Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

ttyv for local only?

1 view
Skip to first unread message

mud...@metafocus.net

unread,
Jun 26, 2004, 4:07:10 PM6/26/04
to

I get this in my security postings.

Jun [undisclosed time] [undiscl.] login: 2 LOGIN FAILURES ON ttyv2
Jun [undisclosed time] [undiscl.] login: 2 LOGIN FAILURES ON ttyv2, qmaild

As it turns out, I'm not running qmail :) And if I did, it would
definitely have a nologin shell. But that's beside the point-

I have had a perception that ttyv was for local/console logins, and that
just "tty" was for remote logins.

Is my understanding wrong here?


_______________________________________________
freebsd-...@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-securi...@freebsd.org"

gmu...@infotechfl.com

unread,
Jun 30, 2004, 11:39:54 AM6/30/04
to
If someone hasn't suggested it already, you may want to install tripwire to
md5 checksum all of your files.

Once you build the database, make a copy off-machine or use chflags on a
copy of it so you have a reference database that your potential cracker
can't modify.

Gary

j...@ods.org

unread,
Jul 7, 2004, 12:04:54 PM7/7/04
to
Perhaps someone is using the snoop device? (man snp).

I do this occasionally.. but you can watch vtys using 'watch' and the snp
devices.

Regards,
-JD-

--On Saturday, June 26, 2004 1:18 PM -0700 Dave <mud...@metafocus.net>
wrote:

0 new messages