View Single Post
Old 27th August 2008, 00:56
houms houms is offline
Junior Member
Join Date: May 2008
Posts: 10
Thanks: 0
Thanked 1 Time in 1 Post
Default Hacking Attack????

looking at your log, it does not appear to be something you need to worry about. those entries are showing a cron job doing its thing. it is not something you need to worry about. I have the same entries in my log

Root is 'su'ing to 'nobody' to run a scheduled system service or a cron job...It starts the service then hands it over to 'nobody'.

oh, and 65534 is uid for user 'nobody', you probably have cron jobs running for various services... you may also want to check your /etc/cron.daily/ directory.

Last edited by houms; 27th August 2008 at 01:01.
Reply With Quote