Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Odd timestampts in /var/log/messages from sshd |
|---|---|
| Date: | Wed, 25 Oct 2006 10:41:01 +0200 |
Tirsdag 24 oktober 2006 18:53, skrev Scot P. Floess:
I am running Fedora Core 5 on a dual PIII 450 Mhz machine, 1 GB of RAM, and OpensSSH_4.3p2/Open SSL 0.9.8a... I am experiencing odd timestamps generated from sshd. Basically whenever someone tries to login via ssh I see timestamps for the current time and then for a few hours before and then current time again. For instance, here is a sample from /var/log/messages (disregard the ellipses as I chopped out the usernames/ip addresses): Oct 23 08:57:26 adminserver sshd[19422]: Failed password for invalid user ... ssh2 Oct 23 *04:57:30* adminserver sshd[19423]: Failed password for invalid user ... ssh2 Oct 23 08:57:30 adminserver sshd[19424]: Failed password for invalid user ... ssh2 Oct 23 *04:57:34* adminserver sshd[19425]: Failed password for invalid user ... ssh2 Oct 23 08:57:34 adminserver sshd[19426]: Failed password for invalid user ... ssh2
<snip>
Scot
Are your sshd daemon running chroot'ed? If so, you probably need to establish the directory /etc under the jail and copy /etc/localtime into this new dir. I had a very similar problem with postfix/smtpd and it resolved by: mkdir /var/spool/postfix/etc (owned by root) and then: cp /etc/localtime /var/spool/postfix/etc Knut
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Odd timestampts in /var/log/messages from sshd, Darren Tucker |
|---|---|
| Next by Date: | Odd key problem, Keith Edmunds |
| Previous by Thread: | Re: Odd timestampts in /var/log/messages from sshd, Darren Tucker |
| Next by Thread: | Odd key problem, Keith Edmunds |
| Indexes: | [Date] [Thread] [Top] [All Lists] |