Quantcast
Channel: EdgeRouter topics
Viewing all articles
Browse latest Browse all 20028

auth.log shows iptables being manipulated

$
0
0

checking through the router and came across a bunch of sudo access at a time where there is no known user logged in.  Does anyone have insight as to whether this is an automated action, and what is actually being done? 

 

 

Sep 14 11:58:21 EdgeRouterAMK sudo: root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/bin
/ip rule del pref 201 fwmark 1686110208/0x7f800000 table 201
Sep 14 11:58:21 EdgeRouterAMK sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Sep 14 11:58:21 EdgeRouterAMK sudo: pam_unix(sudo:session): session closed for user root
Sep 14 11:58:21 EdgeRouterAMK sudo: root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/bin/ip rule add pref 201 fwmark 1686110208/0x7f800000 table 201
Sep 14 11:58:21 EdgeRouterAMK sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Sep 14 11:58:21 EdgeRouterAMK sudo: pam_unix(sudo:session): session closed for user root
Sep 14 11:58:22 EdgeRouterAMK sudo: root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/bin/ip rule del pref 202 fwmark 1694498816/0x7f800000 table 202
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session closed for user root
Sep 14 11:58:22 EdgeRouterAMK sudo: root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/bin/ip rule add pref 202 fwmark 1694498816/0x7f800000 table 202
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session closed for user root
Sep 14 11:58:22 EdgeRouterAMK sudo: root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/sbin/iptables -t mangle -nL VYATTA_WLB_WanLB
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session closed for user root
Sep 14 11:58:22 EdgeRouterAMK sudo: root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/sbin/iptables -t mangle -nL VYATTA_WLBI_WanLB
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session closed for user root
Sep 14 11:58:22 EdgeRouterAMK sudo: root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/sbin/iptables -t mangle -nL VYATTA_WLBO_WanLB
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session closed for user root
Sep 14 11:58:22 EdgeRouterAMK sudo: root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/sbin/iptables -t mangle -nL VYATTA_WLBL_WanLB
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session closed for user root
Sep 14 11:58:22 EdgeRouterAMK sudo: root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/sbin/iptables-restore -n -v
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session closed for user root
Sep 14 11:58:22 EdgeRouterAMK sudo: root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/sbin/ipset create ADDRv4_eth2 hash:net hashsize 10 maxelem 100
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session closed for user root
Sep 14 11:58:22 EdgeRouterAMK sudo: root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/sbin/ipset create NETv4_eth2 hash:net hashsize 10 maxelem 100
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session closed for user root
Sep 14 11:58:22 EdgeRouterAMK sudo: root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/sbin/ipset create ADDRv4_eth1 hash:net hashsize 10 maxelem 100
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session closed for user root
Sep 14 11:58:22 EdgeRouterAMK sudo: root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/sbin/ipset create NETv4_eth1 hash:net hashsize 10 maxelem 100
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session closed for user root
Sep 14 11:58:22 EdgeRouterAMK sudo: root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/sbin/ipset create ADDRv4_eth0 hash:net hashsize 10 maxelem 100
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session opened for user root by (uid=0)
Sep 14 11:58:22 EdgeRouterAMK sudo: pam_unix(sudo:session): session closed for user root
Sep 14 11:58:22 EdgeRouterAMK sudo: root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/sbi:


Viewing all articles
Browse latest Browse all 20028

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>