[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] Last logins



Hi everyone!

Here's a part of our last logins (last -50 -a):

rides1   pts/2        Thu Jan 18 20:14 - 20:16  (00:02)     <hostname>
trechter pts/2        Thu Jan 18 20:04 - 20:04  (00:00)     <hostname>
trechter pts/2        Thu Jan 18 20:04 - 20:04  (00:00)     <hostname>
rides1   ftp          Wed Jan 17 23:51 - 23:51  (00:00)     <hostname>
rides1   ftp          Wed Jan 17 23:49 - 23:51  (00:02)     <hostname>
superior ftp          Wed Jan 17 23:45 - 23:48  (00:03)     <hostname>
rffr1    ftp          Wed Jan 17 23:44 - 23:45  (00:00)     <hostname>
dierenam ftp          Wed Jan 17 23:36 - 23:38  (00:02)     <hostname>
swhost1  ftp          Wed Jan 17 23:34 - 23:35  (00:00)     <hostname>
swhost1  ftp          Wed Jan 17 23:34 - 23:34  (00:00)     <hostname>

<hostname> is a hostname who is not allowed to access this server. Only we
can access this server. We have SSH1 installed and Telnet disabled.

Can someone explain if this "intruder" has been in our system? And how can I
check what he did?¿

Thanks in advance!

- Hans