Hi guys, recently I have been placed in charge of the RAQ4 server which we
rent from an ISP... I installed logcheck and im getting a lot of weird
activity... Now I only have experience in BSD and a little Linux. I am
wondering if this web management software may be causing this. Here is a
Snippet of the logs.
Jun 1 00:15:00 f04-4-3-00-0472 proftpd[18809]: XXX.XXX.XXX
(localhost[127.0.0.1]) - FTP session opened.
Jun 1 00:15:00 f04-4-3-00-0472 proftpd[18809]: XXX.XXX.XXX
(localhost[127.0.0.1]) - FTP session closed.
Jun 1 00:30:01 f04-4-3-00-0472 proftpd[19399]: XXX.XXX.XXX
(localhost[127.0.0.1]) - FTP session opened.
Jun 1 00:30:01 f04-4-3-00-0472 proftpd[19399]: XXX.XXX.XXX
(localhost[127.0.0.1]) - FTP session closed.
Jun 1 00:45:00 f04-4-3-00-0472 proftpd[19983]: XXX.XXX.XXX
(localhost[127.0.0.1]) - FTP session opened.
I have looked at Cron for every user and I cant find a thing... I have
looked at the ProFTP mailing list thou I doubt its a ProFTP problem but more
of a configuration problem when the isp installed the machine... Thank you
all for any advise or suggestions.