I have an ubuntu server and I want to understand if someone enter into it (hacker). I have seen into auth.log many lines like this:
May 30 10:36:00 xxx-System-Product_Name CRON[2758]: pam_unix(cron:session): session opened for user admin by (uid=0)
May 30 10:36:00 xxx-System-Product_Name CRON[2758]: pam_unix(cron:session): session closed for user admin
May 30 10:37:00 xxx-System-Product_Name CRON[2759]: pam_unix(cron:session): session opened for user admin by (uid=0)
May 30 10:37:00 xxx-System-Product_Name CRON[2759]: pam_unix(cron:session): session closed for user admin
My user is 'alessandro' and not admin someone is entered with user 'admin' ?
Can someone help me?
sudo crontab -u admin -e.. – NickW May 30 '13 at 08:46sudo ls -la /var/tmp/you do not see anything? – NickW May 30 '13 at 08:56/dev/nullis empty always, it's like a hole to throw things down, un buco nero dove non torna indietro niente.. – NickW May 30 '13 at 08:57