Hi,
I know both of these things are slighly off topic, but I have heard
nothing from Suse about the network failure on boot, and I am wondering if
anyone else has hit the lpd problem:
We just replaced /etc/printcap (trivial change) on a bunch of Suse9.1
workstations, restarted lpd (we are using the Suse provided lprng) and
about half of the workstations were left in a bizarre state where printing
via lpd left all the print jobs on the local computer and did not send
them on, so to speak.
Hmm, OK let's try and restart lpd on a computer that has this lpd problem:
/etc/init.d/lpd restart
results in xdm being killed along with a few other rather critical
processes. This action logs me off the computer (as root) and the person
who "was" using the console. Only a reboot will suffice.
Most of the computers seem to have been fixable using:
killall -KILL lpd; /etc/init.d/lpd start
http://www.lprng.com/
thinks that:
(For LPRng-3.8.28)
is the latest version, whereas
lprng-3.8.25-37
is what Suse provide in 9.1
between 3.8.25 and 3.8.28 there is a fix for a memory leak.....
Also our process accouting logs seem to show lpd getting into a state
where it is creating a new process every 10 seconds.
Approximately 1 out of 30 boots of Suse 9.1 result the network service not
starting during boot. After the boot it is always possible to start it (
/etc/init.d.network start) successfully, but not much use with other
services relying upon it. Another boot of the same computer and everything
is always fine, so no repeatiblity to speak of - yuk.
Anyone else seen this?
Mike Rose
Hello list,
in my logs I found the appended entries. My question is, what is the intention
of this guy. I don't understand, why he uses a few loginnames many times and
others only one time. There is no account on my box which matches to one of
the tested loginnames.
Another thing. I get this userlist (exactly the same names in the same order)
from many different IPs.
Any hints?
regards
Kai Pfeiffer
Dec 1 11:02:54 mybox sshd[14251]: Illegal user patrick from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:55 mybox sshd[14253]: Illegal user patrick from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:55 mybox sshd[14265]: Illegal user rolo from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:56 mybox sshd[14267]: Illegal user iceuser from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:56 mybox sshd[14269]: Illegal user horde from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:56 mybox sshd[14271]: Illegal user cyrus from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:56 mybox sshd[14273]: Illegal user www from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:56 mybox sshd[14277]: Illegal user matt from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:57 mybox sshd[14279]: Illegal user test from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:57 mybox sshd[14281]: Illegal user test from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:57 mybox sshd[14283]: Illegal user test from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:57 mybox sshd[14285]: Illegal user test from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:57 mybox sshd[14287]: Illegal user www-data from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:57 mybox sshd[14291]: Illegal user operator from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:57 mybox sshd[14293]: Illegal user adm from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:58 mybox sshd[14295]: Illegal user apache from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:58 mybox sshd[14297]: Illegal user irc from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:58 mybox sshd[14299]: Illegal user irc from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:58 mybox sshd[14301]: Illegal user adm from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:58 mybox sshd[14309]: Illegal user jane from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:58 mybox sshd[14311]: Illegal user pamela from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:02:59 mybox sshd[14323]: Illegal user cosmin from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:04 mybox sshd[14397]: Illegal user cip52 from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:04 mybox sshd[14399]: Illegal user cip51 from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:05 mybox sshd[14403]: Illegal user noc from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:05 mybox sshd[14413]: Illegal user webmaster from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:05 mybox sshd[14415]: Illegal user data from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:06 mybox sshd[14417]: Illegal user user from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:06 mybox sshd[14419]: Illegal user user from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:06 mybox sshd[14421]: Illegal user user from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:06 mybox sshd[14423]: Illegal user web from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:06 mybox sshd[14425]: Illegal user web from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:06 mybox sshd[14427]: Illegal user oracle from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:06 mybox sshd[14429]: Illegal user sybase from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:06 mybox sshd[14431]: Illegal user master from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:07 mybox sshd[14433]: Illegal user account from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:07 mybox sshd[14435]: Illegal user backup from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:07 mybox sshd[14437]: Illegal user server from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:07 mybox sshd[14439]: Illegal user adam from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:07 mybox sshd[14441]: Illegal user alan from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:07 mybox sshd[14443]: Illegal user frank from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:08 mybox sshd[14445]: Illegal user george from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:08 mybox sshd[14447]: Illegal user henry from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:08 mybox sshd[14449]: Illegal user john from
::ffff:xxx.xxx.xxx.xxx
Dec 1 11:03:09 mybox sshd[14461]: Illegal user test from
::ffff:xxx.xxx.xxx.xxx
Recently I notice a large increase in spam related to recent transactions I've
made. I ordered pharmaceuticals on line and now get increased spam from thos
type of business. I inquired about credit card fraud and get spam.
Could this mean there is some kind of binary running in my system which sends
information about my activities. I've heard about something called spyware.
I believe my system has some kind of suse 8.2 supplied software firewall but
don't know where or how to configure it.
How would I find and remove any such unwanted intruder?
Dear all
I have a vpn connection that only works in a direction.
Configuration:
GW-Left:
Suse 9.2 (kernel 2.6.8-24.3-default))
Openswan 2.2.0
Susefirewall 3.2
GW-Right:
Suse 7.3 (kernel 2.4-18)
freeswan 1.98b
Susefirewall
PC-Left/Right
Windows XP SP1
| PC-Left |------------| GW-Left
|--------------<Router>-------------| GW-Right |------------| PC-Right |
ISAKMP SA is established, also key-exchange seems to work.
A ping from PC-Right to PC-Left works fine, put a ping from PC-Left to
PC-Right works not.
ipsec.conf
plutodebug=none
# Certificate Revocation List handling
#crlcheckinterval=600
#strictcrlpolicy=yes
# Change rp_filter setting, default = 0 (switch off)
rp_filter=%unchanged
# Switch on NAT-Traversal (if patch is installed)
nat_traversal=yes
interfaces=%defaultroute
#forwardcontrol=yes
# default settings for connections
conn %default
# Default: %forever (try forever)
#keyingtries=3
# Sig keys (default: %dnsondemand)
#leftrsasigkey=%cert
#rightrsasigkey=%cert
# Lifetimes, defaults are 1h/8hrs
#ikelifetime=20m
#keylife=1h
#rekeymargin=8m
left=%defaultroute
compress=no
# Add connections here
# sample VPN connection
conn kbs-test
type=tunnel
auth=esp
# Left security gateway, subnet behind it, next hop
toward right.
left=83.0.0.51
leftsubnet=10.0.0.64/26
leftnexthop=83.0.0.49
# Right security gateway, subnet behind it, next hop
toward left.
right=83.0.0.52
rightsubnet=10.0.0.192/26
rightnexthop=83.0.0.49
# To authorize this connection, but not actually start
it, at startup,
# uncomment this.
auto=start
authby=secret
#Disable Opportunistic Encryption
include /etc/ipsec.d/examples/no_oe.conf
Any ideas about that?
Greetings,
Gabriel