Advertisement
Guest User

sagan_log_example

a guest
Sep 8th, 2019
186
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. [**] [1:5000027] [SU] Successful su as root [**]
  2. [Classification: successful-admin] [Priority: 1] [127.0.0.1]
  3. 2019-07-25 00:16:06 192.168.0.1:514 -> 192.168.0.1:514 authpriv info
  4. Message:  Successful su for root by mestre
  5. [Xref => http://wiki.quadrantsec.com/bin/view/Main/5000027]
  6.  
  7. [**] [1:5000131] [SYSLOG] New user added to the system [**]
  8. [Classification: system-event] [Priority: 2] [127.0.0.1]
  9. 2019-07-25 00:17:01 192.168.0.1:514 -> 192.168.0.1:514 authpriv info
  10. Message:  new user: name=pepecito, UID=1002, GID=1002, home=/home/pepecito, shell=/bin/bash
  11. [Xref => http://wiki.quadrantsec.com/bin/view/Main/5000131]
  12.  
  13. [**] [1:5000377] [SYSLOG] Information for a user was changed [**]
  14. [Classification: system-event] [Priority: 2] [127.0.0.1]
  15. 2019-07-25 00:17:08 192.168.0.1:514 -> 192.168.0.1:514 authpriv info
  16. Message:  changed user 'pepecito' information
  17. [Xref => http://wiki.quadrantsec.com/bin/view/Main/5000377]
  18.  
  19. [**] [1:5000131] [SYSLOG] New user added to the system [**]
  20. [Classification: system-event] [Priority: 2] [127.0.0.1]
  21. 2019-07-25 13:18:45 192.168.0.1:514 -> 192.168.0.1:514 authpriv info
  22. Message:  new user: name=pepecito3, UID=1003, GID=1003, home=/home/pepecito3, shell=/bin/bash
  23. [Xref => http://wiki.quadrantsec.com/bin/view/Main/5000131]
  24.  
  25. [**] [1:5000377] [SYSLOG] Information for a user was changed [**]
  26. [Classification: system-event] [Priority: 2] [127.0.0.1]
  27. 2019-07-25 13:18:52 192.168.0.1:514 -> 192.168.0.1:514 authpriv info
  28. Message:  changed user 'pepecito3' information
  29. [Xref => http://wiki.quadrantsec.com/bin/view/Main/5000377]
  30.  
  31. [**] [1:5000133] [SU] Successful sudo to ROOT executed [**]
  32. [Classification: successful-admin] [Priority: 1] [127.0.0.1]
  33. 2019-07-25 14:37:14 192.168.0.1:514 -> 192.168.0.1:514 authpriv notice
  34. Message:    mestre : TTY=pts/1 ; PWD=/home/mestre ; USER=root ; COMMAND=/usr/sbin/chroot /jaula-sid/
  35. [Xref => http://wiki.quadrantsec.com/bin/view/Main/5000133]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement