Click to See Complete Forum and Search --> : What is this in my syslog


groundzero
05-01-2001, 10:11 AM
Apr 29 17:50:00 Maximus CROND[3084]: (root) CMD ( /usr/share/msec/promisc_check.sh)
Apr 29 17:50:00 Maximus CROND[3085]: (root) CMD ( /sbin/rmmod -as)
Apr 29 17:51:00 Maximus CROND[3090]: (root) CMD ( /usr/share/msec/promisc_check.sh)
Apr 29 17:52:00 Maximus CROND[3095]: (root) CMD ( /usr/share/msec/promisc_check.sh)
Apr 29 17:53:00 Maximus CROND[3100]: (root) CMD ( /usr/share/msec/promisc_check.sh)
Apr 29 17:54:00 Maximus CROND[3105]: (root) CMD ( /usr/share/msec/promisc_check.sh)
Apr 29 17:55:00 Maximus CROND[3111]: (root) CMD ( /usr/share/msec/promisc_check.sh)
Apr 29 17:56:00 Maximus CROND[3116]: (root) CMD ( /usr/share/msec/promisc_check.sh)
Apr 29 17:57:00 Maximus CROND[3121]: (root) CMD ( /usr/share/msec/promisc_check.sh) :eek:

bdl
05-01-2001, 11:22 AM
Looks as if your crond is running a script named promisc_check.sh every minute. I'd guess that it checks your ethernet for promiscuous mode and warns you about it, but it also may be a lovely trojan. Head over to the directory it's in and check it out.