Jan 19 18:40:57 joni-virtual-machine lightdm: pam_unix(lightdm:session): session opened for user lightdm by (uid=0) Jan 19 18:40:57 joni-virtual-machine lightdm: pam_ck_connector(lightdm:session): nox11 mode, ignoring PAM_TTY :0 Jan 19 18:41:00 joni-virtual-machine dbus[776]: [system] Rejected send message, 2 matched rules; type="method_call", sender=":1.17" (uid=104 pid=1357 comm="/usr/sbin/lightdm-gtk-greeter ") interface="org.freedesktop.DBus.Properties" member="GetAll" error name="(unset)" requested_reply="0" destination=":1.15" (uid=0 pid=1278 comm="/usr/sbin/console-kit-daemon --no-daemon ") Jan 19 18:41:02 joni-virtual-machine lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "joni" Jan 19 18:41:21 joni-virtual-machine lightdm: pam_unix(lightdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost= user=joni Jan 19 18:41:22 joni-virtual-machine lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "joni" Jan 19 18:41:28 joni-virtual-machine lightdm: pam_unix(lightdm:session): session closed for user lightdm Jan 19 18:41:28 joni-virtual-machine lightdm: pam_unix(lightdm:session): session opened for user joni by (uid=0) Jan 19 18:41:28 joni-virtual-machine lightdm: pam_ck_connector(lightdm:session): nox11 mode, ignoring PAM_TTY :0 Jan 19 18:41:31 joni-virtual-machine polkitd(authority=local): Registered Authentication Agent for unix-session:/org/freedesktop/ConsoleKit/Session2 (system bus name :1.21 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8) Jan 19 18:42:45 joni-virtual-machine sudo: pam_unix(sudo:auth): authentication failure; logname= uid=1000 euid=0 tty=/dev/pts/0 ruser=joni rhost= user=joni Jan 19 18:43:08 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/home/joni ; USER=root ; COMMAND=/usr/bin/apt-get update Jan 19 18:43:08 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 18:43:17 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 18:43:40 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/home/joni ; USER=root ; COMMAND=/usr/bin/apt-get install ssh Jan 19 18:43:40 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 18:43:41 joni-virtual-machine gnome-keyring-daemon[2080]: couldn't access conrol socket: /tmp/keyring-y6F58T/control: No such file or directory Jan 19 18:43:41 joni-virtual-machine gnome-keyring-daemon[2080]: couldn't set environment variable in session: The name org.gnome.SessionManager was not provided by any .service files Jan 19 18:43:50 joni-virtual-machine useradd[2620]: new user: name=sshd, UID=114, GID=65534, home=/var/run/sshd, shell=/usr/sbin/nologin Jan 19 18:43:50 joni-virtual-machine usermod[2625]: change user 'sshd' password Jan 19 18:43:50 joni-virtual-machine chage[2630]: changed password expiry for sshd Jan 19 18:43:50 joni-virtual-machine sshd[2674]: Server listening on 0.0.0.0 port 22. Jan 19 18:43:50 joni-virtual-machine sshd[2674]: Server listening on :: port 22. Jan 19 18:43:53 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 18:44:21 joni-virtual-machine sshd[2701]: Accepted password for joni from 127.0.0.1 port 40166 ssh2 Jan 19 18:44:21 joni-virtual-machine sshd[2701]: pam_unix(sshd:session): session opened for user joni by (uid=0) Jan 19 18:46:37 joni-virtual-machine sudo: joni : TTY=pts/2 ; PWD=/home/joni ; USER=root ; COMMAND=/usr/bin/apt-get install apache2 Jan 19 18:46:38 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by joni(uid=1000) Jan 19 18:46:47 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 18:55:04 joni-virtual-machine sudo: joni : TTY=pts/2 ; PWD=/home/joni ; USER=root ; COMMAND=/bin/mv /etc/apache2/mods-available/userdir.conf /etc/apache2/mods-enabled/ Jan 19 18:55:04 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by joni(uid=1000) Jan 19 18:55:04 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 18:55:12 joni-virtual-machine sudo: joni : TTY=pts/2 ; PWD=/home/joni ; USER=root ; COMMAND=/bin/mv /etc/apache2/mods-available/userdir.load /etc/apache2/mods-enabled/ Jan 19 18:55:12 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by joni(uid=1000) Jan 19 18:55:12 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 18:55:53 joni-virtual-machine sudo: joni : TTY=pts/2 ; PWD=/home/joni ; USER=root ; COMMAND=/etc/init.d/apache2 restart Jan 19 18:55:53 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by joni(uid=1000) Jan 19 18:55:54 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 18:56:27 joni-virtual-machine sudo: joni : TTY=pts/2 ; PWD=/home/joni ; USER=root ; COMMAND=/etc/init.d/apache2 restart Jan 19 18:56:27 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by joni(uid=1000) Jan 19 18:56:28 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 19:08:01 joni-virtual-machine sudo: joni : TTY=pts/2 ; PWD=/etc/skel ; USER=root ; COMMAND=/bin/mkdir public_html Jan 19 19:08:01 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by joni(uid=1000) Jan 19 19:08:01 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 19:10:50 joni-virtual-machine sudo: joni : TTY=pts/2 ; PWD=/etc/skel ; USER=root ; COMMAND=/usr/sbin/adduser eangstrom Jan 19 19:10:50 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by joni(uid=1000) Jan 19 19:10:50 joni-virtual-machine groupadd[4249]: group added to /etc/group: name=eangstrom, GID=1001 Jan 19 19:10:50 joni-virtual-machine groupadd[4249]: group added to /etc/gshadow: name=eangstrom Jan 19 19:10:50 joni-virtual-machine groupadd[4249]: new group: name=eangstrom, GID=1001 Jan 19 19:10:50 joni-virtual-machine useradd[4253]: new user: name=eangstrom, UID=1001, GID=1001, home=/home/eangstrom, shell=/bin/bash Jan 19 19:12:35 joni-virtual-machine passwd[4260]: pam_unix(passwd:chauthtok): password changed for eangstrom Jan 19 19:12:35 joni-virtual-machine passwd[4260]: gkr-pam: couldn't update the login keyring password: no old password was entered Jan 19 19:13:04 joni-virtual-machine chfn[4261]: changed user 'eangstrom' information Jan 19 19:13:09 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 19:17:01 joni-virtual-machine CRON[4469]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 19 19:17:01 joni-virtual-machine CRON[4469]: pam_unix(cron:session): session closed for user root Jan 19 19:20:50 joni-virtual-machine sudo: joni : TTY=pts/2 ; PWD=/etc/skel ; USER=root ; COMMAND=/usr/sbin/adduser mmehilainen Jan 19 19:20:50 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by joni(uid=1000) Jan 19 19:20:50 joni-virtual-machine groupadd[4477]: group added to /etc/group: name=mmehilainen, GID=1002 Jan 19 19:20:50 joni-virtual-machine groupadd[4477]: group added to /etc/gshadow: name=mmehilainen Jan 19 19:20:50 joni-virtual-machine groupadd[4477]: new group: name=mmehilainen, GID=1002 Jan 19 19:20:50 joni-virtual-machine useradd[4481]: new user: name=mmehilainen, UID=1002, GID=1002, home=/home/mmehilainen, shell=/bin/bash Jan 19 19:21:07 joni-virtual-machine passwd[4488]: pam_unix(passwd:chauthtok): password changed for mmehilainen Jan 19 19:21:07 joni-virtual-machine passwd[4488]: gkr-pam: couldn't update the login keyring password: no old password was entered Jan 19 19:21:18 joni-virtual-machine chfn[4489]: changed user 'mmehilainen' information Jan 19 19:21:20 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 19:21:42 joni-virtual-machine sudo: joni : TTY=pts/2 ; PWD=/etc/skel ; USER=root ; COMMAND=/usr/sbin/adduser vhurme Jan 19 19:21:42 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by joni(uid=1000) Jan 19 19:21:42 joni-virtual-machine groupadd[4495]: group added to /etc/group: name=vhurme, GID=1003 Jan 19 19:21:42 joni-virtual-machine groupadd[4495]: group added to /etc/gshadow: name=vhurme Jan 19 19:21:42 joni-virtual-machine groupadd[4495]: new group: name=vhurme, GID=1003 Jan 19 19:21:42 joni-virtual-machine useradd[4499]: new user: name=vhurme, UID=1003, GID=1003, home=/home/vhurme, shell=/bin/bash Jan 19 19:23:39 joni-virtual-machine passwd[4506]: pam_unix(passwd:chauthtok): password changed for vhurme Jan 19 19:23:39 joni-virtual-machine passwd[4506]: gkr-pam: couldn't update the login keyring password: no old password was entered Jan 19 19:24:01 joni-virtual-machine chfn[4507]: changed user 'vhurme' information Jan 19 19:24:02 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 19:25:05 joni-virtual-machine sudo: joni : TTY=pts/2 ; PWD=/etc/skel ; USER=root ; COMMAND=/usr/sbin/adduser alorenz Jan 19 19:25:05 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by joni(uid=1000) Jan 19 19:25:05 joni-virtual-machine groupadd[4513]: group added to /etc/group: name=alorenz, GID=1004 Jan 19 19:25:05 joni-virtual-machine groupadd[4513]: group added to /etc/gshadow: name=alorenz Jan 19 19:25:05 joni-virtual-machine groupadd[4513]: new group: name=alorenz, GID=1004 Jan 19 19:25:05 joni-virtual-machine useradd[4517]: new user: name=alorenz, UID=1004, GID=1004, home=/home/alorenz, shell=/bin/bash Jan 19 19:25:16 joni-virtual-machine passwd[4524]: pam_unix(passwd:chauthtok): password changed for alorenz Jan 19 19:25:16 joni-virtual-machine passwd[4524]: gkr-pam: couldn't update the login keyring password: no old password was entered Jan 19 19:25:24 joni-virtual-machine chfn[4525]: changed user 'alorenz' information Jan 19 19:25:25 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 19:27:23 joni-virtual-machine sudo: joni : TTY=pts/2 ; PWD=/etc/skel ; USER=root ; COMMAND=/usr/sbin/adduser pakker Jan 19 19:27:23 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by joni(uid=1000) Jan 19 19:27:23 joni-virtual-machine groupadd[4531]: group added to /etc/group: name=pakker, GID=1005 Jan 19 19:27:23 joni-virtual-machine groupadd[4531]: group added to /etc/gshadow: name=pakker Jan 19 19:27:23 joni-virtual-machine groupadd[4531]: new group: name=pakker, GID=1005 Jan 19 19:27:23 joni-virtual-machine useradd[4535]: new user: name=pakker, UID=1005, GID=1005, home=/home/pakker, shell=/bin/bash Jan 19 19:27:36 joni-virtual-machine passwd[4542]: pam_unix(passwd:chauthtok): password changed for pakker Jan 19 19:27:36 joni-virtual-machine passwd[4542]: gkr-pam: couldn't update the login keyring password: no old password was entered Jan 19 19:28:02 joni-virtual-machine chfn[4543]: changed user 'pakker' information Jan 19 19:28:03 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 19:52:49 joni-virtual-machine lightdm: pam_unix(lightdm:session): session closed for user joni Jan 19 19:52:49 joni-virtual-machine polkitd(authority=local): Unregistered Authentication Agent for unix-session:/org/freedesktop/ConsoleKit/Session2 (system bus name :1.21, object path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8) (disconnected from bus) Jan 19 19:52:49 joni-virtual-machine sshd[2857]: Received disconnect from 127.0.0.1: 11: disconnected by user Jan 19 19:52:49 joni-virtual-machine sshd[2701]: pam_unix(sshd:session): session closed for user joni Jan 19 19:52:52 joni-virtual-machine lightdm: pam_unix(lightdm:session): session opened for user lightdm by (uid=0) Jan 19 19:52:52 joni-virtual-machine lightdm: pam_ck_connector(lightdm:session): nox11 mode, ignoring PAM_TTY :0 Jan 19 19:52:53 joni-virtual-machine dbus[776]: [system] Rejected send message, 2 matched rules; type="method_call", sender=":1.59" (uid=104 pid=4637 comm="/usr/sbin/lightdm-gtk-greeter ") interface="org.freedesktop.DBus.Properties" member="GetAll" error name="(unset)" requested_reply="0" destination=":1.15" (uid=0 pid=1278 comm="/usr/sbin/console-kit-daemon --no-daemon ") Jan 19 19:52:53 joni-virtual-machine lightdm: pam_succeed_if(lightdm:auth): requirement "user ingroup nopasswdlogin" not met by user "joni" Jan 19 19:53:08 joni-virtual-machine lightdm: pam_unix(lightdm:session): session closed for user lightdm Jan 19 19:53:08 joni-virtual-machine lightdm: pam_unix(lightdm:session): session opened for user joni by (uid=0) Jan 19 19:53:08 joni-virtual-machine lightdm: pam_ck_connector(lightdm:session): nox11 mode, ignoring PAM_TTY :0 Jan 19 19:53:10 joni-virtual-machine polkitd(authority=local): Registered Authentication Agent for unix-session:/org/freedesktop/ConsoleKit/Session5 (system bus name :1.61 [/usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1], object path /org/gnome/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8) Jan 19 20:03:04 joni-virtual-machine sshd[4983]: Accepted password for eangstrom from 127.0.0.1 port 40284 ssh2 Jan 19 20:03:04 joni-virtual-machine sshd[4983]: pam_unix(sshd:session): session opened for user eangstrom by (uid=0) Jan 19 20:08:23 joni-virtual-machine sshd[5135]: Received disconnect from 127.0.0.1: 11: disconnected by user Jan 19 20:08:23 joni-virtual-machine sshd[4983]: pam_unix(sshd:session): session closed for user eangstrom Jan 19 20:09:01 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/home/joni ; USER=root ; COMMAND=/bin/cp /home/eangstrom/public_html/index.html /home/mmehilainen/public_html/ Jan 19 20:09:01 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 20:09:01 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 20:09:10 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/home/joni ; USER=root ; COMMAND=/bin/cp /home/eangstrom/public_html/index.html /home/vhurme/public_html/ Jan 19 20:09:10 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 20:09:10 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 20:09:18 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/home/joni ; USER=root ; COMMAND=/bin/cp /home/eangstrom/public_html/index.html /home/alorenz/public_html/ Jan 19 20:09:18 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 20:09:18 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 20:09:24 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/home/joni ; USER=root ; COMMAND=/bin/cp /home/eangstrom/public_html/index.html /home/pakker/public_html/ Jan 19 20:09:24 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 20:09:24 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 20:13:53 joni-virtual-machine sshd[5321]: Accepted password for mmehilainen from 127.0.0.1 port 40288 ssh2 Jan 19 20:13:53 joni-virtual-machine sshd[5321]: pam_unix(sshd:session): session opened for user mmehilainen by (uid=0) Jan 19 20:17:01 joni-virtual-machine CRON[5565]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 19 20:17:01 joni-virtual-machine CRON[5565]: pam_unix(cron:session): session closed for user root Jan 19 20:27:24 joni-virtual-machine sshd[5451]: Received disconnect from 127.0.0.1: 11: disconnected by user Jan 19 20:27:24 joni-virtual-machine sshd[5321]: pam_unix(sshd:session): session closed for user mmehilainen Jan 19 20:27:57 joni-virtual-machine sshd[5584]: Accepted password for eangstrom from 127.0.0.1 port 40290 ssh2 Jan 19 20:27:57 joni-virtual-machine sshd[5584]: pam_unix(sshd:session): session opened for user eangstrom by (uid=0) Jan 19 20:39:27 joni-virtual-machine sshd[5714]: Received disconnect from 127.0.0.1: 11: disconnected by user Jan 19 20:39:27 joni-virtual-machine sshd[5584]: pam_unix(sshd:session): session closed for user eangstrom Jan 19 20:47:39 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/home/joni ; USER=root ; COMMAND=/usr/bin/apt-get install java Jan 19 20:47:39 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 20:47:40 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 20:48:00 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/home/joni ; USER=root ; COMMAND=/usr/bin/apt-get install default-jre Jan 19 20:48:00 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 20:48:57 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 20:49:20 joni-virtual-machine gnome-keyring-daemon[6922]: couldn't access conrol socket: /tmp/keyring-K2hEnc/control: No such file or directory Jan 19 20:49:20 joni-virtual-machine gnome-keyring-daemon[6922]: couldn't set environment variable in session: The name org.gnome.SessionManager was not provided by any .service files Jan 19 20:52:43 joni-virtual-machine sshd[6929]: Accepted password for eangstrom from 127.0.0.1 port 40310 ssh2 Jan 19 20:52:43 joni-virtual-machine sshd[6929]: pam_unix(sshd:session): session opened for user eangstrom by (uid=0) Jan 19 21:02:02 joni-virtual-machine sshd[7059]: Received disconnect from 127.0.0.1: 11: disconnected by user Jan 19 21:02:02 joni-virtual-machine sshd[6929]: pam_unix(sshd:session): session closed for user eangstrom Jan 19 21:02:22 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/home/joni ; USER=root ; COMMAND=/usr/bin/apt-get install default-jdk Jan 19 21:02:22 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 21:02:55 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 21:03:15 joni-virtual-machine sshd[11076]: Accepted password for eangstrom from 127.0.0.1 port 40329 ssh2 Jan 19 21:03:15 joni-virtual-machine sshd[11076]: pam_unix(sshd:session): session opened for user eangstrom by (uid=0) Jan 19 21:13:52 joni-virtual-machine sshd[11228]: Received disconnect from 127.0.0.1: 11: disconnected by user Jan 19 21:13:52 joni-virtual-machine sshd[11076]: pam_unix(sshd:session): session closed for user eangstrom Jan 19 21:14:06 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/home/joni ; USER=root ; COMMAND=/usr/bin/apt-cache search firestarter Jan 19 21:14:06 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 21:14:06 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 21:14:16 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/home/joni ; USER=root ; COMMAND=/usr/bin/apt-get install firestarter Jan 19 21:14:16 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 21:14:37 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 21:16:43 joni-virtual-machine sudo: joni : TTY=unknown ; PWD=/home/joni ; USER=root ; COMMAND=/usr/sbin/firestarter Jan 19 21:16:43 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 21:17:01 joni-virtual-machine CRON[12508]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 19 21:17:01 joni-virtual-machine CRON[12508]: pam_unix(cron:session): session closed for user root Jan 19 21:27:06 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 21:27:14 joni-virtual-machine sudo: joni : TTY=unknown ; PWD=/home/joni ; USER=root ; COMMAND=/usr/sbin/firestarter Jan 19 21:27:14 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 21:27:35 joni-virtual-machine sudo: root : TTY=unknown ; PWD=/home/joni ; USER=joni ; COMMAND=/usr/bin/firefox http://www.fs-security.com Jan 19 21:27:35 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user joni by (uid=0) Jan 19 21:27:38 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user joni Jan 19 21:30:11 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 21:31:42 joni-virtual-machine sudo: joni : TTY=unknown ; PWD=/home/joni ; USER=root ; COMMAND=/usr/sbin/firestarter Jan 19 21:31:42 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 21:41:23 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/home/joni ; USER=root ; COMMAND=/usr/bin/apt-get remove firestarter Jan 19 21:41:23 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 21:41:33 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 21:41:45 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/home/joni ; USER=root ; COMMAND=/usr/bin/apt-get install gufw Jan 19 21:41:45 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 21:41:56 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 21:42:08 joni-virtual-machine polkitd(authority=local): Operator of unix-session:/org/freedesktop/ConsoleKit/Session5 successfully authenticated as unix-user:joni to gain TEMPORARY authorization for action gufw.daemon.start for unix-process:13992:1088985 [python /usr/lib/python2.7/dist-packages/gufw/gufw.py] (owned by unix-user:joni) Jan 19 21:50:01 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 21:52:50 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/home/joni ; USER=root ; COMMAND=/usr/bin/apt-get install php5 Jan 19 21:52:50 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 21:53:13 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 21:53:46 joni-virtual-machine sshd[15509]: Accepted password for vhurme from 127.0.0.1 port 40391 ssh2 Jan 19 21:53:46 joni-virtual-machine sshd[15509]: pam_unix(sshd:session): session opened for user vhurme by (uid=0) Jan 19 21:58:17 joni-virtual-machine sshd[15641]: Received disconnect from 127.0.0.1: 11: disconnected by user Jan 19 21:58:17 joni-virtual-machine sshd[15509]: pam_unix(sshd:session): session closed for user vhurme Jan 19 21:58:42 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/etc/apache2/mods-enabled ; USER=root ; COMMAND=/etc/init.d/apache2 restart Jan 19 21:58:42 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 21:58:43 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 22:02:23 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/var/log ; USER=root ; COMMAND=/usr/bin/apt-get install libapache2-mod-php5 Jan 19 22:02:23 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 22:02:24 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 22:05:36 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/var/log ; USER=root ; COMMAND=/usr/bin/nano /etc/apache2/mods-enabled/php5.conf Jan 19 22:05:36 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 22:06:18 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/var/log ; USER=root ; COMMAND=/usr/bin/nano /etc/apache2/mods-enabled/php5.conf Jan 19 22:06:18 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 22:06:28 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 22:06:37 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/var/log ; USER=root ; COMMAND=/etc/init.d/apache2 restart Jan 19 22:06:37 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 22:06:38 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 22:09:01 joni-virtual-machine CRON[15909]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 19 22:09:02 joni-virtual-machine CRON[15909]: pam_unix(cron:session): session closed for user root Jan 19 22:09:40 joni-virtual-machine sudo: joni : TTY=pts/0 ; PWD=/var/log ; USER=root ; COMMAND=/usr/bin/nano /etc/apache2/mods-enabled/php5.conf Jan 19 22:09:40 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by (uid=1000) Jan 19 22:16:05 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 22:17:01 joni-virtual-machine CRON[15926]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 19 22:17:01 joni-virtual-machine CRON[15926]: pam_unix(cron:session): session closed for user root Jan 19 22:21:27 joni-virtual-machine sshd[15935]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=192.168.111.1 user=joni Jan 19 22:21:29 joni-virtual-machine sshd[15935]: Failed password for joni from 192.168.111.1 port 5664 ssh2 Jan 19 22:21:31 joni-virtual-machine sshd[15935]: Accepted password for joni from 192.168.111.1 port 5664 ssh2 Jan 19 22:21:31 joni-virtual-machine sshd[15935]: pam_unix(sshd:session): session opened for user joni by (uid=0) Jan 19 22:25:17 joni-virtual-machine sudo: joni : TTY=pts/2 ; PWD=/home/joni ; USER=root ; COMMAND=/usr/bin/apt-get install curl Jan 19 22:25:17 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by joni(uid=1000) Jan 19 22:25:25 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root Jan 19 22:36:11 joni-virtual-machine sshd[16782]: Accepted password for joni from 192.168.111.1 port 5740 ssh2 Jan 19 22:36:11 joni-virtual-machine sshd[16782]: pam_unix(sshd:session): session opened for user joni by (uid=0) Jan 19 22:36:11 joni-virtual-machine sshd[16912]: subsystem request for sftp by user joni Jan 19 22:39:01 joni-virtual-machine CRON[16915]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 19 22:39:01 joni-virtual-machine CRON[16915]: pam_unix(cron:session): session closed for user root Jan 19 22:45:29 joni-virtual-machine sshd[16782]: pam_unix(sshd:session): session closed for user joni Jan 19 22:45:45 joni-virtual-machine sudo: joni : TTY=pts/2 ; PWD=/home/mmehilainen/starsign ; USER=root ; COMMAND=/usr/sbin/ufw status verbose Jan 19 22:45:45 joni-virtual-machine sudo: pam_unix(sudo:session): session opened for user root by joni(uid=1000) Jan 19 22:45:45 joni-virtual-machine sudo: pam_unix(sudo:session): session closed for user root.