Very strange auth logs, possibly hacked?
Ok when I woke up today, one the servers I admin was down. So I called and had the datacenter reboot it. Anyway after looking through the logs for the possible cause, I came across this:
Quote:
May 18 02:12:44 vortex sshd[1833]: SELECT password FROM users WHERE username='root'
May 18 02:12:44 vortex sshd[1833]: ***DEBUG: MySQL:$1$FPuHiYlG$f6ObPojLF57ZtxOgAMlg2. given:$1$FPuHiYlG$mcOJz8odgTyJTTA.vu97T1
May 18 02:12:44 vortex sshd[1833]: returning 7 .
May 18 02:12:44 vortex sshd[1833]: returning 7 after db_checkpasswd.
May 18 02:12:44 vortex sshd(pam_unix)[1833]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=62.231.98.116 user=root
May 18 02:12:44 vortex sshd[1833]: pam_mysql: acct_mgmt called but not implemented. Dont panic though :)
May 18 02:12:44 vortex sshd[1833]: Accepted password for root from 62.231.98.116 port 1881 ssh2
May 18 02:12:45 vortex sshd(pam_unix)[1833]: session opened for user root by (uid=0)
Now I am using pam_mysql, and the person didn't enter the correct root pw but it still logged them in. I can't figure out why, plus they also show up in wmtp log as well. Has anyone seen that before, and yes sshd is up to date.