“Sucesso su para usuário por root” - entradas suspeitas no meu /var/log/auth.log?

5

Esta publicação no reddit fez com que eu passasse pelos meus registros. Foi quando descobri as seguintes entradas que apareceram em dois dias não subsequentes. "usuário" é minha conta de usuário.

Aug  4 22:50:37 UbuntuSystem sudo: pam_unix(sudo:session): session opened for user root by user(uid=1000)
Aug  4 22:50:39 UbuntuSystem sudo: pam_unix(sudo:session): session closed for user root
Aug  4 22:51:16 UbuntuSystem su[10710]: Successful su for user by root
Aug  4 22:51:16 UbuntuSystem su[10710]: + ??? root:user
Aug  4 22:51:16 UbuntuSystem su[10710]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 22:51:17 UbuntuSystem su[10710]: pam_unix(su:session): session closed for user user
Aug  4 22:51:17 UbuntuSystem su[10720]: Successful su for user by root
Aug  4 22:51:17 UbuntuSystem su[10720]: + ??? root:user
Aug  4 22:51:17 UbuntuSystem su[10720]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 22:51:17 UbuntuSystem su[10720]: pam_unix(su:session): session closed for user user
Aug  4 22:51:17 UbuntuSystem su[10735]: Successful su for user by root
Aug  4 22:51:17 UbuntuSystem su[10735]: + ??? root:user
Aug  4 22:51:17 UbuntuSystem su[10735]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 22:51:17 UbuntuSystem su[10735]: pam_unix(su:session): session closed for user user
Aug  4 22:51:17 UbuntuSystem su[10763]: Successful su for user by root
Aug  4 22:51:17 UbuntuSystem su[10763]: + ??? root:user
Aug  4 22:51:17 UbuntuSystem su[10763]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 22:51:17 UbuntuSystem su[10763]: pam_unix(su:session): session closed for user user
Aug  4 22:51:17 UbuntuSystem su[10773]: Successful su for user by root
Aug  4 22:51:17 UbuntuSystem su[10773]: + ??? root:user
Aug  4 22:51:17 UbuntuSystem su[10773]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 22:51:17 UbuntuSystem su[10773]: pam_unix(su:session): session closed for user user
Aug  4 22:51:17 UbuntuSystem su[10788]: Successful su for user by root
Aug  4 22:51:17 UbuntuSystem su[10788]: + ??? root:user
Aug  4 22:51:17 UbuntuSystem su[10788]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 22:51:17 UbuntuSystem su[10788]: pam_unix(su:session): session closed for user user
Aug  4 22:51:17 UbuntuSystem su[10801]: Successful su for user by root
Aug  4 22:51:17 UbuntuSystem su[10801]: + ??? root:user
Aug  4 22:51:17 UbuntuSystem su[10801]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 22:51:17 UbuntuSystem su[10801]: pam_unix(su:session): session closed for user user
Aug  4 22:51:17 UbuntuSystem su[10814]: Successful su for user by root
Aug  4 22:51:17 UbuntuSystem su[10814]: + ??? root:user
Aug  4 22:51:17 UbuntuSystem su[10814]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 22:51:17 UbuntuSystem su[10814]: pam_unix(su:session): session closed for user user
Aug  4 22:51:17 UbuntuSystem su[10829]: Successful su for user by root
Aug  4 22:51:17 UbuntuSystem su[10829]: + ??? root:user
Aug  4 22:51:17 UbuntuSystem su[10829]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 22:51:17 UbuntuSystem su[10829]: pam_unix(su:session): session closed for user user
Aug  4 22:51:17 UbuntuSystem su[10842]: Successful su for user by root
Aug  4 22:51:17 UbuntuSystem su[10842]: + ??? root:user
Aug  4 22:51:17 UbuntuSystem su[10842]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 22:51:17 UbuntuSystem su[10842]: pam_unix(su:session): session closed for user user
Aug  4 22:51:17 UbuntuSystem su[10855]: Successful su for user by root
Aug  4 22:51:17 UbuntuSystem su[10855]: + ??? root:user
Aug  4 22:51:17 UbuntuSystem su[10855]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 22:51:17 UbuntuSystem su[10855]: pam_unix(su:session): session closed for user user
Aug  4 23:41:39 UbuntuSystem su[11153]: Successful su for user by root
Aug  4 23:41:39 UbuntuSystem su[11153]: + ??? root:user
Aug  4 23:41:39 UbuntuSystem su[11153]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 23:41:39 UbuntuSystem su[11153]: pam_unix(su:session): session closed for user user
Aug  4 23:41:39 UbuntuSystem su[11166]: Successful su for user by root
Aug  4 23:41:39 UbuntuSystem su[11166]: + ??? root:user
Aug  4 23:41:39 UbuntuSystem su[11166]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 23:41:39 UbuntuSystem su[11166]: pam_unix(su:session): session closed for user user
Aug  4 23:41:39 UbuntuSystem su[11181]: Successful su for user by root
Aug  4 23:41:39 UbuntuSystem su[11181]: + ??? root:user
Aug  4 23:41:39 UbuntuSystem su[11181]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 23:41:39 UbuntuSystem su[11181]: pam_unix(su:session): session closed for user user
Aug  4 23:41:39 UbuntuSystem su[11193]: Successful su for user by root
Aug  4 23:41:39 UbuntuSystem su[11193]: + ??? root:user
Aug  4 23:41:39 UbuntuSystem su[11193]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 23:41:39 UbuntuSystem su[11193]: pam_unix(su:session): session closed for user user
Aug  4 23:41:39 UbuntuSystem su[11211]: Successful su for user by root
Aug  4 23:41:39 UbuntuSystem su[11211]: + ??? root:user
Aug  4 23:41:39 UbuntuSystem su[11211]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 23:41:39 UbuntuSystem su[11211]: pam_unix(su:session): session closed for user user
Aug  4 23:41:39 UbuntuSystem su[11226]: Successful su for user by root
Aug  4 23:41:39 UbuntuSystem su[11226]: + ??? root:user
Aug  4 23:41:39 UbuntuSystem su[11226]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 23:41:39 UbuntuSystem su[11226]: pam_unix(su:session): session closed for user user
Aug  4 23:41:39 UbuntuSystem su[11241]: Successful su for user by root
Aug  4 23:41:39 UbuntuSystem su[11241]: + ??? root:user
Aug  4 23:41:39 UbuntuSystem su[11241]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 23:41:39 UbuntuSystem su[11241]: pam_unix(su:session): session closed for user user
Aug  4 23:41:39 UbuntuSystem su[11253]: Successful su for user by root
Aug  4 23:41:39 UbuntuSystem su[11253]: + ??? root:user
Aug  4 23:41:39 UbuntuSystem su[11253]: pam_unix(su:session): session opened for user user by (uid=0)
Aug  4 23:41:39 UbuntuSystem su[11253]: pam_unix(su:session): session closed for user user
Aug  4 23:42:18 UbuntuSystem gnome-screensaver-dialog: gkr-pam: unlocked login keyring
Aug  4 23:42:33 UbuntuSystem polkitd(authority=local): Unregistered Authentication Agent for unix-session:/org/freedesktop/ConsoleKit/Session2 (system bus name :1.48, object path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8) (disconnected from bus)

Aug 15 20:17:01 UbuntuSystem CRON[26579]: pam_unix(cron:session): session opened for user root by (uid=0)
Aug 15 20:17:01 UbuntuSystem CRON[26579]: pam_unix(cron:session): session closed for user root
Aug 15 21:15:15 UbuntuSystem su[27098]: Successful su for user by root
Aug 15 21:15:15 UbuntuSystem su[27098]: + ??? root:user
Aug 15 21:15:15 UbuntuSystem su[27098]: pam_unix(su:session): session opened for user user by (uid=0)
Aug 15 21:15:15 UbuntuSystem su[27098]: pam_unix(su:session): session closed for user user
Aug 15 21:17:01 UbuntuSystem CRON[27141]: pam_unix(cron:session): session opened for user root by (uid=0)
Aug 15 21:17:01 UbuntuSystem CRON[27141]: pam_unix(cron:session): session closed for user root

Além dessas iterações, as únicas outras vezes em que encontrei uma saída semelhante foram ao testar a conta de convidado:

Aug 11 22:38:49 UbuntuSystem lightdm: pam_unix(lightdm:session): session closed for user lightdm
Aug 11 22:38:49 UbuntuSystem groupadd[2918]: group added to /etc/group: name=guest-4Eflre, GID=125
Aug 11 22:38:49 UbuntuSystem groupadd[2918]: group added to /etc/gshadow: name=guest-4Eflre
Aug 11 22:38:49 UbuntuSystem groupadd[2918]: new group: name=guest-4Eflre, GID=125
Aug 11 22:38:50 UbuntuSystem useradd[2922]: new user: name=guest-4Eflre, UID=115, GID=125, home=/, shell=/bin/bash
Aug 11 22:38:50 UbuntuSystem usermod[2927]: change user 'guest-4Eflre' password
Aug 11 22:38:50 UbuntuSystem chage[2932]: changed password expiry for guest-4Eflre
Aug 11 22:38:50 UbuntuSystem chfn[2935]: changed user 'guest-4Eflre' information
Aug 11 22:38:50 UbuntuSystem usermod[2943]: change user 'guest-4Eflre' home from '/' to '/tmp/guest-4Eflre'
Aug 11 22:38:50 UbuntuSystem su[2948]: Successful su for guest-4Eflre by root
Aug 11 22:38:50 UbuntuSystem su[2948]: + ??? root:guest-4Eflre
Aug 11 22:38:50 UbuntuSystem su[2948]: pam_unix(su:session): session opened for user guest-4Eflre by (uid=0)
Aug 11 22:38:50 UbuntuSystem su[2948]: pam_unix(su:session): session closed for user guest-4Eflre
Aug 11 22:38:50 UbuntuSystem lightdm: pam_unix(lightdm-autologin:session): session opened for user guest-4Eflre by (uid=0)
Aug 11 22:38:50 UbuntuSystem lightdm: pam_ck_connector(lightdm-autologin:session): nox11 mode, ignoring PAM_TTY :0

Eu posso ter que adicionar que eu configurei meu sistema apenas recentemente (4 de agosto).

Esse comportamento é normal? O que exatamente está acontecendo com todos os comandos su? Eu tenho que estar preocupado que meu sistema possa estar comprometido?

Muito obrigado antecipadamente.

    
por Glutanimate 17.08.2012 / 21:08

3 respostas

6

Esses avisos são quando você navega da raiz para o seu usuário

Não parece que você tenha algum problema.

    
por LnxSlck 17.08.2012 / 21:43
3

Não há quando você executa sudo . Mas eles não são um problema também.

As mensagens dizem:

Successful su for user by root

Isso acontece sempre que você faz o login. Se você está logando como um usuário real ou um usuário convidado, a tela de login é executada como root , então ele deve alterar a identidade do usuário de root para um usuário que não seja root como parte do processo de login.

Isso não está user se tornando root . Isso é root se tornando user .

    
por Eliah Kagan 17.08.2012 / 22:50
2

Acho que encontrei pelo menos um dos culpados:

Aug 21 16:15:09 UbuntuSystem su[30135]: Successful su for user by root
Aug 21 16:15:09 UbuntuSystem su[30135]: + ??? root:user
Aug 21 16:15:09 UbuntuSystem su[30135]: pam_unix(su:session): session opened for user user by (uid=0)
Aug 21 16:15:09 UbuntuSystem su[30135]: pam_unix(su:session): session closed for user user
Aug 21 16:15:09 UbuntuSystem sudo: pam_unix(sudo:session): session closed for user root
Aug 21 16:15:12 UbuntuSystem sudo:      user : TTY=unknown ; PWD=/home/user ; USER=root ; COMMAND=/usr/lib/jupiter/scripts/cpu-control high
Aug 21 16:15:12 UbuntuSystem sudo: pam_unix(sudo:session): session opened for user root by (uid=1000)
Aug 21 16:15:12 UbuntuSystem su[30174]: Successful su for user by root
Aug 21 16:15:12 UbuntuSystem su[30174]: + ??? root:user
Aug 21 16:15:12 UbuntuSystem su[30174]: pam_unix(su:session): session opened for user user by (uid=0)
Aug 21 16:15:12 UbuntuSystem su[30174]: pam_unix(su:session): session closed for user user
Aug 21 16:15:12 UbuntuSystem sudo: pam_unix(sudo:session): session closed for user root

Neste caso, as entradas foram conectadas ao applet de energia Jupiter e apareceram especificamente ao alterar o modo de energia da CPU. Como não houve menção de Júpiter em nenhuma das outras instâncias, não posso ter certeza se elas podem ser atribuídas ao mesmo processo.

Vou continuar monitorando meus registros e postar mais resultados aqui.

    
por Glutanimate 21.08.2012 / 16:20