Re: suspekter Eintrag in der auth.log
Michael DINDORF schrieb:
> Jun 12 06:25:01 a209014 CRON[12013]: (pam_unix) session opened for user
> root by (uid=0)
> Jun 12 06:25:02 a209014 CRON[12009]: (pam_unix) session closed for user
> root
> Jun 12 06:25:02 a209014 CRON[12011]: (pam_unix) session closed for user
> root
> --->
> Jun 12 06:25:02 a209014 su[12040]: + ??? root:nobody
> Jun 12 06:25:02 a209014 su[12040]: (pam_unix) session opened for user
> nobody by (uid=0)
grep nobody /etc/cron.daily/*
Ciao
Walter
Reply to: