Ci-dessous, les différences entre deux révisions de la page.
Les deux révisions précédentesRévision précédenteProchaine révision | Révision précédente | ||
raspberry:log [03-07-2013 20:57] – [Samba] edmc73 | raspberry:log [04-03-2021 19:34] (Version actuelle) – edmc73 | ||
---|---|---|---|
Ligne 1: | Ligne 1: | ||
- | ====== | + | ====== |
Comme vous le savez, le raspberry tourne sur une SDcard, et cette mémoire flash n'aime pas trop les écritures à outrance. | Comme vous le savez, le raspberry tourne sur une SDcard, et cette mémoire flash n'aime pas trop les écritures à outrance. | ||
Ligne 6: | Ligne 6: | ||
- | ===== / | + | ===== Les logs ===== |
- | < | + | < |
+ | # cd /var/log | ||
+ | # find -mtime -1 -type f -exec ls -l {} \; | ||
-rw-r--r-- 1 root root 86111 juil. 2 21:41 ./ | -rw-r--r-- 1 root root 86111 juil. 2 21:41 ./ | ||
-rw-r--r-- 1 root root 1829 juil. 1 21:49 ./ | -rw-r--r-- 1 root root 1829 juil. 1 21:49 ./ | ||
Ligne 27: | Ligne 29: | ||
On va analyser tous les fichiers qui ont été modifié récemment et qui ont une taille élevée. | On va analyser tous les fichiers qui ont été modifié récemment et qui ont une taille élevée. | ||
- | ===== Samba ===== | + | ==== Samba ==== |
Extrait | Extrait | ||
< | < | ||
Ligne 64: | Ligne 66: | ||
</ | </ | ||
- | Editez votre fichier de config **/ | + | Editez votre fichier de config **/ |
< | < | ||
########## Printing ########## | ########## Printing ########## | ||
Ligne 71: | Ligne 73: | ||
# than setting them up individually then you'll need this | # than setting them up individually then you'll need this | ||
load printers = no | load printers = no | ||
+ | show add printer wizard = no | ||
+ | | ||
+ | | ||
</ | </ | ||
Relancez samba | Relancez samba | ||
service samba restart | service samba restart | ||
- | ===== auth.log ===== | + | ==== auth.log |
+ | Extrait : | ||
+ | < | ||
+ | Jul 4 19:48:59 edmchome sshd[8201]: Failed password for root from 80.84.55.183 port 11919 ssh2 | ||
+ | Jul 4 19:48:59 edmchome sshd[8201]: Disconnecting: | ||
+ | Jul 4 19:48:59 edmchome sshd[8201]: PAM 5 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=80.84.55.183 | ||
+ | Jul 4 19:48:59 edmchome sshd[8201]: PAM service(sshd) ignoring max retries; 6 > 3 | ||
+ | Jul 4 19:49:01 edmchome sshd[8205]: reverse mapping checking getaddrinfo for 183-55-84-80.rackcentre.redstation.net.uk [80.84.55.183] failed - POSSIBLE BREAK-IN ATTEMPT! | ||
+ | Jul 4 19:49:02 edmchome sshd[8205]: pam_unix(sshd: | ||
+ | Jul 4 19:49:03 edmchome sshd[8205]: Failed password for root from 80.84.55.183 port 12041 ssh2 | ||
+ | Jul 4 19:49:07 edmchome sshd[8205]: Failed password for root from 80.84.55.183 port 12041 ssh2 | ||
+ | Jul 4 19:49:09 edmchome sshd[8205]: Failed password for root from 80.84.55.183 port 12041 ssh2 | ||
+ | Jul 4 19:49:11 edmchome sshd[8205]: Failed password for root from 80.84.55.183 port 12041 ssh2 | ||
+ | Jul 4 19:49:13 edmchome sshd[8205]: Failed password for root from 80.84.55.183 port 12041 ssh2 | ||
+ | Jul 4 19:49:16 edmchome sshd[8205]: Failed password for root from 80.84.55.183 port 12041 ssh2 | ||
+ | Jul 4 19:49:16 edmchome sshd[8205]: Disconnecting: | ||
+ | Jul 4 19:49:16 edmchome sshd[8205]: PAM 5 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=80.84.55.183 | ||
+ | Jul 4 19:49:16 edmchome sshd[8205]: PAM service(sshd) ignoring max retries; 6 > 3 | ||
+ | Jul 4 19:49:18 edmchome sshd[8209]: reverse mapping checking getaddrinfo for 183-55-84-80.rackcentre.redstation.net.uk [80.84.55.183] failed - POSSIBLE BREAK-IN ATTEMPT! | ||
+ | Jul 4 19:49:19 edmchome sshd[8209]: pam_unix(sshd: | ||
+ | Jul 4 19:49:20 edmchome sshd[8209]: Failed password for root from 80.84.55.183 port 12167 ssh2 | ||
+ | Jul 4 19:49:22 edmchome sshd[8209]: Failed password for root from 80.84.55.183 port 12167 ssh2 | ||
+ | Jul 4 19:49:25 edmchome sshd[8209]: Failed password for root from 80.84.55.183 port 12167 ssh2 | ||
+ | Jul 4 19:49:28 edmchome sshd[8209]: Failed password for root from 80.84.55.183 port 12167 ssh2 | ||
+ | Jul 4 19:49:31 edmchome sshd[8209]: Failed password for root from 80.84.55.183 port 12167 ssh2 | ||
+ | Jul 4 19:49:33 edmchome sshd[8209]: Failed password for root from 80.84.55.183 port 12167 ssh2 | ||
+ | Jul 4 19:49:33 edmchome sshd[8209]: Disconnecting: | ||
+ | Jul 4 19:49:33 edmchome sshd[8209]: PAM 5 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=80.84.55.183 | ||
+ | Jul 4 19:49:33 edmchome sshd[8209]: PAM service(sshd) ignoring max retries; 6 > 3 | ||
+ | Jul 4 19:49:35 edmchome sshd[8213]: reverse mapping checking getaddrinfo for 183-55-84-80.rackcentre.redstation.net.uk [80.84.55.183] failed - POSSIBLE BREAK-IN ATTEMPT! | ||
+ | Jul 4 19:49:35 edmchome sshd[8213]: pam_unix(sshd: | ||
+ | Jul 4 19:49:37 edmchome sshd[8213]: Failed password for root from 80.84.55.183 port 12290 ssh2 | ||
+ | Jul 4 19:49:40 edmchome sshd[8213]: Failed password for root from 80.84.55.183 port 12290 ssh2 | ||
+ | Jul 4 19:49:43 edmchome sshd[8213]: Failed password for root from 80.84.55.183 port 12290 ssh2 | ||
+ | Jul 4 19:49:45 edmchome sshd[8213]: Failed password for root from 80.84.55.183 port 12290 ssh2 | ||
+ | Jul 4 19:49:47 edmchome sshd[8213]: Failed password for root from 80.84.55.183 port 12290 ssh2 | ||
+ | Jul 4 19:49:50 edmchome sshd[8213]: Failed password for root from 80.84.55.183 port 12290 ssh2 | ||
+ | Jul 4 19:49:50 edmchome sshd[8213]: Disconnecting: | ||
+ | Jul 4 19:49:50 edmchome sshd[8213]: PAM 5 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=80.84.55.183 | ||
+ | Jul 4 19:49:50 edmchome sshd[8213]: PAM service(sshd) ignoring max retries; 6 > 3 | ||
+ | </ | ||
+ | |||
+ | A peine un port ssh ouvert sur la toile que déjà des milliers de tentative de connexions qui génère des logs à n'en plus finir. | ||
+ | |||
+ | On va donc modifier le niveau de verbosité des logs de sshd | ||
+ | > | ||
+ | > Donne le niveau de verbosité utilisé lors de l' | ||
+ | > Par défaut INFO. DEBUG et DEBUG1 sont équivalents. DEBUG2 et DEBUG3 spécifient des niveaux plus élevés de sortie de débogage. L' | ||
+ | |||
+ | vi / | ||
+ | LogLevel QUIET | ||
+ | |||
+ | service ssh reload | ||
+ | |||
+ | Inconvénient, | ||
+ | |||
+ | voir aussi dans / | ||
+ | |||
+ | Commenter la ligne suivante pour ne plus rien recevoir dans /var/log/auth.log | ||
+ | # | ||
+ | et relancez le service des journaux | ||
+ | service rsyslog restart | ||
+ | |||
+ | |||
+ | --- | ||
+ | |||
+ | Dans auth.log il y a aussi un paquet de ligne venant de cron | ||
+ | < | ||
+ | Jun 24 20:35:01 edmchome CRON[9024]: pam_unix(cron: | ||
+ | Jun 24 20:35:01 edmchome CRON[9024]: pam_unix(cron: | ||
+ | Jun 24 20:36:01 edmchome CRON[9040]: pam_unix(cron: | ||
+ | Jun 24 20:36:01 edmchome CRON[9040]: pam_unix(cron: | ||
+ | Jun 24 20:37:01 edmchome CRON[9056]: pam_unix(cron: | ||
+ | Jun 24 20:37:02 edmchome CRON[9056]: pam_unix(cron: | ||
+ | Jun 24 20:38:01 edmchome CRON[9072]: pam_unix(cron: | ||
+ | Jun 24 20:38:01 edmchome CRON[9072]: pam_unix(cron: | ||
+ | Jun 24 20:39:01 edmchome CRON[9088]: pam_unix(cron: | ||
+ | Jun 24 20:39:01 edmchome CRON[9088]: pam_unix(cron: | ||
+ | Jun 24 20:40:01 edmchome CRON[9104]: pam_unix(cron: | ||
+ | Jun 24 20:40:02 edmchome CRON[9104]: pam_unix(cron: | ||
+ | Jun 24 20:41:01 edmchome CRON[9120]: pam_unix(cron: | ||
+ | Jun 24 20:41:01 edmchome CRON[9120]: pam_unix(cron: | ||
+ | Jun 24 20:42:01 edmchome CRON[9136]: pam_unix(cron: | ||
+ | Jun 24 20:42:02 edmchome CRON[9136]: pam_unix(cron: | ||
+ | Jun 24 20:43:01 edmchome CRON[9152]: pam_unix(cron: | ||
+ | Jun 24 20:43:01 edmchome CRON[9152]: pam_unix(cron: | ||
+ | Jun 24 20:44:01 edmchome CRON[9168]: pam_unix(cron: | ||
+ | Jun 24 20:44:01 edmchome CRON[9168]: pam_unix(cron: | ||
+ | Jun 24 20:45:01 edmchome CRON[9184]: pam_unix(cron: | ||
+ | Jun 24 20:45:02 edmchome CRON[9184]: pam_unix(cron: | ||
+ | Jun 24 20:46:01 edmchome CRON[9200]: pam_unix(cron: | ||
+ | Jun 24 20:46:01 edmchome CRON[9200]: pam_unix(cron: | ||
+ | Jun 24 20:47:01 edmchome CRON[9216]: pam_unix(cron: | ||
+ | Jun 24 20:47:02 edmchome CRON[9216]: pam_unix(cron: | ||
+ | Jun 24 20:48:01 edmchome CRON[9232]: pam_unix(cron: | ||
+ | Jun 24 20:48:01 edmchome CRON[9232]: pam_unix(cron: | ||
+ | Jun 24 20:49:01 edmchome CRON[9248]: pam_unix(cron: | ||
+ | Jun 24 20:49:01 edmchome CRON[9248]: pam_unix(cron: | ||
+ | Jun 24 20:50:01 edmchome CRON[9264]: pam_unix(cron: | ||
+ | Jun 24 20:50:02 edmchome CRON[9264]: pam_unix(cron: | ||
+ | Jun 24 20:51:01 edmchome CRON[9280]: pam_unix(cron: | ||
+ | Jun 24 20:51:01 edmchome CRON[9280]: pam_unix(cron: | ||
+ | Jun 24 20:52:01 edmchome CRON[9296]: pam_unix(cron: | ||
+ | Jun 24 20:52:02 edmchome CRON[9296]: pam_unix(cron: | ||
+ | Jun 24 20:53:01 edmchome CRON[9312]: pam_unix(cron: | ||
+ | Jun 24 20:53:01 edmchome CRON[9312]: pam_unix(cron: | ||
+ | Jun 24 20:54:01 edmchome CRON[9328]: pam_unix(cron: | ||
+ | Jun 24 20:54:01 edmchome CRON[9328]: pam_unix(cron: | ||
+ | Jun 24 20:55:01 edmchome CRON[9344]: pam_unix(cron: | ||
+ | </ | ||
+ | |||
+ | === 1ère méthode trouvé sur le net mais qui ne marche pas pour moi === | ||
+ | Pour éviter ça, modifiez **/ | ||
+ | vi / | ||
+ | |||
+ | après la ligne | ||
+ | session required pam_unix.so | ||
+ | ajoutez | ||
+ | session [success=1 default=ignore] pam_succeed_if.so service in cron quiet use_uid | ||
+ | |||
+ | Redémarrez le service crond | ||
+ | service cron restart | ||
+ | |||
+ | === 2ème méthode qui marche pour moi :) === | ||
+ | Configurer le rsyslog pour exclure ce type d' | ||
+ | vi / | ||
+ | Modifiez la ligne | ||
+ | auth, | ||
+ | par | ||
+ | :msg, contains, " | ||
+ | auth, | ||
+ | et redémarrez le service des journaux | ||
+ | service rsyslog restart | ||
+ | ==== messages ==== | ||
+ | |||
+ | ==== syslog ==== | ||
+ | Extrait: | ||
+ | < | ||
+ | Jul 4 06:26:19 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:26:31 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:26:43 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:26:59 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:27:18 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:27:33 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:27:49 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:28:05 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:28:15 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:28:34 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:28:46 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:28:57 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:29:11 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:29:21 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:29:31 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:29:50 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:30:00 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:30:10 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:30:25 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:30:32 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:30:46 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:30:56 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:31:11 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:31:20 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:31:31 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:31:45 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:31:55 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:32:09 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:32:18 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:32:26 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:32:35 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:32:55 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:33:11 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:33:30 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:33:44 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:33:54 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:34:08 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:34:20 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:34:30 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | Jul 4 06:34:39 edmchome dhclient: DHCPREQUEST on eth0 to 192.168.0.254 port 67 | ||
+ | </ | ||
+ | |||
+ | Rien trouvé de concret sur le net à part configurer son réseau en ip static ce dont je n'ai pas envie de faire. | ||
+ | |||
+ | Ma solution un peu brut mais qui marche est de faire un | ||
+ | killall dhclient | ||
+ | |||
+ | ---- | ||
+ | |||
+ | Extrait | ||
+ | < | ||
+ | Jul 5 09:17:01 edmchome / | ||
+ | Jul 5 10:17:01 edmchome / | ||
+ | Jul 5 11:17:01 edmchome / | ||
+ | Jul 5 12:17:01 edmchome / | ||
+ | Jul 5 13:17:01 edmchome / | ||
+ | Jul 5 14:17:01 edmchome / | ||
+ | Jul 5 15:17:01 edmchome / | ||
+ | Jul 5 16:17:01 edmchome / | ||
+ | Jul 5 17:17:01 edmchome / | ||
+ | Jul 5 18:17:01 edmchome / | ||
+ | Jul 5 19:17:01 edmchome / | ||
+ | Jul 5 20:17:01 edmchome / | ||
+ | Jul 5 21:17:01 edmchome / | ||
+ | </ | ||
- | ===== messages ===== | + | > Solution trouvé ici http:// |
- | ===== syslog ===== | + | Editer le fichier **/ |
+ | EXTRA_OPTS='-L 4' | ||
+ | Ce qui permet de logguer tout de même les erreurs, sinon remplacez 4 par 0 | ||
- | ===== user.log | + | Un petit redémarrage du service au cas ou |
+ | service cron restart | ||
+ | ==== user.log ==== | ||
- | ===== wtmp ===== | + | ==== wtmp ==== |
- | ===== rsnapshot.log | + | ==== rsnapshot.log ==== |
- | ===== kern.log | + | ==== kern.log ==== |
Extrait : | Extrait : | ||
Ligne 142: | Ligne 353: | ||
sysctl -p | sysctl -p | ||
- | ===== lastlog ===== | + | ==== lastlog |
+ | |||
+ | ==== daemon.log ==== | ||
+ | |||
+ | ===== Les services ===== | ||
+ | |||
+ | ==== console-kit-daemon ==== | ||
+ | Le paquet ConsoleKit est un environnement pour garder une trace des différents utilisateurs, | ||
+ | |||
+ | |||
+ | ==== polkitd ==== | ||
+ | |||
+ | ==== triggerhappy ==== | ||
+ | |||
+ | ==== dbus-daemon ==== | ||
+ | |||
+ | ===== Stopper tous les logs ===== | ||
+ | |||
+ | Solution radicale pour éviter l' | ||
+ | |||
+ | sudo systemctl stop rsyslog | ||
+ | sudo systemctl disable rsyslog | ||
+ | |||
+ | ou | ||
+ | |||
+ | Edit the file / | ||
- | ===== daemon.log ===== | + | ############### |
+ | #### RULES #### | ||
+ | ############### | ||
+ | add the following line. | ||
+ | *.* ~ | ||
+ | If you want to be more fine-grained you will need to read the file comments. | ||
+ | Do not forget to restart rsyslog daemon: | ||
+ | sudo service rsyslog restart | ||