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 1 Time(s) **Unmatched Entries** sudo: barrie : TTY=tty1 ; PWD=/home/barrie ; USER=root ; COMMAND=/bin/vi /etc/passwd sudo: barrie : TTY=tty1 ; PWD=/home/barrie ; USER=root ; COMMAND=/sbin/shutdown -h now sudo: barrie : TTY=pts/2 ; PWD=/home/barrie ; USER=root ; COMMAND=/usr/local/mysql/bin/mysqldu mp HSLTEST ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Sat Oct 26 16:35:23 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9QKZNMn001161 --More--(40%)  for ; Sat, 26 Oct 2002 16:35:23 -0400 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9QKZNVQ001158 for root; Sat, 26 Oct 2002 16:35:23 -0400 Date: Sat, 26 Oct 2002 16:35:23 -0400 From: root Message-Id: <200210262035.g9QKZNVQ001158@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 1 Time(s) ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### --More--(45%)  From root@magnolia.brighton.org Sun Oct 27 20:59:43 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9S1xgf5001430 for ; Sun, 27 Oct 2002 20:59:42 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9S1xgGW001427 for root; Sun, 27 Oct 2002 20:59:42 -0500 Date: Sun, 27 Oct 2002 20:59:42 -0500 From: root Message-Id: <200210280159.g9S1xgGW001427@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- **Unmatched Entries** sudo: barrie : TTY=tty1 ; PWD=/home/barrie ; USER=root ; COMMAND=/sbin/shutdown -h now ----------------- Connections (secure-log) End -------------------- --More--(51%)  ###################### LogWatch End ######################### From root@magnolia.brighton.org Mon Oct 28 07:19:55 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id g9SCJs5j001470 for ; Mon, 28 Oct 2002 07:19:54 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id g9SCJsnC001467 for root; Mon, 28 Oct 2002 07:19:54 -0500 Date: Mon, 28 Oct 2002 07:19:54 -0500 From: root Message-Id: <200210281219.g9SCJsnC001467@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- **Unmatched Entries** --More--(56%) sudo: barrie : TTY=pts/1 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND=/bin/cp php-4.2.3.tar.gz /usr/local sudo: barrie : TTY=pts/1 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/gunzip php-4.2.3.tar.gz sudo: barrie : TTY=pts/1 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/tar xvf php-4.2.3.tar sudo: barrie : TTY=pts/1 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND=/usr/bin/wget http://www .openssl.org/source/openssl-0.9.6g.tar.gz ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Sat Nov 9 17:58:50 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id gA9Mwo2s001508 for ; Sat, 9 Nov 2002 17:58:50 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id gA9MwnA3001505 for root; Sat, 9 Nov 2002 17:58:49 -0500 Date: Sat, 9 Nov 2002 17:58:49 -0500 From: root Message-Id: <200211092258.gA9MwnA3001505@magnolia.brighton.org> To: root@magnolia.brighton.org --More--(63%) Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 1 Time(s) ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Sun Nov 10 11:58:31 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id gAAGwVf9001283 for ; Sun, 10 Nov 2002 11:58:31 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id gAAGwUXl001280 --More--(67%)  for root; Sun, 10 Nov 2002 11:58:30 -0500 Date: Sun, 10 Nov 2002 11:58:30 -0500 From: root Message-Id: <200211101658.gAAGwUXl001280@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: LogWatch for magnolia.brighton.org ################## LogWatch 2.6 Begin ##################### ---------------- Connections (secure-log) Begin ------------------- Connections: Service sgi_fam: : 2 Time(s) **Unmatched Entries** sudo: barrie : TTY=pts/0 ; PWD=/etc/rc.d/rc3.d ; USER=root ; COMMAND=/bin/cp S85gpm S85gpmBU sudo: barrie : TTY=pts/0 ; PWD=/etc/rc.d/rc5.d ; USER=root ; COMMAND=/bin/cp S85gpm S85gpmBU sudo: barrie : TTY=pts/2 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/rm php-4.2.3.tar.gz sudo: barrie : TTY=pts/3 ; PWD=/sbin ; USER=root ; COMMAND=/sbin/kernelversion sudo: barrie : TTY=pts/0 ; PWD=/home/barrie/tmp/kernel ; USER=root ; COMMAND=/bin/cp linux-2.4 .19.tar.gz /usr/src sudo: barrie : TTY=tty1 ; PWD=/etc ; USER=root ; COMMAND=/bin/vi grub.conf --More--(73%)  ----------------- Connections (secure-log) End -------------------- ###################### LogWatch End ######################### From root@magnolia.brighton.org Sun Nov 24 22:00:01 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id gAP301ku007450 for ; Sun, 24 Nov 2002 22:00:01 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id gAP300pG007447 for root; Sun, 24 Nov 2002 22:00:00 -0500 Date: Sun, 24 Nov 2002 22:00:00 -0500 From: root Message-Id: <200211250300.gAP300pG007447@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: magnolia.brighton.org 11/24/02:22.00 system check Unusual System Events =-=-=-=-=-=-=-=-=-=-= Nov 24 13:11:42 magnolia syslogd 1.4.1: restart. Nov 24 16:10:33 magnolia su(pam_unix)[7123]: session opened for user root by (uid=500) --More--(79%) Nov 24 16:04:57 magnolia sudo: barrie : TTY=pts/3 ; PWD=/home/barrie/tmp ; USER=root ; COMMAND =/bin/cp logsentry-1.1.1.tar.gz /usr/local Nov 24 16:07:44 magnolia sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/ gunzip logsentry-1.1.1.tar.gz Nov 24 16:08:18 magnolia sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/ tar tf logsentry-1.1.1.tar Nov 24 16:09:57 magnolia sudo: barrie : TTY=pts/3 ; PWD=/usr/local ; USER=root ; COMMAND=/bin/ tar xvf logsentry-1.1.1.tar From root@magnolia.brighton.org Sun Nov 24 22:02:44 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id gAP32iku007491 for ; Sun, 24 Nov 2002 22:02:44 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id gAP32i7q007488 for root; Sun, 24 Nov 2002 22:02:44 -0500 Date: Sun, 24 Nov 2002 22:02:44 -0500 From: root Message-Id: <200211250302.gAP32i7q007488@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: magnolia.brighton.org 11/24/02:22.02 system check Unusual System Events =-=-=-=-=-=-=-=-=-=-= --More--(86%) Nov 24 22:00:01 magnolia sendmail[7451]: gAP301ku007450: forward /home/barrie/.forward: Group wr itable file From root@magnolia.brighton.org Sun Nov 24 22:09:41 2002 Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id gAP39fku007546 for ; Sun, 24 Nov 2002 22:09:41 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id gAP39fFx007543 for root; Sun, 24 Nov 2002 22:09:41 -0500 Date: Sun, 24 Nov 2002 22:09:41 -0500 From: root Message-Id: <200211250309.gAP39fFx007543@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: magnolia.brighton.org 11/24/02:22.09 system check Unusual System Events =-=-=-=-=-=-=-=-=-=-= Nov 24 22:09:19 magnolia su(pam_unix)[7123]: session closed for user root Nov 24 22:09:28 magnolia su(pam_unix)[7500]: session opened for user root by (uid=500) Nov 24 22:02:44 magnolia sendmail[7492]: gAP32iku007491: forward /home/barrie/.forward: Group wr itable file From root@magnolia.brighton.org Sun Nov 24 22:46:12 2002 --More--(93%) Return-Path: Received: from magnolia.brighton.org (magnolia.brighton.org [127.0.0.1]) by magnolia.brighton.org (8.12.5/8.12.5) with ESMTP id gAP3kBku007611 for ; Sun, 24 Nov 2002 22:46:12 -0500 Received: (from root@localhost) by magnolia.brighton.org (8.12.5/8.12.5/Submit) id gAP3kBqX007608 for root; Sun, 24 Nov 2002 22:46:11 -0500 Date: Sun, 24 Nov 2002 22:46:11 -0500 From: root Message-Id: <200211250346.gAP3kBqX007608@magnolia.brighton.org> To: root@magnolia.brighton.org Subject: magnolia.brighton.org 11/24/02:22.46 system check Unusual System Events =-=-=-=-=-=-=-=-=-=-= Nov 24 22:45:48 magnolia su(pam_unix)[7500]: session closed for user root Nov 24 22:45:55 magnolia su(pam_unix)[7565]: session opened for user root by (uid=500) Nov 24 22:26:25 magnolia sudo: barrie : TTY=pts/4 ; PWD=/usr/local/logcheck-1.1.1/systems/linu x ; USER=root ; COMMAND=/bin/more logcheck.sh Nov 24 22:09:41 magnolia sendmail[7547]: gAP39fku007546: forward /home/barrie/.forward: Group wr itable file ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# [root@magnolia logcheck-1.1.1]# e [root@magnolia logcheck-1.1.1]# e [root@magnolia logcheck-1.1.1]# ex [root@magnolia logcheck-1.1.1]# ex [root@magnolia logcheck-1.1.1]# exi [root@magnolia logcheck-1.1.1]# exi [root@magnolia logcheck-1.1.1]# exit [root@magnolia logcheck-1.1.1]# exit exit ]0;barrie@magnolia:/usr/local/logcheck-1.1.1 [barrie@magnolia logcheck-1.1.1]$ [barrie@magnolia logcheck-1.1.1]$ Script done on Sun Nov 24 22:55:31 2002