Advertisement
Guest User

Untitled

a guest
Nov 29th, 2017
78
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 66.88 KB | None | 0 0
  1. Nov 26 14:54:13 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/sbin/hdparm -Tt /dev/sda
  2. Nov 26 14:54:13 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  3. Nov 26 14:54:26 mscd sudo: pam_unix(sudo:session): session closed for user root
  4. Nov 26 14:56:39 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  5. Nov 26 14:56:39 mscd pkexec[9911]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  6. Nov 26 15:00:11 mscd polkitd(authority=local): Operator of unix-session:c17 successfully authenticated as unix-user:mscd to gain TEMPORARY authorization for action org.freedesktop.udisks2.open-device-system for system-bus-name::1.145 [gnome-disks] (owned by unix-user:mscd)
  7. Nov 26 15:14:08 mscd polkitd(authority=local): message repeated 2 times: [ Operator of unix-session:c17 successfully authenticated as unix-user:mscd to gain TEMPORARY authorization for action org.freedesktop.udisks2.open-device-system for system-bus-name::1.145 [gnome-disks] (owned by unix-user:mscd)]
  8. Nov 26 15:16:49 mscd polkitd(authority=local): Operator of unix-session:c17 successfully authenticated as unix-user:mscd to gain TEMPORARY authorization for action org.freedesktop.udisks2.filesystem-unmount-others for system-bus-name::1.145 [gnome-disks] (owned by unix-user:mscd)
  9. Nov 26 15:17:01 mscd CRON[14320]: pam_unix(cron:session): session opened for user root by (uid=0)
  10. Nov 26 15:17:01 mscd CRON[14320]: pam_unix(cron:session): session closed for user root
  11. Nov 26 15:20:15 mscd polkitd(authority=local): Operator of unix-session:c17 successfully authenticated as unix-user:mscd to gain TEMPORARY authorization for action org.freedesktop.udisks2.open-device-system for system-bus-name::1.145 [gnome-disks] (owned by unix-user:mscd)
  12. Nov 26 15:21:45 mscd polkitd(authority=local): Operator of unix-session:c17 successfully authenticated as unix-user:mscd to gain TEMPORARY authorization for action org.freedesktop.udisks2.open-device-system for system-bus-name::1.156 [gnome-disks] (owned by unix-user:mscd)
  13. Nov 26 15:28:59 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install openssh-server
  14. Nov 26 15:28:59 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  15. Nov 26 15:31:24 mscd useradd[17860]: new user: name=sshd, UID=117, GID=65534, home=/var/run/sshd, shell=/usr/sbin/nologin
  16. Nov 26 15:31:24 mscd usermod[17865]: change user 'sshd' password
  17. Nov 26 15:31:24 mscd chage[17870]: changed password expiry for sshd
  18. Nov 26 15:31:25 mscd sshd[17925]: Server listening on 0.0.0.0 port 22.
  19. Nov 26 15:31:25 mscd sshd[17925]: Server listening on :: port 22.
  20. Nov 26 15:31:25 mscd sudo: pam_unix(sudo:session): session closed for user root
  21. Nov 26 15:32:39 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  22. Nov 26 15:32:39 mscd pkexec[18226]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  23. Nov 26 15:33:35 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install gcc
  24. Nov 26 15:33:35 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  25. Nov 26 15:33:35 mscd sudo: pam_unix(sudo:session): session closed for user root
  26. Nov 26 16:07:02 mscd sudo: pam_unix(sudo:auth): authentication failure; logname=mscd uid=1001 euid=0 tty=/dev/pts/0 ruser=mscd rhost= user=mscd
  27. Nov 26 16:07:07 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get update
  28. Nov 26 16:07:07 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  29. Nov 26 16:07:49 mscd sudo: pam_unix(sudo:session): session closed for user root
  30. Nov 26 16:07:54 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get update
  31. Nov 26 16:07:54 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  32. Nov 26 16:08:36 mscd sudo: pam_unix(sudo:session): session closed for user root
  33. Nov 26 16:09:10 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get update
  34. Nov 26 16:09:10 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  35. Nov 26 16:09:52 mscd sudo: pam_unix(sudo:session): session closed for user root
  36. Nov 26 16:09:55 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get update
  37. Nov 26 16:09:55 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  38. Nov 26 16:10:37 mscd sudo: pam_unix(sudo:session): session closed for user root
  39. Nov 26 16:12:00 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get update
  40. Nov 26 16:12:00 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  41. Nov 26 16:12:42 mscd sudo: pam_unix(sudo:session): session closed for user root
  42. Nov 26 16:13:36 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get update
  43. Nov 26 16:13:36 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  44. Nov 26 16:14:18 mscd sudo: pam_unix(sudo:session): session closed for user root
  45. Nov 26 16:17:01 mscd CRON[26327]: pam_unix(cron:session): session opened for user root by (uid=0)
  46. Nov 26 16:17:01 mscd CRON[26327]: pam_unix(cron:session): session closed for user root
  47. Nov 26 16:21:41 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get update
  48. Nov 26 16:21:41 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  49. Nov 26 16:22:24 mscd sudo: pam_unix(sudo:session): session closed for user root
  50. Nov 26 16:24:37 mscd dbus[998]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.109" (uid=0 pid=3179 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.35" (uid=0 pid=1546 comm="NetworkManager ")
  51. Nov 26 16:24:43 mscd dbus[998]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.109" (uid=0 pid=3179 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.35" (uid=0 pid=1546 comm="NetworkManager ")
  52. Nov 26 16:35:39 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  53. Nov 26 16:35:39 mscd pkexec[29858]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  54. Nov 26 17:17:01 mscd CRON[37313]: pam_unix(cron:session): session opened for user root by (uid=0)
  55. Nov 26 17:17:01 mscd CRON[37313]: pam_unix(cron:session): session closed for user root
  56. Nov 26 18:17:01 mscd CRON[48199]: pam_unix(cron:session): session opened for user root by (uid=0)
  57. Nov 26 18:17:01 mscd CRON[48199]: pam_unix(cron:session): session closed for user root
  58. Nov 26 18:32:22 mscd polkitd(authority=local): Operator of unix-session:c17 successfully authenticated as unix-user:mscd to gain TEMPORARY authorization for action org.freedesktop.udisks2.open-device-system for system-bus-name::1.180 [gnome-disks] (owned by unix-user:mscd)
  59. Nov 26 18:34:42 mscd polkitd(authority=local): Unregistered Authentication Agent for unix-session:c17 (system bus name :1.99, object path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8) (disconnected from bus)
  60. Nov 27 12:00:35 mscd su[1431]: Successful su for root by root
  61. Nov 27 12:00:35 mscd su[1431]: + ??? root:root
  62. Nov 27 12:00:35 mscd su[1431]: pam_unix(su:session): session opened for user root by (uid=0)
  63. Nov 27 12:00:35 mscd su[1385]: Successful su for root by root
  64. Nov 27 12:00:35 mscd su[1385]: + ??? root:root
  65. Nov 27 12:00:35 mscd su[1385]: pam_unix(su:session): session opened for user root by (uid=0)
  66. Nov 27 12:00:35 mscd su[1441]: Successful su for root by root
  67. Nov 27 12:00:35 mscd su[1431]: pam_unix(su:session): session closed for user root
  68. Nov 27 12:00:35 mscd su[1441]: + ??? root:root
  69. Nov 27 12:00:35 mscd su[1441]: pam_unix(su:session): session opened for user root by (uid=0)
  70. Nov 27 12:00:35 mscd su[1385]: pam_unix(su:session): session closed for user root
  71. Nov 27 12:00:35 mscd su[1441]: pam_unix(su:session): session closed for user root
  72. Nov 27 12:00:35 mscd su[1446]: Successful su for root by root
  73. Nov 27 12:00:35 mscd su[1446]: + ??? root:root
  74. Nov 27 12:00:35 mscd su[1446]: pam_unix(su:session): session opened for user root by (uid=0)
  75. Nov 27 12:00:35 mscd su[1450]: Successful su for root by root
  76. Nov 27 12:00:35 mscd su[1450]: + ??? root:root
  77. Nov 27 12:00:35 mscd su[1449]: Successful su for root by root
  78. Nov 27 12:00:35 mscd su[1450]: pam_unix(su:session): session opened for user root by (uid=0)
  79. Nov 27 12:00:35 mscd su[1449]: + ??? root:root
  80. Nov 27 12:00:35 mscd su[1449]: pam_unix(su:session): session opened for user root by (uid=0)
  81. Nov 27 12:00:35 mscd su[1446]: pam_unix(su:session): session closed for user root
  82. Nov 27 12:00:35 mscd su[1449]: pam_unix(su:session): session closed for user root
  83. Nov 27 12:00:35 mscd su[1450]: pam_unix(su:session): session closed for user root
  84. Nov 27 12:00:35 mscd su[1457]: Successful su for root by root
  85. Nov 27 12:00:35 mscd su[1457]: + ??? root:root
  86. Nov 27 12:00:35 mscd su[1457]: pam_unix(su:session): session opened for user root by (uid=0)
  87. Nov 27 12:00:35 mscd su[1464]: Successful su for root by root
  88. Nov 27 12:00:35 mscd su[1464]: + ??? root:root
  89. Nov 27 12:00:35 mscd su[1467]: Successful su for root by root
  90. Nov 27 12:00:35 mscd su[1467]: + ??? root:root
  91. Nov 27 12:00:35 mscd su[1464]: pam_unix(su:session): session opened for user root by (uid=0)
  92. Nov 27 12:00:35 mscd su[1467]: pam_unix(su:session): session opened for user root by (uid=0)
  93. Nov 27 12:00:35 mscd su[1457]: pam_unix(su:session): session closed for user root
  94. Nov 27 12:00:35 mscd su[1464]: pam_unix(su:session): session closed for user root
  95. Nov 27 12:00:35 mscd su[1467]: pam_unix(su:session): session closed for user root
  96. Nov 27 12:00:35 mscd su[1481]: Successful su for root by root
  97. Nov 27 12:00:35 mscd su[1481]: + ??? root:root
  98. Nov 27 12:00:35 mscd su[1481]: pam_unix(su:session): session opened for user root by (uid=0)
  99. Nov 27 12:00:35 mscd su[1487]: Successful su for root by root
  100. Nov 27 12:00:35 mscd su[1487]: + ??? root:root
  101. Nov 27 12:00:35 mscd su[1486]: Successful su for root by root
  102. Nov 27 12:00:35 mscd su[1486]: + ??? root:root
  103. Nov 27 12:00:35 mscd su[1486]: pam_unix(su:session): session opened for user root by (uid=0)
  104. Nov 27 12:00:35 mscd su[1487]: pam_unix(su:session): session opened for user root by (uid=0)
  105. Nov 27 12:00:35 mscd su[1481]: pam_unix(su:session): session closed for user root
  106. Nov 27 12:00:35 mscd su[1486]: pam_unix(su:session): session closed for user root
  107. Nov 27 12:00:35 mscd su[1487]: pam_unix(su:session): session closed for user root
  108. Nov 27 12:00:35 mscd su[1534]: Successful su for root by root
  109. Nov 27 12:00:35 mscd su[1534]: + ??? root:root
  110. Nov 27 12:00:35 mscd su[1534]: pam_unix(su:session): session opened for user root by (uid=0)
  111. Nov 27 12:00:35 mscd su[1542]: Successful su for root by root
  112. Nov 27 12:00:35 mscd su[1542]: + ??? root:root
  113. Nov 27 12:00:35 mscd su[1542]: pam_unix(su:session): session opened for user root by (uid=0)
  114. Nov 27 12:00:35 mscd su[1542]: pam_unix(su:session): session closed for user root
  115. Nov 27 12:00:35 mscd su[1534]: pam_unix(su:session): session closed for user root
  116. Nov 27 12:00:35 mscd sshd[1743]: Server listening on 0.0.0.0 port 22.
  117. Nov 27 12:00:35 mscd sshd[1743]: Server listening on :: port 22.
  118. Nov 27 12:00:36 mscd su[2013]: Successful su for root by root
  119. Nov 27 12:00:36 mscd su[2013]: + ??? root:root
  120. Nov 27 12:00:36 mscd su[2013]: pam_unix(su:session): session opened for user root by (uid=0)
  121. Nov 27 12:00:36 mscd su[2013]: pam_unix(su:session): session closed for user root
  122. Nov 27 12:00:36 mscd lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
  123. Nov 27 12:00:36 mscd lightdm: PAM adding faulty module: pam_kwallet.so
  124. Nov 27 12:00:36 mscd lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm by (uid=0)
  125. Nov 27 12:00:36 mscd lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
  126. Nov 27 12:00:36 mscd lightdm: PAM adding faulty module: pam_kwallet.so
  127. Nov 27 12:00:36 mscd lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "mscd"
  128. Nov 27 12:00:47 mscd dbus[980]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.76" (uid=0 pid=2598 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1571 comm="NetworkManager ")
  129. Nov 27 12:00:48 mscd lightdm: pam_unix(lightdm-greeter:session): session closed for user lightdm
  130. Nov 27 12:00:48 mscd lightdm: pam_unix(lightdm:session): session opened for user mscd by (uid=0)
  131. Nov 27 12:00:49 mscd polkitd(authority=local): Registered Authentication Agent for unix-session:c17 (system bus name :1.105 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8)
  132. Nov 27 12:01:52 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  133. Nov 27 12:01:52 mscd pkexec[3639]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  134. Nov 27 12:17:01 mscd CRON[6767]: pam_unix(cron:session): session opened for user root by (uid=0)
  135. Nov 27 12:17:01 mscd CRON[6767]: pam_unix(cron:session): session closed for user root
  136. Nov 27 12:28:54 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  137. Nov 27 12:28:54 mscd pkexec[8908]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  138. Nov 27 12:29:29 mscd dbus[980]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.76" (uid=0 pid=2598 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1571 comm="NetworkManager ")
  139. Nov 27 12:29:31 mscd gnome-keyring-daemon[2747]: keyring alias directory: /home/mscd/.local/share/keyrings
  140. Nov 27 12:29:53 mscd dbus[980]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.76" (uid=0 pid=2598 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1571 comm="NetworkManager ")
  141. Nov 27 12:52:11 mscd dbus[980]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.76" (uid=0 pid=2598 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1571 comm="NetworkManager ")
  142. Nov 27 12:53:13 mscd dbus[980]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.76" (uid=0 pid=2598 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1571 comm="NetworkManager ")
  143. Nov 27 13:17:01 mscd CRON[18136]: pam_unix(cron:session): session opened for user root by (uid=0)
  144. Nov 27 13:17:01 mscd CRON[18136]: pam_unix(cron:session): session closed for user root
  145. Nov 27 13:34:37 mscd dbus[980]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.76" (uid=0 pid=2598 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1571 comm="NetworkManager ")
  146. Nov 27 13:36:25 mscd dbus[980]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.76" (uid=0 pid=2598 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1571 comm="NetworkManager ")
  147. Nov 27 13:54:30 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install htop
  148. Nov 27 13:54:30 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  149. Nov 27 13:55:12 mscd sudo: pam_unix(sudo:session): session closed for user root
  150. Nov 27 13:55:19 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install htop
  151. Nov 27 13:55:19 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  152. Nov 27 13:56:00 mscd sudo: pam_unix(sudo:session): session closed for user root
  153. Nov 27 13:59:52 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install --fix-missing
  154. Nov 27 13:59:52 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  155. Nov 27 13:59:53 mscd sudo: pam_unix(sudo:session): session closed for user root
  156. Nov 27 14:17:01 mscd CRON[29217]: pam_unix(cron:session): session opened for user root by (uid=0)
  157. Nov 27 14:17:01 mscd CRON[29217]: pam_unix(cron:session): session closed for user root
  158. Nov 27 14:32:42 mscd dbus[980]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.76" (uid=0 pid=2598 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1571 comm="NetworkManager ")
  159. Nov 27 14:34:29 mscd dbus[980]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.76" (uid=0 pid=2598 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1571 comm="NetworkManager ")
  160. Nov 27 15:17:01 mscd CRON[40332]: pam_unix(cron:session): session opened for user root by (uid=0)
  161. Nov 27 15:17:01 mscd CRON[40332]: pam_unix(cron:session): session closed for user root
  162. Nov 27 15:49:39 mscd dbus[980]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.76" (uid=0 pid=2598 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1571 comm="NetworkManager ")
  163. Nov 27 15:50:00 mscd dbus[980]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.76" (uid=0 pid=2598 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1571 comm="NetworkManager ")
  164. Nov 27 16:17:01 mscd CRON[51514]: pam_unix(cron:session): session opened for user root by (uid=0)
  165. Nov 27 16:17:01 mscd CRON[51514]: pam_unix(cron:session): session closed for user root
  166. Nov 27 17:14:45 mscd sudo: mscd : TTY=pts/2 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install bmon
  167. Nov 27 17:14:45 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  168. Nov 27 17:14:53 mscd sudo: pam_unix(sudo:session): session closed for user root
  169. Nov 27 17:15:04 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install iotop
  170. Nov 27 17:15:04 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  171. Nov 27 17:15:06 mscd sudo: pam_unix(sudo:session): session closed for user root
  172. Nov 27 17:15:18 mscd sudo: mscd : TTY=pts/2 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install htop
  173. Nov 27 17:15:18 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  174. Nov 27 17:15:24 mscd sudo: pam_unix(sudo:session): session closed for user root
  175. Nov 27 17:15:31 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/sbin/iotop
  176. Nov 27 17:15:31 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  177. Nov 27 17:15:33 mscd sudo: pam_unix(sudo:session): session closed for user root
  178. Nov 27 17:16:51 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  179. Nov 27 17:16:51 mscd pkexec[64611]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  180. Nov 27 17:17:01 mscd CRON[64672]: pam_unix(cron:session): session opened for user root by (uid=0)
  181. Nov 27 17:17:01 mscd CRON[64672]: pam_unix(cron:session): session closed for user root
  182. Nov 27 17:20:28 mscd sudo: mscd : TTY=pts/2 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/sbin/iotop
  183. Nov 27 17:20:28 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  184. Nov 27 18:17:01 mscd CRON[76667]: pam_unix(cron:session): session opened for user root by (uid=0)
  185. Nov 27 18:17:01 mscd CRON[76667]: pam_unix(cron:session): session closed for user root
  186. Nov 27 18:32:36 mscd sudo: pam_unix(sudo:session): session closed for user root
  187. Nov 27 18:32:39 mscd polkitd(authority=local): Unregistered Authentication Agent for unix-session:c17 (system bus name :1.105, object path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8) (disconnected from bus)
  188. Nov 29 11:47:34 mscd su[1418]: Successful su for root by root
  189. Nov 29 11:47:34 mscd su[1419]: Successful su for root by root
  190. Nov 29 11:47:34 mscd su[1419]: + ??? root:root
  191. Nov 29 11:47:34 mscd su[1418]: + ??? root:root
  192. Nov 29 11:47:34 mscd su[1417]: Successful su for root by root
  193. Nov 29 11:47:34 mscd su[1418]: pam_unix(su:session): session opened for user root by (uid=0)
  194. Nov 29 11:47:34 mscd su[1419]: pam_unix(su:session): session opened for user root by (uid=0)
  195. Nov 29 11:47:34 mscd su[1417]: + ??? root:root
  196. Nov 29 11:47:34 mscd su[1417]: pam_unix(su:session): session opened for user root by (uid=0)
  197. Nov 29 11:47:34 mscd su[1419]: pam_unix(su:session): session closed for user root
  198. Nov 29 11:47:34 mscd su[1418]: pam_unix(su:session): session closed for user root
  199. Nov 29 11:47:34 mscd su[1417]: pam_unix(su:session): session closed for user root
  200. Nov 29 11:47:34 mscd su[1450]: Successful su for root by root
  201. Nov 29 11:47:34 mscd su[1449]: Successful su for root by root
  202. Nov 29 11:47:34 mscd su[1450]: + ??? root:root
  203. Nov 29 11:47:34 mscd su[1449]: + ??? root:root
  204. Nov 29 11:47:34 mscd su[1450]: pam_unix(su:session): session opened for user root by (uid=0)
  205. Nov 29 11:47:34 mscd su[1449]: pam_unix(su:session): session opened for user root by (uid=0)
  206. Nov 29 11:47:34 mscd su[1454]: Successful su for root by root
  207. Nov 29 11:47:34 mscd su[1454]: + ??? root:root
  208. Nov 29 11:47:34 mscd su[1454]: pam_unix(su:session): session opened for user root by (uid=0)
  209. Nov 29 11:47:34 mscd su[1450]: pam_unix(su:session): session closed for user root
  210. Nov 29 11:47:34 mscd su[1454]: pam_unix(su:session): session closed for user root
  211. Nov 29 11:47:34 mscd su[1449]: pam_unix(su:session): session closed for user root
  212. Nov 29 11:47:34 mscd su[1466]: Successful su for root by root
  213. Nov 29 11:47:34 mscd su[1466]: + ??? root:root
  214. Nov 29 11:47:34 mscd su[1466]: pam_unix(su:session): session opened for user root by (uid=0)
  215. Nov 29 11:47:34 mscd su[1468]: Successful su for root by root
  216. Nov 29 11:47:34 mscd su[1468]: + ??? root:root
  217. Nov 29 11:47:34 mscd su[1467]: Successful su for root by root
  218. Nov 29 11:47:34 mscd su[1467]: + ??? root:root
  219. Nov 29 11:47:34 mscd su[1468]: pam_unix(su:session): session opened for user root by (uid=0)
  220. Nov 29 11:47:34 mscd su[1467]: pam_unix(su:session): session opened for user root by (uid=0)
  221. Nov 29 11:47:34 mscd su[1466]: pam_unix(su:session): session closed for user root
  222. Nov 29 11:47:34 mscd su[1468]: pam_unix(su:session): session closed for user root
  223. Nov 29 11:47:34 mscd su[1467]: pam_unix(su:session): session closed for user root
  224. Nov 29 11:47:34 mscd su[1476]: Successful su for root by root
  225. Nov 29 11:47:34 mscd su[1476]: + ??? root:root
  226. Nov 29 11:47:34 mscd su[1476]: pam_unix(su:session): session opened for user root by (uid=0)
  227. Nov 29 11:47:34 mscd su[1479]: Successful su for root by root
  228. Nov 29 11:47:34 mscd su[1479]: + ??? root:root
  229. Nov 29 11:47:34 mscd su[1477]: Successful su for root by root
  230. Nov 29 11:47:34 mscd su[1477]: + ??? root:root
  231. Nov 29 11:47:34 mscd su[1479]: pam_unix(su:session): session opened for user root by (uid=0)
  232. Nov 29 11:47:34 mscd su[1477]: pam_unix(su:session): session opened for user root by (uid=0)
  233. Nov 29 11:47:34 mscd su[1476]: pam_unix(su:session): session closed for user root
  234. Nov 29 11:47:34 mscd su[1479]: pam_unix(su:session): session closed for user root
  235. Nov 29 11:47:34 mscd su[1477]: pam_unix(su:session): session closed for user root
  236. Nov 29 11:47:34 mscd su[1526]: Successful su for root by root
  237. Nov 29 11:47:34 mscd su[1526]: + ??? root:root
  238. Nov 29 11:47:34 mscd su[1526]: pam_unix(su:session): session opened for user root by (uid=0)
  239. Nov 29 11:47:34 mscd su[1529]: Successful su for root by root
  240. Nov 29 11:47:34 mscd su[1529]: + ??? root:root
  241. Nov 29 11:47:34 mscd su[1529]: pam_unix(su:session): session opened for user root by (uid=0)
  242. Nov 29 11:47:34 mscd su[1526]: pam_unix(su:session): session closed for user root
  243. Nov 29 11:47:34 mscd su[1529]: pam_unix(su:session): session closed for user root
  244. Nov 29 11:47:34 mscd sshd[1753]: Server listening on 0.0.0.0 port 22.
  245. Nov 29 11:47:34 mscd sshd[1753]: Server listening on :: port 22.
  246. Nov 29 11:47:35 mscd su[2032]: Successful su for root by root
  247. Nov 29 11:47:35 mscd su[2032]: + ??? root:root
  248. Nov 29 11:47:35 mscd su[2032]: pam_unix(su:session): session opened for user root by (uid=0)
  249. Nov 29 11:47:35 mscd su[2032]: pam_unix(su:session): session closed for user root
  250. Nov 29 11:47:35 mscd lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
  251. Nov 29 11:47:35 mscd lightdm: PAM adding faulty module: pam_kwallet.so
  252. Nov 29 11:47:35 mscd lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm by (uid=0)
  253. Nov 29 11:47:35 mscd lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
  254. Nov 29 11:47:35 mscd lightdm: PAM adding faulty module: pam_kwallet.so
  255. Nov 29 11:47:35 mscd lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "mscd"
  256. Nov 29 11:47:42 mscd lightdm: pam_unix(lightdm-greeter:session): session closed for user lightdm
  257. Nov 29 11:47:42 mscd lightdm: pam_unix(lightdm:session): session opened for user mscd by (uid=0)
  258. Nov 29 11:47:42 mscd polkitd(authority=local): Registered Authentication Agent for unix-session:c17 (system bus name :1.96 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8)
  259. Nov 29 11:48:07 mscd dbus[945]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.105" (uid=0 pid=3298 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.33" (uid=0 pid=1566 comm="NetworkManager ")
  260. Nov 29 11:48:45 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  261. Nov 29 11:48:45 mscd pkexec[3731]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  262. Nov 29 12:11:46 mscd dbus[945]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.105" (uid=0 pid=3298 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.33" (uid=0 pid=1566 comm="NetworkManager ")
  263. Nov 29 12:12:23 mscd gnome-keyring-daemon[2627]: keyring alias directory: /home/mscd/.local/share/keyrings
  264. Nov 29 12:12:36 mscd dbus[945]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.105" (uid=0 pid=3298 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.33" (uid=0 pid=1566 comm="NetworkManager ")
  265. Nov 29 12:14:52 mscd polkitd(authority=local): Unregistered Authentication Agent for unix-session:c17 (system bus name :1.96, object path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8) (disconnected from bus)
  266. Nov 29 12:14:57 mscd lightdm: pam_unix(lightdm:session): session closed for user mscd
  267. Nov 29 12:14:57 mscd lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
  268. Nov 29 12:14:57 mscd lightdm: PAM adding faulty module: pam_kwallet.so
  269. Nov 29 12:14:57 mscd lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm by (uid=0)
  270. Nov 29 12:14:57 mscd lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
  271. Nov 29 12:14:57 mscd lightdm: PAM adding faulty module: pam_kwallet.so
  272. Nov 29 12:14:57 mscd lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "mscd"
  273. Nov 29 12:15:02 mscd lightdm: pam_unix(lightdm-greeter:session): session closed for user lightdm
  274. Nov 29 12:15:02 mscd lightdm: pam_unix(lightdm:session): session opened for user mscd by (uid=0)
  275. Nov 29 12:15:02 mscd polkitd(authority=local): Registered Authentication Agent for unix-session:c19 (system bus name :1.175 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8)
  276. Nov 29 12:16:05 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  277. Nov 29 12:16:05 mscd pkexec[10976]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  278. Nov 29 12:17:01 mscd CRON[11348]: pam_unix(cron:session): session opened for user root by (uid=0)
  279. Nov 29 12:17:01 mscd CRON[11348]: pam_unix(cron:session): session closed for user root
  280. Nov 29 12:19:11 mscd gnome-keyring-daemon[10082]: keyring alias directory: /home/mscd/.local/share/keyrings
  281. Nov 29 12:28:10 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install iperf
  282. Nov 29 12:28:10 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  283. Nov 29 12:28:29 mscd sudo: pam_unix(sudo:session): session closed for user root
  284. Nov 29 12:31:04 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  285. Nov 29 12:31:04 mscd pkexec[14558]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  286. Nov 29 12:31:05 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/gedit /etc/hosts
  287. Nov 29 12:31:05 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  288. Nov 29 12:31:35 mscd sudo: pam_unix(sudo:session): session closed for user root
  289. Nov 29 12:45:03 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install iftop
  290. Nov 29 12:45:03 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  291. Nov 29 12:45:26 mscd sudo: pam_unix(sudo:session): session closed for user root
  292. Nov 29 12:45:34 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/sbin/iftop
  293. Nov 29 12:45:34 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  294. Nov 29 12:45:53 mscd sudo: pam_unix(sudo:session): session closed for user root
  295. Nov 29 12:45:58 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/sbin/iftop
  296. Nov 29 12:45:58 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  297. Nov 29 12:46:02 mscd sudo: pam_unix(sudo:session): session closed for user root
  298. Nov 29 12:46:04 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  299. Nov 29 12:46:04 mscd pkexec[17942]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  300. Nov 29 12:46:05 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/sbin/iftop
  301. Nov 29 12:46:05 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  302. Nov 29 12:46:08 mscd sudo: pam_unix(sudo:session): session closed for user root
  303. Nov 29 12:46:09 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/sbin/iftop
  304. Nov 29 12:46:09 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  305. Nov 29 12:47:59 mscd sudo: pam_unix(sudo:session): session closed for user root
  306. Nov 29 12:50:12 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/gedit /etc/hosts
  307. Nov 29 12:50:12 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  308. Nov 29 12:50:18 mscd sudo: pam_unix(sudo:session): session closed for user root
  309. Nov 29 12:52:14 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/sbin/iftop
  310. Nov 29 12:52:14 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  311. Nov 29 12:52:15 mscd sudo: pam_unix(sudo:session): session closed for user root
  312. Nov 29 13:08:19 mscd gnome-keyring-daemon[10082]: exponent1 exponent1: no decoded value
  313. Nov 29 13:09:05 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install openssh-server
  314. Nov 29 13:09:05 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  315. Nov 29 13:09:06 mscd sudo: pam_unix(sudo:session): session closed for user root
  316. Nov 29 13:10:36 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install firewall
  317. Nov 29 13:10:36 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  318. Nov 29 13:10:36 mscd sudo: pam_unix(sudo:session): session closed for user root
  319. Nov 29 13:10:42 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install service firewall
  320. Nov 29 13:10:42 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  321. Nov 29 13:10:42 mscd sudo: pam_unix(sudo:session): session closed for user root
  322. Nov 29 13:15:09 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/sbin/iptables
  323. Nov 29 13:15:09 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  324. Nov 29 13:15:09 mscd sudo: pam_unix(sudo:session): session closed for user root
  325. Nov 29 13:17:01 mscd CRON[24110]: pam_unix(cron:session): session opened for user root by (uid=0)
  326. Nov 29 13:17:01 mscd CRON[24110]: pam_unix(cron:session): session closed for user root
  327. Nov 29 13:18:59 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/sbin/iptables
  328. Nov 29 13:18:59 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  329. Nov 29 13:18:59 mscd sudo: pam_unix(sudo:session): session closed for user root
  330. Nov 29 13:19:06 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/sbin/iptables -L
  331. Nov 29 13:19:06 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  332. Nov 29 13:19:06 mscd sudo: pam_unix(sudo:session): session closed for user root
  333. Nov 29 13:19:09 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/sbin/iptables -L
  334. Nov 29 13:19:09 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  335. Nov 29 13:19:09 mscd sudo: pam_unix(sudo:session): session closed for user root
  336. Nov 29 13:22:51 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/sbin/iptables -L
  337. Nov 29 13:22:51 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  338. Nov 29 13:22:51 mscd sudo: pam_unix(sudo:session): session closed for user root
  339. Nov 29 13:22:53 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/sbin/iptables -L
  340. Nov 29 13:22:53 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  341. Nov 29 13:22:53 mscd sudo: pam_unix(sudo:session): session closed for user root
  342. Nov 29 13:23:58 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install nmap
  343. Nov 29 13:23:58 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  344. Nov 29 13:24:38 mscd sudo: pam_unix(sudo:session): session closed for user root
  345. Nov 29 13:25:04 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  346. Nov 29 13:25:04 mscd pkexec[26226]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  347. Nov 29 13:27:44 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/sbin/iptables -L
  348. Nov 29 13:27:44 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  349. Nov 29 13:27:44 mscd sudo: pam_unix(sudo:session): session closed for user root
  350. Nov 29 13:27:59 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/sbin/ufw status
  351. Nov 29 13:27:59 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  352. Nov 29 13:27:59 mscd sudo: pam_unix(sudo:session): session closed for user root
  353. Nov 29 13:31:36 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/sbin/adduser mpiuser
  354. Nov 29 13:31:36 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  355. Nov 29 13:31:36 mscd groupadd[27500]: group added to /etc/group: name=mpiuser, GID=1000
  356. Nov 29 13:31:36 mscd groupadd[27500]: group added to /etc/gshadow: name=mpiuser
  357. Nov 29 13:31:36 mscd groupadd[27500]: new group: name=mpiuser, GID=1000
  358. Nov 29 13:31:36 mscd useradd[27504]: new user: name=mpiuser, UID=1000, GID=1000, home=/home/mpiuser, shell=/bin/bash
  359. Nov 29 13:31:36 mscd passwd[27511]: pam_ecryptfs: PAM passphrase change module retrieved a NULL passphrase; nothing to do
  360. Nov 29 13:31:39 mscd passwd[27511]: pam_unix(passwd:chauthtok): password changed for mpiuser
  361. Nov 29 13:31:39 mscd passwd[27511]: gkr-pam: couldn't update the login keyring password: no old password was entered
  362. Nov 29 13:31:39 mscd passwd[27511]: pam_ecryptfs: Passphrase file wrapped
  363. Nov 29 13:31:39 mscd passwd[27511]: pam_ecryptfs: PAM passphrase change module retrieved at least one NULL passphrase; nothing to do
  364. Nov 29 13:31:41 mscd chfn[27590]: changed user 'mpiuser' information
  365. Nov 29 13:31:43 mscd sudo: pam_unix(sudo:session): session closed for user root
  366. Nov 29 13:31:52 mscd su[27720]: Successful su for mpiuser by mscd
  367. Nov 29 13:31:52 mscd su[27720]: + /dev/pts/10 mscd:mpiuser
  368. Nov 29 13:31:52 mscd su[27720]: pam_unix(su:session): session opened for user mpiuser by mscd(uid=1001)
  369. Nov 29 13:37:31 mscd sudo: mpiuser : user NOT in sudoers ; TTY=pts/10 ; PWD=/home/mpiuser ; USER=root ; COMMAND=/usr/bin/nmap -p22 node2
  370. Nov 29 13:37:36 mscd su[27720]: pam_unix(su:session): session closed for user mpiuser
  371. Nov 29 13:37:53 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/nmap -p22 node2
  372. Nov 29 13:37:53 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  373. Nov 29 13:37:54 mscd sudo: pam_unix(sudo:session): session closed for user root
  374. Nov 29 13:38:36 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/nmap -p0 node2
  375. Nov 29 13:38:36 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  376. Nov 29 13:38:36 mscd sudo: pam_unix(sudo:session): session closed for user root
  377. Nov 29 13:38:41 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/nmap -p0 node0
  378. Nov 29 13:38:41 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  379. Nov 29 13:38:41 mscd sudo: pam_unix(sudo:session): session closed for user root
  380. Nov 29 13:39:02 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/nmap -P0 node0
  381. Nov 29 13:39:02 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  382. Nov 29 13:39:02 mscd sudo: pam_unix(sudo:session): session closed for user root
  383. Nov 29 13:39:08 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/nmap -P0 node2
  384. Nov 29 13:39:08 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  385. Nov 29 13:39:08 mscd sudo: pam_unix(sudo:session): session closed for user root
  386. Nov 29 13:39:13 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/nmap -P0 node2
  387. Nov 29 13:39:13 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  388. Nov 29 13:39:13 mscd sudo: pam_unix(sudo:session): session closed for user root
  389. Nov 29 13:39:28 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get update
  390. Nov 29 13:39:28 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  391. Nov 29 13:41:58 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/gedit /etc/hosts
  392. Nov 29 13:41:58 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  393. Nov 29 13:42:04 mscd sudo: pam_unix(sudo:session): session closed for user root
  394. Nov 29 13:44:55 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/nano etc/NetworkManager/NetworkManager.conf
  395. Nov 29 13:44:55 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  396. Nov 29 13:45:17 mscd sudo: pam_unix(sudo:session): session closed for user root
  397. Nov 29 13:45:25 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/gedit etc/NetworkManager/NetworkManager.conf
  398. Nov 29 13:45:25 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  399. Nov 29 13:46:06 mscd sudo: pam_unix(sudo:session): session closed for user root
  400. Nov 29 13:49:43 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install openssh-server
  401. Nov 29 13:49:43 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  402. Nov 29 13:49:45 mscd sudo: pam_unix(sudo:session): session closed for user root
  403. Nov 29 13:54:55 mscd dbus[945]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.105" (uid=0 pid=3298 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.33" (uid=0 pid=1566 comm="NetworkManager ")
  404. Nov 29 13:55:10 mscd sudo: pam_unix(sudo:session): session closed for user root
  405. Nov 29 13:55:51 mscd dbus[945]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.105" (uid=0 pid=3298 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.33" (uid=0 pid=1566 comm="NetworkManager ")
  406. Nov 29 13:55:55 mscd dbus[945]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.105" (uid=0 pid=3298 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.33" (uid=0 pid=1566 comm="NetworkManager ")
  407. Nov 29 13:57:07 mscd dbus[945]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.105" (uid=0 pid=3298 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.33" (uid=0 pid=1566 comm="NetworkManager ")
  408. Nov 29 13:57:40 mscd sudo: mscd : TTY=pts/10 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get update
  409. Nov 29 13:57:40 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  410. Nov 29 13:58:59 mscd sudo: pam_unix(sudo:session): session closed for user root
  411. Nov 29 14:01:04 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  412. Nov 29 14:01:04 mscd pkexec[33736]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  413. Nov 29 14:01:41 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/bin/ss -lnp
  414. Nov 29 14:01:41 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  415. Nov 29 14:01:41 mscd sudo: pam_unix(sudo:session): session closed for user root
  416. Nov 29 14:02:12 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/bin/ss -lnp
  417. Nov 29 14:02:12 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  418. Nov 29 14:02:12 mscd sudo: pam_unix(sudo:session): session closed for user root
  419. Nov 29 14:03:28 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/bin/ss -lnp
  420. Nov 29 14:03:28 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  421. Nov 29 14:03:28 mscd sudo: pam_unix(sudo:session): session closed for user root
  422. Nov 29 14:04:05 mscd sshd[34266]: Accepted password for mscd from 127.0.0.1 port 41003 ssh2
  423. Nov 29 14:04:05 mscd sshd[34266]: pam_unix(sshd:session): session opened for user mscd by (uid=0)
  424. Nov 29 14:04:51 mscd sshd[34464]: Received disconnect from 127.0.0.1: 11: disconnected by user
  425. Nov 29 14:04:51 mscd sshd[34266]: pam_unix(sshd:session): session closed for user mscd
  426. Nov 29 14:05:29 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/bin/ss -lnp
  427. Nov 29 14:05:29 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  428. Nov 29 14:05:29 mscd sudo: pam_unix(sudo:session): session closed for user root
  429. Nov 29 14:06:07 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/bin/cp /etc/ssh/sshd_config /etc/ssh/sshd_config.factory-defaults
  430. Nov 29 14:06:07 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  431. Nov 29 14:06:07 mscd sudo: pam_unix(sudo:session): session closed for user root
  432. Nov 29 14:06:22 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/bin/chmod a-w /etc/ssh/sshd_config.factory-defaults
  433. Nov 29 14:06:22 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  434. Nov 29 14:06:22 mscd sudo: pam_unix(sudo:session): session closed for user root
  435. Nov 29 14:06:37 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/gedit /etc/ssh/sshd_config
  436. Nov 29 14:06:37 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  437. Nov 29 14:08:09 mscd sudo: pam_unix(sudo:session): session closed for user root
  438. Nov 29 14:08:19 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/sbin/restart ssh
  439. Nov 29 14:08:19 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  440. Nov 29 14:08:19 mscd sshd[1753]: Received signal 15; terminating.
  441. Nov 29 14:08:19 mscd sshd[35356]: Server listening on 0.0.0.0 port 22.
  442. Nov 29 14:08:19 mscd sshd[35356]: Server listening on :: port 22.
  443. Nov 29 14:08:19 mscd sudo: pam_unix(sudo:session): session closed for user root
  444. Nov 29 14:10:16 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/gedit /etc/ssh/sshd_config
  445. Nov 29 14:10:16 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  446. Nov 29 14:10:41 mscd sudo: pam_unix(sudo:session): session closed for user root
  447. Nov 29 14:10:42 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/gedit /etc/ssh/sshd_config
  448. Nov 29 14:10:42 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  449. Nov 29 14:13:10 mscd sudo: pam_unix(sudo:session): session closed for user root
  450. Nov 29 14:13:30 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/sbin/restart sshd
  451. Nov 29 14:13:30 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  452. Nov 29 14:13:30 mscd sudo: pam_unix(sudo:session): session closed for user root
  453. Nov 29 14:13:35 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/sbin/restart ssh
  454. Nov 29 14:13:35 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  455. Nov 29 14:13:35 mscd sshd[35356]: Received signal 15; terminating.
  456. Nov 29 14:13:35 mscd sshd[36375]: Server listening on 0.0.0.0 port 22.
  457. Nov 29 14:13:35 mscd sshd[36375]: Server listening on :: port 22.
  458. Nov 29 14:13:35 mscd sudo: pam_unix(sudo:session): session closed for user root
  459. Nov 29 14:14:18 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/bin/ss -lnp
  460. Nov 29 14:14:18 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  461. Nov 29 14:14:19 mscd sudo: pam_unix(sudo:session): session closed for user root
  462. Nov 29 14:15:25 mscd sshd[36711]: Accepted password for mscd from 127.0.0.1 port 41004 ssh2
  463. Nov 29 14:15:25 mscd sshd[36711]: pam_unix(sshd:session): session opened for user mscd by (uid=0)
  464. Nov 29 14:16:05 mscd sshd[36754]: Received disconnect from 127.0.0.1: 11: disconnected by user
  465. Nov 29 14:16:05 mscd sshd[36711]: pam_unix(sshd:session): session closed for user mscd
  466. Nov 29 14:16:12 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/gedit /etc/ssh/sshd_config
  467. Nov 29 14:16:12 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  468. Nov 29 14:17:01 mscd CRON[37173]: pam_unix(cron:session): session opened for user root by (uid=0)
  469. Nov 29 14:17:01 mscd CRON[37173]: pam_unix(cron:session): session closed for user root
  470. Nov 29 14:18:36 mscd sudo: pam_unix(sudo:session): session closed for user root
  471. Nov 29 14:27:00 mscd sudo: mscd : TTY=pts/14 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/sbin/service ssh restart
  472. Nov 29 14:27:00 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  473. Nov 29 14:27:00 mscd sshd[36375]: Received signal 15; terminating.
  474. Nov 29 14:27:00 mscd sshd[39098]: Server listening on 0.0.0.0 port 22.
  475. Nov 29 14:27:00 mscd sshd[39098]: Server listening on :: port 22.
  476. Nov 29 14:27:00 mscd sudo: pam_unix(sudo:session): session closed for user root
  477. Nov 29 14:34:45 mscd polkitd(authority=local): Unregistered Authentication Agent for unix-session:c19 (system bus name :1.175, object path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8) (disconnected from bus)
  478. Nov 29 14:35:14 mscd su[1384]: Successful su for root by root
  479. Nov 29 14:35:14 mscd su[1384]: + ??? root:root
  480. Nov 29 14:35:14 mscd su[1384]: pam_unix(su:session): session opened for user root by (uid=0)
  481. Nov 29 14:35:14 mscd su[1386]: Successful su for root by root
  482. Nov 29 14:35:14 mscd su[1386]: + ??? root:root
  483. Nov 29 14:35:14 mscd su[1386]: pam_unix(su:session): session opened for user root by (uid=0)
  484. Nov 29 14:35:14 mscd su[1384]: pam_unix(su:session): session closed for user root
  485. Nov 29 14:35:14 mscd su[1386]: pam_unix(su:session): session closed for user root
  486. Nov 29 14:35:14 mscd su[1389]: Successful su for root by root
  487. Nov 29 14:35:14 mscd su[1389]: + ??? root:root
  488. Nov 29 14:35:14 mscd su[1389]: pam_unix(su:session): session opened for user root by (uid=0)
  489. Nov 29 14:35:14 mscd su[1390]: Successful su for root by root
  490. Nov 29 14:35:14 mscd su[1390]: + ??? root:root
  491. Nov 29 14:35:14 mscd su[1391]: Successful su for root by root
  492. Nov 29 14:35:14 mscd su[1391]: + ??? root:root
  493. Nov 29 14:35:14 mscd su[1390]: pam_unix(su:session): session opened for user root by (uid=0)
  494. Nov 29 14:35:14 mscd su[1391]: pam_unix(su:session): session opened for user root by (uid=0)
  495. Nov 29 14:35:14 mscd su[1389]: pam_unix(su:session): session closed for user root
  496. Nov 29 14:35:14 mscd su[1390]: pam_unix(su:session): session closed for user root
  497. Nov 29 14:35:14 mscd su[1391]: pam_unix(su:session): session closed for user root
  498. Nov 29 14:35:14 mscd su[1395]: Successful su for root by root
  499. Nov 29 14:35:14 mscd su[1395]: + ??? root:root
  500. Nov 29 14:35:14 mscd su[1395]: pam_unix(su:session): session opened for user root by (uid=0)
  501. Nov 29 14:35:14 mscd su[1398]: Successful su for root by root
  502. Nov 29 14:35:14 mscd su[1398]: + ??? root:root
  503. Nov 29 14:35:14 mscd su[1397]: Successful su for root by root
  504. Nov 29 14:35:14 mscd su[1397]: + ??? root:root
  505. Nov 29 14:35:14 mscd su[1398]: pam_unix(su:session): session opened for user root by (uid=0)
  506. Nov 29 14:35:14 mscd su[1397]: pam_unix(su:session): session opened for user root by (uid=0)
  507. Nov 29 14:35:14 mscd su[1395]: pam_unix(su:session): session closed for user root
  508. Nov 29 14:35:14 mscd su[1398]: pam_unix(su:session): session closed for user root
  509. Nov 29 14:35:14 mscd su[1397]: pam_unix(su:session): session closed for user root
  510. Nov 29 14:35:14 mscd su[1409]: Successful su for root by root
  511. Nov 29 14:35:14 mscd su[1409]: + ??? root:root
  512. Nov 29 14:35:14 mscd su[1409]: pam_unix(su:session): session opened for user root by (uid=0)
  513. Nov 29 14:35:14 mscd su[1416]: Successful su for root by root
  514. Nov 29 14:35:14 mscd su[1416]: + ??? root:root
  515. Nov 29 14:35:14 mscd su[1416]: pam_unix(su:session): session opened for user root by (uid=0)
  516. Nov 29 14:35:14 mscd su[1409]: pam_unix(su:session): session closed for user root
  517. Nov 29 14:35:14 mscd su[1416]: pam_unix(su:session): session closed for user root
  518. Nov 29 14:35:14 mscd su[1436]: Successful su for root by root
  519. Nov 29 14:35:14 mscd su[1438]: Successful su for root by root
  520. Nov 29 14:35:14 mscd su[1438]: + ??? root:root
  521. Nov 29 14:35:14 mscd su[1436]: + ??? root:root
  522. Nov 29 14:35:14 mscd su[1438]: pam_unix(su:session): session opened for user root by (uid=0)
  523. Nov 29 14:35:14 mscd su[1436]: pam_unix(su:session): session opened for user root by (uid=0)
  524. Nov 29 14:35:14 mscd su[1436]: pam_unix(su:session): session closed for user root
  525. Nov 29 14:35:14 mscd su[1449]: Successful su for root by root
  526. Nov 29 14:35:14 mscd su[1449]: + ??? root:root
  527. Nov 29 14:35:14 mscd su[1438]: pam_unix(su:session): session closed for user root
  528. Nov 29 14:35:14 mscd su[1449]: pam_unix(su:session): session opened for user root by (uid=0)
  529. Nov 29 14:35:14 mscd su[1449]: pam_unix(su:session): session closed for user root
  530. Nov 29 14:35:14 mscd su[1414]: Successful su for root by root
  531. Nov 29 14:35:14 mscd su[1414]: + ??? root:root
  532. Nov 29 14:35:14 mscd su[1414]: pam_unix(su:session): session opened for user root by (uid=0)
  533. Nov 29 14:35:14 mscd su[1414]: pam_unix(su:session): session closed for user root
  534. Nov 29 14:35:14 mscd sshd[1749]: Server listening on 0.0.0.0 port 22.
  535. Nov 29 14:35:14 mscd sshd[1749]: Server listening on :: port 22.
  536. Nov 29 14:35:15 mscd su[2029]: Successful su for root by root
  537. Nov 29 14:35:15 mscd su[2029]: + ??? root:root
  538. Nov 29 14:35:15 mscd su[2029]: pam_unix(su:session): session opened for user root by (uid=0)
  539. Nov 29 14:35:15 mscd su[2029]: pam_unix(su:session): session closed for user root
  540. Nov 29 14:35:15 mscd lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
  541. Nov 29 14:35:15 mscd lightdm: PAM adding faulty module: pam_kwallet.so
  542. Nov 29 14:35:15 mscd lightdm: pam_unix(lightdm-greeter:session): session opened for user lightdm by (uid=0)
  543. Nov 29 14:35:15 mscd lightdm: PAM unable to dlopen(pam_kwallet.so): /lib/security/pam_kwallet.so: cannot open shared object file: No such file or directory
  544. Nov 29 14:35:15 mscd lightdm: PAM adding faulty module: pam_kwallet.so
  545. Nov 29 14:35:15 mscd lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "mscd"
  546. Nov 29 14:35:21 mscd lightdm: pam_unix(lightdm-greeter:session): session closed for user lightdm
  547. Nov 29 14:35:21 mscd lightdm: pam_unix(lightdm:session): session opened for user mscd by (uid=0)
  548. Nov 29 14:35:22 mscd polkitd(authority=local): Registered Authentication Agent for unix-session:c17 (system bus name :1.103 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8)
  549. Nov 29 14:35:30 mscd dbus[915]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.77" (uid=0 pid=2715 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1559 comm="NetworkManager ")
  550. Nov 29 14:36:26 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  551. Nov 29 14:36:26 mscd pkexec[3853]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  552. Nov 29 14:37:04 mscd dbus[915]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.77" (uid=0 pid=2715 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1559 comm="NetworkManager ")
  553. Nov 29 14:37:10 mscd dbus[915]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.77" (uid=0 pid=2715 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1559 comm="NetworkManager ")
  554. Nov 29 14:37:33 mscd sudo: mscd : TTY=pts/2 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/gedit /etc/hosts
  555. Nov 29 14:37:33 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  556. Nov 29 14:37:44 mscd sudo: pam_unix(sudo:session): session closed for user root
  557. Nov 29 14:38:29 mscd sudo: mscd : TTY=pts/2 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/gedit /etc/hosts
  558. Nov 29 14:38:29 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  559. Nov 29 14:38:43 mscd sudo: pam_unix(sudo:session): session closed for user root
  560. Nov 29 14:39:59 mscd sudo: mscd : TTY=pts/2 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/sbin/tcpdump -i any -vvv -s 1600 port 22
  561. Nov 29 14:39:59 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  562. Nov 29 14:40:08 mscd sudo: pam_unix(sudo:session): session closed for user root
  563. Nov 29 14:40:11 mscd sudo: mscd : TTY=pts/2 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/sbin/tcpdump -i any -vvv -s 1600 port 22
  564. Nov 29 14:40:11 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  565. Nov 29 14:40:32 mscd gnome-keyring-daemon[2785]: exponent1 exponent1: no decoded value
  566. Nov 29 14:41:16 mscd sudo: pam_unix(sudo:session): session closed for user root
  567. Nov 29 14:37:18 mscd dbus[915]: message repeated 2 times: [ [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.77" (uid=0 pid=2715 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1559 comm="NetworkManager ")]
  568. Nov 29 14:44:08 mscd dbus[915]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.77" (uid=0 pid=2715 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1559 comm="NetworkManager ")
  569. Nov 29 14:45:01 mscd dbus[915]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.77" (uid=0 pid=2715 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1559 comm="NetworkManager ")
  570. Nov 29 14:45:02 mscd dbus[915]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.77" (uid=0 pid=2715 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1559 comm="NetworkManager ")
  571. Nov 29 14:45:11 mscd dbus[915]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.77" (uid=0 pid=2715 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1559 comm="NetworkManager ")
  572. Nov 29 15:10:37 mscd dbus[915]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.77" (uid=0 pid=2715 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1559 comm="NetworkManager ")
  573. Nov 29 15:17:01 mscd CRON[12221]: pam_unix(cron:session): session opened for user root by (uid=0)
  574. Nov 29 15:17:01 mscd CRON[12221]: pam_unix(cron:session): session closed for user root
  575. Nov 29 15:21:01 mscd dbus[915]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.77" (uid=0 pid=2715 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1559 comm="NetworkManager ")
  576. Nov 29 15:50:27 mscd dbus[915]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.77" (uid=0 pid=2715 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1559 comm="NetworkManager ")
  577. Nov 29 15:52:30 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get purge openssh-server
  578. Nov 29 15:52:30 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  579. Nov 29 15:52:33 mscd sshd[1749]: Received signal 15; terminating.
  580. Nov 29 15:52:34 mscd userdel[19450]: delete user 'sshd'
  581. Nov 29 15:52:34 mscd sudo: pam_unix(sudo:session): session closed for user root
  582. Nov 29 15:53:04 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get purge shh
  583. Nov 29 15:53:04 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  584. Nov 29 15:53:04 mscd sudo: pam_unix(sudo:session): session closed for user root
  585. Nov 29 15:54:11 mscd dbus[915]: [system] Rejected send message, 7 matched rules; type="method_return", sender=":1.77" (uid=0 pid=2715 comm="/usr/sbin/dnsmasq --no-resolv --keep-in-foreground") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.36" (uid=0 pid=1559 comm="NetworkManager ")
  586. Nov 29 15:54:25 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  587. Nov 29 15:54:25 mscd pkexec[20121]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  588. Nov 29 15:54:45 mscd gnome-keyring-daemon[2785]: keyring alias directory: /home/mscd/.local/share/keyrings
  589. Nov 29 15:55:52 mscd sudo: mscd : TTY=pts/2 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/sbin/deluser mpiuser
  590. Nov 29 15:55:52 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  591. Nov 29 15:55:52 mscd userdel[20422]: delete user 'mpiuser'
  592. Nov 29 15:55:52 mscd userdel[20422]: removed group 'mpiuser' owned by 'mpiuser'
  593. Nov 29 15:55:52 mscd userdel[20422]: removed shadow group 'mpiuser' owned by 'mpiuser'
  594. Nov 29 15:55:52 mscd sudo: pam_unix(sudo:session): session closed for user root
  595. Nov 29 15:57:24 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get remove --purge openssh-server
  596. Nov 29 15:57:24 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  597. Nov 29 15:57:25 mscd sudo: pam_unix(sudo:session): session closed for user root
  598. Nov 29 15:57:53 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get autoremove
  599. Nov 29 15:57:53 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  600. Nov 29 15:58:10 mscd sudo: pam_unix(sudo:session): session closed for user root
  601. Nov 29 15:59:57 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get remove ssh
  602. Nov 29 15:59:57 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  603. Nov 29 15:59:58 mscd sudo: pam_unix(sudo:session): session closed for user root
  604. Nov 29 16:00:24 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  605. Nov 29 16:00:24 mscd pkexec[28830]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  606. Nov 29 16:09:56 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get remove ssh
  607. Nov 29 16:09:56 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  608. Nov 29 16:09:57 mscd sudo: pam_unix(sudo:session): session closed for user root
  609. Nov 29 16:10:03 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get remove ssh-keygen
  610. Nov 29 16:10:03 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  611. Nov 29 16:10:03 mscd sudo: pam_unix(sudo:session): session closed for user root
  612. Nov 29 16:11:35 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install openssh-sever
  613. Nov 29 16:11:35 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  614. Nov 29 16:11:35 mscd sudo: pam_unix(sudo:session): session closed for user root
  615. Nov 29 16:11:42 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install openssh-server
  616. Nov 29 16:11:42 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  617. Nov 29 16:11:47 mscd useradd[31658]: new user: name=sshd, UID=117, GID=65534, home=/var/run/sshd, shell=/usr/sbin/nologin
  618. Nov 29 16:11:47 mscd usermod[31663]: change user 'sshd' password
  619. Nov 29 16:11:47 mscd chage[31668]: changed password expiry for sshd
  620. Nov 29 16:11:48 mscd sshd[31723]: Server listening on 0.0.0.0 port 22.
  621. Nov 29 16:11:48 mscd sshd[31723]: Server listening on :: port 22.
  622. Nov 29 16:11:48 mscd sudo: pam_unix(sudo:session): session closed for user root
  623. Nov 29 16:12:11 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install openssh-server
  624. Nov 29 16:12:11 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  625. Nov 29 16:12:11 mscd sudo: pam_unix(sudo:session): session closed for user root
  626. Nov 29 16:12:15 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install openssh-server
  627. Nov 29 16:12:15 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  628. Nov 29 16:12:15 mscd sudo: pam_unix(sudo:session): session closed for user root
  629. Nov 29 16:12:24 mscd pkexec: pam_unix(polkit-1:session): session opened for user root by (uid=1001)
  630. Nov 29 16:12:24 mscd pkexec[31934]: mscd: Executing command [USER=root] [TTY=unknown] [CWD=/home/mscd] [COMMAND=/usr/lib/update-notifier/package-system-locked]
  631. Nov 29 16:13:57 mscd gnome-keyring-daemon[2785]: exponent1 exponent1: no decoded value
  632. Nov 29 16:14:07 mscd sudo: mscd : TTY=pts/0 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/ssh-copy-id node1
  633. Nov 29 16:14:07 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  634. Nov 29 16:14:13 mscd sudo: pam_unix(sudo:session): session closed for user root
  635. Nov 29 16:17:01 mscd CRON[32865]: pam_unix(cron:session): session opened for user root by (uid=0)
  636. Nov 29 16:17:01 mscd CRON[32865]: pam_unix(cron:session): session closed for user root
  637. Nov 29 16:24:54 mscd sudo: mscd : TTY=pts/2 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/apt-get install openssh-server
  638. Nov 29 16:24:54 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
  639. Nov 29 16:24:55 mscd sudo: pam_unix(sudo:session): session closed for user root
  640. Nov 29 16:28:46 mscd sudo: mscd : TTY=pts/2 ; PWD=/home/mscd ; USER=root ; COMMAND=/usr/bin/gedit /var/log/auth.log
  641. Nov 29 16:28:46 mscd sudo: pam_unix(sudo:session): session opened for user root by mscd(uid=0)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement