Subject: Re: system possibly compromised
To: None <khym@azeotrope.org, quadreverb@yahoo.com>
From: Roger Fischer <rgfisch@excite.com>
List: netbsd-help
Date: 02/24/2004 18:05:26
 --- On Tue 02/24, Dave Huang < khym@azeotrope.org > wrote:

> That's just something cron used to do... nothing to worry
> about :) The current version of cron no longer does that; 
> see the log message for revision 1.14 of
> http://cvsweb.netbsd.org/bsdweb.cgi/src/usr.sbin/cron/do_command.c
> use setproctitle() instead of uppercasing ProgramName this
> makes the ps display nicer, and also avoids uppercasing the
> cron program name in logs idea from FreeBSD

Dave,
From my first email, somebody had been sending mail from my machine or with my domain name because my ISP threatened to close my account if I didn't stop it.  After poking around, that was the only thing I could find that was weird.  I've got relaying off in postfix, so I don't know if somebody compromised my machine or if the headers were forged.

The /USR/SBIN/CRON as a child of /usr/sbin/cron was the only thing weird I could find and I couldn't trace down what was starting it.  I'll do more investigation, buy maybe my machine is OK.

thanks,
   - Roger


_______________________________________________
Join Excite! - http://www.excite.com
The most personalized portal on the Web!