Sponsored Content
Full Discussion: Entries in /var/log/messgaes
Top Forums UNIX for Dummies Questions & Answers Entries in /var/log/messgaes Post 31073 by Kelam_Magnus on Thursday 31st of October 2002 03:47:19 PM
Old 10-31-2002
Okay, I'll bite.

Is this for a home or work system?

Are you having problems with inetd? Maybe stop and start it again.

Is this an IP that you recognize? Is the range in your same Class as the box? Is it in your domain?

Is it outside your firewall? Only systems that have access can telnet to your host.

If this is an unauthorized attempt to access your system, I would report it to your security group.

Smilie
 

10 More Discussions You Might Find Interesting

1. UNIX for Dummies Questions & Answers

help interpreting var/log/messages log

I'm using RHEL and my var/log/messages file is filled with "FTP session opened/closed" lines that happen all day: Aug 2 04:04:38 web proftpd: 74.125.56.10 (142.231.76.249) - FTP session closed. Aug 2 04:05:11 web proftpd: 74.125.56.10 (142.231.88.123) - FTP session opened.Is this normal? We... (2 Replies)
Discussion started by: gaspol
2 Replies

2. Solaris

diff b/w /var/log/syslog and /var/adm/messages

hi sirs can u tell the difference between /var/log/syslogs and /var/adm/messages in my working place i am having two servers. in one servers messages file is empty and syslog file is going on increasing.. and in another servers message file is going on increasing but syslog file is... (2 Replies)
Discussion started by: tv.praveenkumar
2 Replies

3. Solaris

Error messgaes can not be redirected

# whoami 2>/dev/null whoami: not found # Why the error message not getting redirected to /dev/null ... The shell is # echo $SHELL /sbin/sh For other commands it is working # ls aaa 2>/dev/null # Is there any other way to redirect the err msg from whoami Thank you for your... (7 Replies)
Discussion started by: Anu_1
7 Replies

4. UNIX for Advanced & Expert Users

/var/adm/messages vs /var/log/messages

The /var/adm/messages in Solaris seem to log more system messages/errors compared to /var/log/messages in Linux. I checked the log level in Linux and they seem OK. Is there any other log file that contains the messages or is it just that Linux doesn't log great many things? (2 Replies)
Discussion started by: gomes1333
2 Replies

5. Emergency UNIX and Linux Support

/var/log/wtmp SuSE log permission rollback

Hello All, On my SuSE system, I have wtmp log this log file permission is 644 but every reboot the file permission rollback to 664. In the logrotate.conf and logrotate.d/wtmp files the wtmp logrotate set to 644. I would like to know, which "file" or "script" modify the wtmp log to rollback to... (7 Replies)
Discussion started by: kalaso
7 Replies

6. Solaris

Difference between /var/log/syslog and /var/adm/messages

Hi, Is the contents in /var/log/syslog and /var/adm/messages are same?? Regards (3 Replies)
Discussion started by: vks47
3 Replies

7. Shell Programming and Scripting

How can view log messages between two time frame from /var/log/message or any type of log files

How can view log messages between two time frame from /var/log/message or any type of log files. when logfiles are very big and especially many messages with in few minutes, I would like to display log messages between 5 minute interval. Could you pls give me the command? (1 Reply)
Discussion started by: johnveslin
1 Replies

8. HP-UX

Script to monitor /var/opt/resmon/log/event.log file

AM in need of some plugin/script that can monitor HP-UX file "/var/opt/resmon/log/event.log" . Have written a scrip in sh shell that is working fine for syslog.log and mail.log as having standard format, have interrogated that to Nagios and is working as I required . But same script failed to... (3 Replies)
Discussion started by: Shirishlnx
3 Replies

9. Shell Programming and Scripting

Log all the commands input by user at real time in /var/log/messages

Below is my script to log all the command input by any user to /var/log/messages. But I cant achieve the desired output that i want. PLease see below. function log2syslog { declare COMMAND COMMAND=$(fc -ln -0) logger -p local1.notice -t bash -i -- "$USER:$COMMAND" } trap... (12 Replies)
Discussion started by: invinzin21
12 Replies

10. Shell Programming and Scripting

Transfer the logs being thrown into /var/log/messages into another file example /var/log/volumelog

I have been searching and reading about syslog. I would like to know how to Transfer the logs being thrown into /var/log/messages into another file example /var/log/volumelog. tail -f /var/log/messages dblogger: msg_to_dbrow: no logtype using missing dblogger: msg_to_dbrow_str: val ==... (2 Replies)
Discussion started by: kenshinhimura
2 Replies
SOCKD(8)						      System Manager's Manual							  SOCKD(8)

NAME
sockd - Internet firewall secure socket server (proxy server) SYNOPSIS
sockd [ -ver | -i | -I ] DESCRIPTION
sockd is an internet secure socket server, often referred to as a proxy server. It was designed primarily to provide hosts within a fire- wall access to resources outside of the firewall. Normally, hosts inside a firewall has no IP-accessibility to the network outside of the firewall. This reduces the risk of being intruded by unauthorized people from the Internet. Unfortunately, without IP-accessibility users on the inside hosts can no longer use many of the important tools such as telnet, ftp, xgopher, Mosaic, etc. to access the tremendous resources available in the Internet. With sockd installed on a server host, users on the other inside hosts can gain back the lost functionalities by using clients programs designed to work with sockd proxy server, e.g, rtelnet in place of telnet, rftp in place of ftp, rfinger in place of finger, etc. Since these client programs work like their normal counterparts without requiring direct IP-connectivity to the Internet, convenience to the users is accomplished without breaching the security. The server host that runs sockd does have to be open to the Internet, and it there- fore requires special attention to make sure that it is secure. A configuration file /etc/sockd.fc (or /etc/sockd.conf) is used to control access to sockd and its services. Permission and denial of a service request can be decided based on various combinations of the requesting host, the destination host, the type of service (destination port number), as well as the requesting user. (See sockd.conf(5) and sockd.fc(5).) If the server host is multi-homed, i.e., having more than one network interface and with its IP_FORWARDING turned off, and the server sup- port RBIND operation, then it must run a multi-homed version of sockd, which requires another control file /etc/sockd.fr (or /etc/sockd.route) to decide which interface to use for connection to any given destination host. See sockd.route(5) and sockd.fr(5). A multi-homed sockd can be run on a single-homed host as well if necessary; you just have to set up /etc/sockd.route to direct all traffic through the host's one and only network interface. sockd uses syslog with facility daemon and level notice to log its activities and errors. Typical lines look like Apr 11 08:51:29 eon sockd[636]: connected -- Connect from don(don)@abc.edu to wxy.com (telnet) Apr 11 09:24:59 eon sockd[636]: terminated -- Connect from don(don)@abc.edu to wxy.com (telnet) Apr 11 09:24:59 eon sockd[636]: 1048 bytes from abc.edu, 285143 bytes from wxy.com Jun 22 18:24:54 eon sockd[884]: refused -- Connect from sam(unknown)@big.com to small.com (ftp) In these lines, the first user-id is the one reported by the client program, the second one (within the parentheses) is what is reported by identd on the client host. These log lines usually appear in file /var/adm/messages though that can be changed by modifying /etc/sys- log.conf. (See syslogd(8) and syslog.conf(5).) If you allow access to infosystems such as Gopher or WWW, you should be aware that they by nature would tend to get connections to hosts all over the world and would use not only Gopher and WWW ports but possibly also ports for finger, telnet, ftp, nntp, etc. as well as non- privileged ports ( > 1023). For a stand-alone sockd, /etc/sockd.fc (or /etc/sockd.conf) and /etc/sockd.fr (or /etc/sockd.route), if required, are only read and parsed once at the beginning of program execution. If you change the contents of either file and want to make the running sockd use the new con- tents, you must send a SIGHUP signal to the running sockd process. Sending a running stand-alone sockd a SIGUSR1 signal causes it to record on the systems's log file the effective contents of configuration and route files that it is currently using. You can find the process id of the stand-alone sockd in /etc/sockd.pid. Rather than using plain-text configuration file /etc/sockd.conf and route file /etc/sockd.route, sockd now looks for the corresponding frozen files /etc/sockd.fc and /etc/sockd.fr first. The plain-text files are used only if the corresponding frozen files are not found. Use commands make_sockdfc and make_sockdfr to produce the frosen files. Use commands dump_sockdfc and dump_sockdfr to examine the contents of frozen files. (See make_sockdfc(8), make_sockdfr(8), dump_sockdfc(8), and dump_sockdfr(8).) Using frozen configuration and route files can save a lot of overhead at start-up of sockd. OPTIONS
The options are mutually exclusive and thus may only be used one at a time. -ver With this option, sockd prints its own version number, the version number of the SOCKS protocol, whether it is SOCKSified, whether it is a standalone daemon or must be run under inetd, whether it support RBIND, and whether a route file is required. -I Use identd (RFC 1413) to verify the requester's user-id. Deny access if connection to client's identd fails or if the result does not match the user-id reported by the client program. Client hosts without a properly installed identd daemon will not be served. User verification is done before and in addition to the normal access control. This can be overridden in the sockd.conf file on a line by line basis. -i Similar to -I but more lenient. Access is denied only if client's identd reports a user-id that's different from what the client program claims. This can be overridden in the sockd.conf file on a line by line basis. Log entries similar to the following are produced upon failure of user-id verification: Apr 15 14:42:51 eon sockd[729]: cannot connect to identd on big.edu Apr 15 14:42:51 eon sockd[729]: refused -- Connect from bob(unknown)@big.edu to xyz.com (ftp) Jul 15 12:23:06 eon sockd[832]: *Alert*: real user is sam, not jim Jul 15 12:23:06 eon sockd[832]: refused -- Connect from jim(sam)@abc.org to bad.place.com (WWW) FILES
/etc/sockd.fc, /etc/sockd.conf, /etc/sockd.fr, /etc/sockd.route, /etc/inetd.conf, /etc/services, /var/adm/messages, /etc/syslog.conf SEE ALSO
socks_clients(1), sockd.conf(5), sockd.route(5), socks.conf(5), make_sockdfc(8), make_sockdfr(8), dump_sockdfc(8), dump_sockdfr(8) AUTHOR
David Koblas, koblas@sgi.com Ying-Da Lee, ylee@syl.dl.nec.com David Mischel, dm@kansas.gene.com June 6, 1996 SOCKD(8)
All times are GMT -4. The time now is 08:20 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy