The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > Security
Google UNIX.COM


Security Anything involving computer security goes here.

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
syslogd 30% utilization in top, solaris 9 chugheshc SUN Solaris 2 05-28-2008 08:18 AM
Syslogd silvaman UNIX for Advanced & Expert Users 3 08-29-2006 04:53 AM
Message from syslogd Hitori Linux 18 07-27-2006 12:25 PM
multiple instances of syslogd - is it possible? Gary Dunn UNIX for Advanced & Expert Users 9 07-20-2004 06:10 AM
syslogd buRst UNIX for Dummies Questions & Answers 2 11-26-2002 10:00 AM

Reply
 
Submit Tools LinkBack Thread Tools Search this Thread Display Modes
  #1  
Old 12-05-2002
Registered User
 

Join Date: Aug 2002
Location: Philadelphia, PA
Posts: 75
HELP!!! syslogd is down...

Hi all
My system logger has been down for the past 3 days... I am not able to get it to start from the terminal... /etc/init.d/syslogd start
I am unable to find a log as to why it is failing!!

Please advice where to look!!! I am totally lost here!

Thanks in advance...

KS
Reply With Quote
Forum Sponsor
  #2  
Old 12-05-2002
Perderabo's Avatar
Unix Daemon
 

Join Date: Aug 2001
Location: Washington DC Area
Posts: 8,656
What version of unix? Does /etc/syslog.conf exist? Maybe the command: "syslogd -d" will give you a clue.
Reply With Quote
  #3  
Old 12-05-2002
RTM's Avatar
RTM RTM is offline
Hog Hunter
 
Join Date: Apr 2002
Location: On my motorcycle
Posts: 3,039
Please post which OS and version.

Have you checked disk space?
Have you checked that permissions on the following files have not changed? (configuration file {could be /etc/syslog.conf}, /etc/init.d/syslogd, the directory it should be dumping to and the file {look in the configuration file to insure it's dumping where you thought it should})

You can add the -d option to debug when starting it (may have to do this either in the startup script or start the daemon manually ).

(Perderabo hit this at the same time)
Reply With Quote
  #4  
Old 12-05-2002
Registered User
 

Join Date: Aug 2002
Location: Philadelphia, PA
Posts: 75
)
I got hit by a rootkit. The hacker must have shut down the daemon. Is there a way to clean out the system from the SK rootkit? Please let me know! I know a re-install is suggested but this is the second time this is happenning and I want to find a way to tackle this with the minimum downtime!!
I am running redhat linux 7.0.
Please advice...

thanks

KS
Reply With Quote
  #5  
Old 12-05-2002
RTM's Avatar
RTM RTM is offline
Hog Hunter
 
Join Date: Apr 2002
Location: On my motorcycle
Posts: 3,039
If it's the second time, then you must know that you have not done enough to keep the hacker out. Attempting to check all your files and hope you get them all so you don't have to do this a third time I believe to be a waste of your time.

See what others have to say - IMHO - rebuild.

Wright State U - Internet Security
Reply With Quote
  #6  
Old 12-05-2002
LivinFree's Avatar
Goober Extraordinaire
 

Join Date: Jul 2001
Location: Portland, OR, USA
Posts: 1,584
Definitely rebuild. There were a few gnarly rootkits floating around - you'll never get clean.

Reinstall, then go to Redhat and install every one of those darn updates for 7.0. It takes some time, but that's how it's got to be if you want to be a decent 'net citizen. Think how many other users have been rooted from your box (acting as a launch-pad).

Also, out of interest, search google for info to find out which one got you. Then you can go back and see how they got in.
Reply With Quote
Google The UNIX and Linux Forums
Reply

Tags
linux

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes




All times are GMT -7. The time now is 10:58 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008. All Rights Reserved.Ad Management by RedTyger Visit The Complex Event Processing Blog

Content Relevant URLs by vBSEO 3.2.0