Bonjour,
dans mon post précédent ( Virus ? ) j’ai conclus avec l’aide de Mimosa que mon compte root a été piraté et ceci a priori le 16/04/15 vers 15h45. Les logs ( auth ) montrent effectivement qqc à cette date mais je ne sais pas les interpréter. Si qq voit qqc merci de le faire savoir. Pour info le PC a pour nom bg1, l’utilisateur normal bernard qui dispose du mdp root mais ne devrait pas l’utiliser sans mon support téléphonique.
Apr 16 15:36:01 bg1 CRON[12840]: pam_unix(cron:session): session closed for user root
Apr 16 15:39:01 bg1 CRON[13435]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 16 15:39:01 bg1 CRON[13436]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 16 15:39:01 bg1 CRON[13435]: pam_unix(cron:session): session closed for user root
Apr 16 15:39:01 bg1 CRON[13436]: pam_unix(cron:session): session closed for user root
Apr 16 15:40:20 bg1 sshd[21755]: Received signal 15; terminating.
Apr 16 15:40:20 bg1 sshd[13917]: Server listening on 0.0.0.0 port 22.
Apr 16 15:40:20 bg1 sshd[13917]: Server listening on :: port 22.
Apr 16 15:42:01 bg1 CRON[14385]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 16 15:42:01 bg1 CRON[14385]: pam_unix(cron:session): session closed for user root
Apr 16 15:44:25 bg1 gdm3][4065]: pam_unix(gdm3:session): session closed for user bernard
Apr 16 15:44:25 bg1 polkitd(authority=local): Unregistered Authentication Agent for unix-session:/org/freedesktop/ConsoleKit/Session2 (system bus name :1.66, object path /org/gnome/PolicyKit1/AuthenticationAgent, locale fr_FR.UTF-8) (disconnected from bus)
Apr 16 15:44:32 bg1 sshd[13917]: Received signal 15; terminating.
Apr 16 15:45:38 bg1 sshd[3686]: Server listening on 0.0.0.0 port 22.
Apr 16 15:45:38 bg1 sshd[3686]: Server listening on :: port 22.
Apr 16 15:45:41 bg1 gdm-welcome][3715]: pam_unix(gdm-welcome:session): session opened for user Debian-gdm by (uid=0)
Apr 16 15:45:41 bg1 gdm-welcome][3715]: pam_ck_connector(gdm-welcome:session): nox11 mode, ignoring PAM_TTY :0
Apr 16 15:45:48 bg1 polkitd(authority=local): Registered Authentication Agent for unix-session:/org/freedesktop/ConsoleKit/Session1 (system bus name :1.48 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale fr_FR.UTF-8)
Apr 16 15:45:50 bg1 dbus[2450]: [system] Rejected send message, 2 matched rules; type=“method_call”, sender=":1.49" (uid=114 pid=4011 comm="/usr/lib/gdm3/gdm-simple-greeter “) interface=“org.freedesktop.DBus.Properties” member=“GetAll” error name=”(unset)" requested_reply=“0” destination=":1.17" (uid=0 pid=3088 comm="/usr/sbin/console-kit-daemon --no-daemon “)
Apr 16 15:45:50 bg1 dbus[2450]: [system] Rejected send message, 2 matched rules; type=“method_call”, sender=”:1.49" (uid=114 pid=4011 comm="/usr/lib/gdm3/gdm-simple-greeter “) interface=“org.freedesktop.DBus.Properties” member=“GetAll” error name=”(unset)" requested_reply=“0” destination=":1.17" (uid=0 pid=3088 comm="/usr/sbin/console-kit-daemon --no-daemon “)
Apr 16 15:45:50 bg1 dbus[2450]: [system] Rejected send message, 2 matched rules; type=“method_call”, sender=”:1.49" (uid=114 pid=4011 comm="/usr/lib/gdm3/gdm-simple-greeter “) interface=“org.freedesktop.DBus.Properties” member=“GetAll” error name=”(unset)" requested_reply=“0” destination=":1.17" (uid=0 pid=3088 comm="/usr/sbin/console-kit-daemon --no-daemon “)
Apr 16 15:45:50 bg1 dbus[2450]: [system] Rejected send message, 2 matched rules; type=“method_call”, sender=”:1.49" (uid=114 pid=4011 comm="/usr/lib/gdm3/gdm-simple-greeter “) interface=“org.freedesktop.DBus.Properties” member=“GetAll” error name=”(unset)" requested_reply=“0” destination=":1.17" (uid=0 pid=3088 comm="/usr/sbin/console-kit-daemon --no-daemon “)
Apr 16 15:45:50 bg1 dbus[2450]: [system] Rejected send message, 2 matched rules; type=“method_call”, sender=”:1.49" (uid=114 pid=4011 comm="/usr/lib/gdm3/gdm-simple-greeter “) interface=“org.freedesktop.DBus.Properties” member=“GetAll” error name=”(unset)" requested_reply=“0” destination=":1.17" (uid=0 pid=3088 comm="/usr/sbin/console-kit-daemon --no-daemon ")
Apr 16 15:45:57 bg1 gdm3][4022]: pam_unix(gdm3:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost= user=bernard
Apr 16 15:45:57 bg1 gdm3][4022]: pam_winbind(gdm3:auth): getting password (0x00000388)
Apr 16 15:45:57 bg1 gdm3][4022]: pam_winbind(gdm3:auth): pam_get_item returned a password
Apr 16 15:45:57 bg1 gdm3][4022]: pam_winbind(gdm3:auth): request wbcLogonUser failed: WBC_ERR_AUTH_ERROR, PAM error: PAM_USER_UNKNOWN (10), NTSTATUS: NT_STATUS_NO_SUCH_USER, Error message was: No such user
Apr 16 15:46:05 bg1 gdm3][4059]: pam_unix(gdm3:session): session opened for user bernard by (uid=0)
Apr 16 15:46:05 bg1 gdm3][4059]: pam_ck_connector(gdm3:session): nox11 mode, ignoring PAM_TTY :0
Apr 16 15:46:05 bg1 gdm-welcome][3715]: pam_unix(gdm-welcome:session): session closed for user Debian-gdm
Apr 16 15:46:05 bg1 polkitd(authority=local): Unregistered Authentication Agent for unix-session:/org/freedesktop/ConsoleKit/Session1 (system bus name :1.48, object path /org/gnome/PolicyKit1/AuthenticationAgent, locale fr_FR.UTF-8) (disconnected from bus)
Apr 16 15:46:10 bg1 polkitd(authority=local): Registered Authentication Agent for unix-session:/org/freedesktop/ConsoleKit/Session2 (system bus name :1.68 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale fr_FR.UTF-8)
Apr 16 15:48:01 bg1 CRON[4807]: pam_unix(cron:session): session opened for user root by (uid=0)
Apr 16 15:48:01 bg1 CRON[4807]: pam_unix(cron:session): session closed for user root