Advertisement
Guest User

Untitled

a guest
Jun 19th, 2019
136
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 17.41 KB | None | 0 0
  1. sudo tail /var/log/auth.log -n 100
  2.  
  3. May 19 01:02:41 raspberrypi usermod[866]: change user 'pi' password
  4.  
  5. sudo mv /usr/sbin/usermod /usr/sbin/usermod-dell
  6.  
  7. rp@raspberrypi:~ $ sudo tail /var/log/auth.log -n 100
  8. [sudo] password for rp:
  9. May 19 00:19:20 raspberrypi sudo: pam_unix(sudo:session): session closed for use r root
  10. May 19 00:19:31 raspberrypi sudo: rp : TTY=pts/1 ; PWD=/home/rp ; USER=roo t ; COMMAND=/sbin/reboot
  11. May 19 00:19:31 raspberrypi sudo: pam_unix(sudo:session): session opened for use r root by rp(uid=0)
  12. May 19 00:19:38 raspberrypi systemd-logind[478]: New seat seat0.
  13. May 19 00:19:39 raspberrypi sshd[847]: Server listening on 0.0.0.0 port 22.
  14. May 19 00:19:39 raspberrypi sshd[847]: Server listening on :: port 22.
  15. May 19 00:19:39 raspberrypi usermod[824]: change user 'pi' password
  16. May 19 00:19:40 raspberrypi sshd[847]: Received SIGHUP; restarting.
  17. May 19 00:19:41 raspberrypi sshd[847]: Server listening on 0.0.0.0 port 22.
  18. May 19 00:19:41 raspberrypi sshd[847]: Server listening on :: port 22.
  19. May 19 00:19:46 raspberrypi lightdm: pam_unix(lightdm-autologin:session): sessio n opened for user pi by (uid=0)
  20. May 19 00:19:46 raspberrypi systemd-logind[478]: New session c1 of user pi.
  21. May 19 00:19:46 raspberrypi systemd: pam_unix(systemd-user:session): session ope ned for user pi by (uid=0)
  22. May 19 00:19:55 raspberrypi polkitd(authority=local): Registered Authentication Agent for unix-session:c1 (system bus name :1.12 [lxpolkit], object path /org/fr eedesktop/PolicyKit1/AuthenticationAgent, locale en_GB.UTF-8)
  23. May 19 00:22:24 raspberrypi sudo: pi : TTY=pts/0 ; PWD=/home/pi ; USER=roo t ; COMMAND=/usr/local/bin/noip2 -S
  24. May 19 00:22:24 raspberrypi sudo: pam_unix(sudo:session): session opened for use r root by (uid=0)
  25. May 19 00:22:24 raspberrypi sudo: pam_unix(sudo:session): session closed for use r root
  26. May 19 00:22:36 raspberrypi passwd[2138]: pam_unix(passwd:chauthtok): authentica tion failure; logname= uid=1000 euid=0 tty= ruser= rhost= user=pi
  27. May 19 00:22:47 raspberrypi sudo: pi : TTY=pts/0 ; PWD=/home/pi ; USER=roo t ; COMMAND=/usr/bin/passwd pi
  28. May 19 00:22:47 raspberrypi sudo: pam_unix(sudo:session): session opened for use r root by (uid=0)
  29. May 19 00:22:55 raspberrypi passwd[2152]: pam_unix(passwd:chauthtok): password c hanged for pi
  30. May 19 00:22:55 raspberrypi sudo: pam_unix(sudo:session): session closed for use r root
  31. May 19 00:23:11 raspberrypi passwd[2163]: pam_unix(passwd:chauthtok): password c hanged for pi
  32. May 19 00:24:04 raspberrypi passwd[2235]: pam_unix(passwd:chauthtok): authentica tion failure; logname= uid=1000 euid=0 tty= ruser= rhost= user=pi
  33. May 19 00:24:43 raspberrypi passwd[2254]: pam_unix(passwd:chauthtok): password c hanged for pi
  34. May 19 00:24:49 raspberrypi sudo: pi : TTY=pts/0 ; PWD=/home/pi ; USER=roo t ; COMMAND=/sbin/reboot
  35. May 19 00:24:50 raspberrypi sudo: pam_unix(sudo:session): session opened for use r root by (uid=0)
  36. May 19 00:24:57 raspberrypi systemd-logind[477]: New seat seat0.
  37. May 19 00:24:58 raspberrypi sshd[881]: Server listening on 0.0.0.0 port 22.
  38. May 19 00:24:58 raspberrypi sshd[881]: Server listening on :: port 22.
  39. May 19 00:24:58 raspberrypi usermod[861]: change user 'pi' password
  40. May 19 00:25:03 raspberrypi lightdm: pam_unix(lightdm-autologin:session): sessio n opened for user pi by (uid=0)
  41. May 19 00:25:04 raspberrypi systemd-logind[477]: New session c1 of user pi.
  42. May 19 00:25:04 raspberrypi systemd: pam_unix(systemd-user:session): session ope ned for user pi by (uid=0)
  43. May 19 00:25:11 raspberrypi polkitd(authority=local): Registered Authentication Agent for unix-session:c1 (system bus name :1.12 [lxpolkit], object path /org/fr eedesktop/PolicyKit1/AuthenticationAgent, locale en_GB.UTF-8)
  44. May 19 00:26:56 raspberrypi passwd[2064]: pam_unix(passwd:chauthtok): authentica tion failure; logname= uid=1000 euid=0 tty= ruser= rhost= user=pi
  45. May 19 00:27:10 raspberrypi passwd[2068]: pam_unix(passwd:chauthtok): authentica tion failure; logname= uid=1000 euid=0 tty= ruser= rhost= user=pi
  46. May 19 00:39:01 raspberrypi CRON[8534]: pam_unix(cron:session): session opened f or user root by (uid=0)
  47. May 19 00:39:02 raspberrypi CRON[8534]: pam_unix(cron:session): session closed f or user root
  48. May 19 00:44:32 raspberrypi sshd[9696]: pam_unix(sshd:auth): authentication fail ure; logname= uid=0 euid=0 tty=ssh ruser= rhost=192.168.1.155 user=rp
  49. May 19 00:44:34 raspberrypi sshd[9696]: Failed password for rp from 192.168.1.15 5 port 51768 ssh2
  50. May 19 00:44:41 raspberrypi sshd[9696]: Accepted password for rp from 192.168.1. 155 port 51768 ssh2
  51. May 19 00:44:41 raspberrypi sshd[9696]: pam_unix(sshd:session): session opened f or user rp by (uid=0)
  52. May 19 00:44:41 raspberrypi systemd-logind[477]: New session c2 of user rp.
  53. May 19 00:44:41 raspberrypi systemd: pam_unix(systemd-user:session): session ope ned for user rp by (uid=0)
  54. May 19 00:44:57 raspberrypi sudo: pam_unix(sudo:auth): authentication failure; l ogname=rp uid=1003 euid=0 tty=/dev/pts/1 ruser=rp rhost= user=rp
  55. May 19 00:45:03 raspberrypi sudo: rp : TTY=pts/1 ; PWD=/home/rp ; USER=roo t ; COMMAND=/usr/sbin/update-rc.d noip2.sh enable
  56. May 19 00:45:03 raspberrypi sudo: pam_unix(sudo:session): session opened for use r root by rp(uid=0)
  57. May 19 00:45:04 raspberrypi sudo: pam_unix(sudo:session): session closed for use r root
  58. May 19 00:45:36 raspberrypi smbd[10031]: pam_unix(samba:session): session opened for user pi by (uid=0)
  59. May 19 00:46:55 raspberrypi sudo: rp : TTY=pts/1 ; PWD=/home/rp ; USER=roo t ; COMMAND=/usr/local/bin/noip2 -S
  60. May 19 00:46:55 raspberrypi sudo: pam_unix(sudo:session): session opened for use r root by rp(uid=0)
  61. May 19 00:46:55 raspberrypi sudo: pam_unix(sudo:session): session closed for use r root
  62. May 19 00:49:17 raspberrypi sudo: rp : TTY=pts/1 ; PWD=/home/rp ; USER=roo t ; COMMAND=/usr/bin/tail /var/log/auth.log -n 100
  63. May 19 00:49:17 raspberrypi sudo: pam_unix(sudo:session): session opened for use r root by rp(uid=0)
  64. May 19 00:49:17 raspberrypi sudo: pam_unix(sudo:session): session closed for use r root
  65. May 19 00:51:24 raspberrypi sudo: rp : TTY=pts/1 ; PWD=/home/rp ; USER=roo t ; COMMAND=/usr/bin/passwd pi
  66. May 19 00:51:24 raspberrypi sudo: pam_unix(sudo:session): session opened for use r root by rp(uid=0)
  67. May 19 00:51:30 raspberrypi passwd[11384]: pam_unix(passwd:chauthtok): password changed for pi
  68. May 19 00:51:30 raspberrypi sudo: pam_unix(sudo:session): session closed for use r root
  69. May 19 00:51:39 raspberrypi sudo: rp : TTY=pts/1 ; PWD=/home/rp ; USER=roo t ; COMMAND=/sbin/reboot
  70. May 19 00:51:39 raspberrypi sudo: pam_unix(sudo:session): session opened for use r root by rp(uid=0)
  71. May 19 00:51:39 raspberrypi sshd[9696]: pam_unix(sshd:session): session closed f or user rp
  72. May 19 00:51:47 raspberrypi systemd-logind[475]: New seat seat0.
  73. May 19 00:51:48 raspberrypi sshd[882]: Server listening on 0.0.0.0 port 22.
  74. May 19 00:51:48 raspberrypi sshd[882]: Server listening on :: port 22.
  75. May 19 00:51:48 raspberrypi usermod[859]: change user 'pi' password
  76. May 19 00:51:55 raspberrypi lightdm: pam_unix(lightdm-autologin:session): sessio n opened for user pi by (uid=0)
  77. May 19 00:51:55 raspberrypi systemd-logind[475]: New session c1 of user pi.
  78. May 19 00:51:55 raspberrypi systemd: pam_unix(systemd-user:session): session ope ned for user pi by (uid=0)
  79. May 19 00:52:01 raspberrypi polkitd(authority=local): Registered Authentication Agent for unix-session:c1 (system bus name :1.12 [lxpolkit], object path /org/fr eedesktop/PolicyKit1/AuthenticationAgent, locale en_GB.UTF-8)
  80. May 19 00:54:58 raspberrypi sshd[2091]: Accepted password for rp from 192.168.1. 155 port 51869 ssh2
  81. May 19 00:54:58 raspberrypi sshd[2091]: pam_unix(sshd:session): session opened f or user rp by (uid=0)
  82. May 19 00:54:58 raspberrypi systemd-logind[475]: New session c2 of user rp.
  83. May 19 00:54:58 raspberrypi systemd: pam_unix(systemd-user:session): session ope ned for user rp by (uid=0)
  84. May 19 00:55:08 raspberrypi sudo: rp : TTY=pts/0 ; PWD=/home/rp ; USER=roo t ; COMMAND=/usr/bin/tail /var/log/auth.log -n 100
  85. May 19 00:55:08 raspberrypi sudo: pam_unix(sudo:session): session opened for use r root by rp(uid=0)
  86. May 19 00:55:08 raspberrypi sudo: pam_unix(sudo:session): session closed for use r root
  87. May 19 01:02:21 raspberrypi sudo: rp : TTY=pts/0 ; PWD=/home/rp ; USER=roo t ; COMMAND=/usr/local/bin/noip2 -S
  88. May 19 01:02:21 raspberrypi sudo: pam_unix(sudo:session): session opened for use r root by rp(uid=0)
  89. May 19 01:02:21 raspberrypi sudo: pam_unix(sudo:session): session closed for use r root
  90. May 19 01:02:33 raspberrypi sudo: rp : TTY=pts/0 ; PWD=/home/rp ; USER=roo t ; COMMAND=/sbin/reboot
  91. May 19 01:02:33 raspberrypi sudo: pam_unix(sudo:session): session opened for use r root by rp(uid=0)
  92. May 19 01:02:33 raspberrypi sshd[2091]: pam_unix(sshd:session): session closed f or user rp
  93. May 19 01:02:33 raspberrypi sudo: pam_unix(sudo:session): session closed for use r root
  94. May 19 01:02:33 raspberrypi polkitd(authority=local): Unregistered Authenticatio n Agent for unix-session:c1 (system bus name :1.12, object path /org/freedesktop /PolicyKit1/AuthenticationAgent, locale en_GB.UTF-8) (disconnected from bus)
  95. May 19 01:02:40 raspberrypi systemd-logind[480]: New seat seat0.
  96. May 19 01:02:41 raspberrypi sshd[879]: Server listening on 0.0.0.0 port 22.
  97. May 19 01:02:41 raspberrypi sshd[879]: Server listening on :: port 22.
  98. May 19 01:02:41 raspberrypi usermod[866]: change user 'pi' password
  99. May 19 01:02:47 raspberrypi lightdm: pam_unix(lightdm-autologin:session): sessio n opened for user pi by (uid=0)
  100. May 19 01:02:47 raspberrypi systemd-logind[480]: New session c1 of user pi.
  101. May 19 01:02:47 raspberrypi systemd: pam_unix(systemd-user:session): session ope ned for user pi by (uid=0)
  102. May 19 01:02:53 raspberrypi polkitd(authority=local): Registered Authentication Agent for unix-session:c1 (system bus name :1.12 [lxpolkit], object path /org/fr eedesktop/PolicyKit1/AuthenticationAgent, locale en_GB.UTF-8)
  103. May 19 01:04:53 raspberrypi sshd[2010]: Accepted password for rp from 192.168.1. 155 port 51907 ssh2
  104. May 19 01:04:53 raspberrypi sshd[2010]: pam_unix(sshd:session): session opened f or user rp by (uid=0)
  105. May 19 01:04:53 raspberrypi systemd-logind[480]: New session c2 of user rp.
  106. May 19 01:04:53 raspberrypi systemd: pam_unix(systemd-user:session): session ope ned for user rp by (uid=0)
  107. May 19 01:05:01 raspberrypi sudo: rp : TTY=pts/0 ; PWD=/home/rp ; USER=roo t ; COMMAND=/usr/bin/tail /var/log/auth.log -n 100
  108. May 19 01:05:01 raspberrypi sudo: pam_unix(sudo:session): session opened for use
  109.  
  110. #!/bin/bash
  111. (
  112. echo "usermod called at $(date)"
  113. echo "env"
  114. env
  115. echo
  116. echo "command line"
  117. echo "$@"
  118. ) >>/tmp/usermod.log
  119.  
  120. usermod called at Sun 19 May 10:03:01 +07 2019
  121. env
  122. TERM=linux
  123. PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
  124. PWD=/
  125. LANG=en_GB.UTF-8
  126. SHLVL=2
  127. _=/usr/bin/env
  128.  
  129. command line
  130. -p $6$vGkGPKUr$heqvOhUzvbQ66Nb0JGCijh/81sG1WACcZgzPn8A0Wn58hHXWqy5yOgTlYJEbOjhk$
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement