[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] Have I been hacked ?



And if so how to stop tjis.

My active monitor shows the following
The Post Office Protocol (POP3) server has not been responding since Sat Feb 17 13:30:42 2001 GMT.

and in my messages logfile, I have the following

Feb 17 13:15:10 raq3 useradd[5442]: new group: name=named, gid=25
Feb 17 13:15:10 raq3 useradd[5442]: new user: name=named, uid=25, gid=25, home=/var/named, shell=/bin/false Feb 17 13:15:22 raq3 in.qpopper[7038]: Active_Monitor_69@localhost: -ERR POP EOF received
Feb 17 13:15:22 raq3 telnetd[7041]: ttloop:  read: Broken pipe
Feb 17 13:16:57 raq3 named[24405]: reloading nameserver
Feb 17 13:16:57 raq3 named[24405]: Forwarding source address

If I have been hacked, what should I do to bring things back to normal. Everything else is working fine.

<panick>Thanks a lot</panick>
_________________________________________________________________________
Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com.