Depuis quelques temps, la boîte mail d'admin sur ma SME (V7.3) est surchargée par des messages d'alerte de sme7admin dont voici le contenu :
- Code: Tout sélectionner
Fri Aug 14 15:45:06 2009
Status du serveur
Nombre de connexions ouvertes : ssh=0 ftp=0 vpn=0 netbios=0
#>tail /var/log/messages :
Aug 14 15:25:01 scenic su(pam_unix)[2535]: session opened for user qmailr by (uid=0)
Aug 14 15:25:02 scenic su(pam_unix)[2535]: session closed for user qmailr
Aug 14 15:30:01 scenic su(pam_unix)[2612]: session opened for user qmailr by (uid=0)
Aug 14 15:30:01 scenic su(pam_unix)[2612]: session closed for user qmailr
Aug 14 15:35:01 scenic su(pam_unix)[2691]: session opened for user qmailr by (uid=0)
Aug 14 15:35:02 scenic su(pam_unix)[2691]: session closed for user qmailr
Aug 14 15:40:01 scenic su(pam_unix)[2836]: session opened for user qmailr by (uid=0)
Aug 14 15:40:01 scenic su(pam_unix)[2836]: session closed for user qmailr
Aug 14 15:45:01 scenic su(pam_unix)[2914]: session opened for user qmailr by (uid=0)
Aug 14 15:45:02 scenic su(pam_unix)[2914]: session closed for user qmailr
#>netstat --numeric-hosts -tpu :
Connexions Internet actives (sans serveurs)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 86.210.88.35:44078 213.205.99.116:http ESTABLISHED 4005/squid
tcp 0 0 86.210.88.35:44095 91.103.138.65:http TIME_WAIT -
tcp 0 0 192.168.1.1:squid 192.168.1.10:40051 ESTABLISHED 4005/squid
#>service httpd status
#>service smb status
run: /service/nmbd: (pid 4034) 690934s, normally down; run: log: (pid 2790) 690958s
run: /service/smbd: (pid 4046) 690933s, normally down; run: log: (pid 2804) 690958s
#>service sshd status
run: /service/sshd: (pid 3873) 690940s, normally down; run: log: (pid 2800) 690958s
Le fichier /var/log/messages est envahi par ce type de lignes :
- Code: Tout sélectionner
Aug 14 16:30:01 scenic su(pam_unix)[3794]: session opened for user qmailr by (uid=0)
Aug 14 16:30:01 scenic su(pam_unix)[3794]: session closed for user qmailr
Aug 14 16:32:01 scenic slapd[3756]: conn=21 fd=7 ACCEPT from IP=127.0.0.1:44218 (IP=0.0.0.0:389)
Aug 14 16:32:01 scenic slapd[3756]: conn=21 op=0 BIND dn="" method=128
Aug 14 16:32:01 scenic slapd[3756]: conn=21 op=0 RESULT tag=97 err=0 text=
Aug 14 16:32:01 scenic slapd[3756]: conn=21 op=1 UNBIND
Aug 14 16:32:01 scenic slapd[3756]: conn=21 fd=7 closed
Aug 14 16:35:01 scenic su(pam_unix)[3881]: session opened for user qmailr by (uid=0)
Aug 14 16:35:02 scenic su(pam_unix)[3881]: session closed for user qmailr
Est-ce quelqu'un a déjà eu ce genre de problème ? (si c'en est un).
Merci et bon weekend.
Cilor.