- Server operating system version
- Almalinux 9.4
- Plesk version and microupdate number
- Plesk Obsidian 18.0.62 #1
Hello
Some days ago somebody upload a file to my domain, I didn't know how the guy made it, so I am exploring logs.
I found the upload in xferlog, it was made from an unknown IP, so I suspect the the guy broke my password or the proftpd server (how?)
Then looking in message and secure logs I've found something I can't understand. It's about users opening proftp sessions, it looks like there are two users: one for session and one for proftpd
I have a domain and several subdomains. Every domain has its own user for ftp access.
Reading this logs you can see that in secure log appears one user in systemd-user:session (some domains has not his line), and messages log shows just session user.
I wonder why? I suppose that both logs should show the ftp_user
When I open a ftp connection from any subdomain or from the main domain I get :
secure log file:
Jul 31 18:37:01 myservername systemd[2757962]: pam_unix(systemd-user:session): session opened for user other_user_name(uid=10004) by other_user_name(uid=0)
Jul 31 18:37:01 myservername proftpd[2757954]: pam_unix(proftpd:session): session opened for user ftp_user(uid=10004) by (uid=0)
message log file
Jul 31 18:37:01 myservername systemd[1]: Started ProFTPD FTP Server (xxx.xxx.xxx.xxx:48303).
Jul 31 18:37:01 myservername systemd-logind[701]: New session c1586 of user other_user_name.
Jul 31 18:37:01 myservername systemd[1]: Created slice User Slice of UID 10004.
Jul 31 18:37:01 myservername systemd[1]: Starting User Runtime Directory /run/user/10004...
Jul 31 18:37:01 myservername systemd[1]: Finished User Runtime Directory /run/user/10004.
Jul 31 18:37:01 myservername systemd[1]: Starting User Manager for UID 10004...
Jul 31 18:37:01 myservername systemd[2757962]: Queued start job for default target Main User Target.
Jul 31 18:37:01 myservername systemd[2757962]: Created slice User Application Slice.
Jul 31 18:37:01 myservername systemd[2757962]: Started Mark boot as successful after the user session has run 2 minutes.
Jul 31 18:37:01 myservername systemd[2757962]: Started Daily Cleanup of User's Temporary Directories.
Jul 31 18:37:01 myservername systemd[2757962]: Reached target Paths.
Jul 31 18:37:01 myservername systemd[2757962]: Reached target Timers.
Jul 31 18:37:01 myservername systemd[2757962]: Starting D-Bus User Message Bus Socket...
Jul 31 18:37:01 myservername systemd[2757962]: Starting Create User's Volatile Files and Directories...
Jul 31 18:37:01 myservername systemd[2757962]: Listening on D-Bus User Message Bus Socket.
Jul 31 18:37:01 myservername systemd[2757962]: Reached target Sockets.
Jul 31 18:37:01 myservername systemd[2757962]: Finished Create User's Volatile Files and Directories.
Jul 31 18:37:01 myservername systemd[2757962]: Reached target Basic System.
Jul 31 18:37:01 myservername systemd[2757962]: Reached target Main User Target.
Jul 31 18:37:01 myservername systemd[2757962]: Startup finished in 88ms.
Jul 31 18:37:01 myservername systemd[1]: Started User Manager for UID 10004.
Jul 31 18:37:01 myservername systemd[1]: Started Session c1586 of User other_user_name.
Thanks
Some days ago somebody upload a file to my domain, I didn't know how the guy made it, so I am exploring logs.
I found the upload in xferlog, it was made from an unknown IP, so I suspect the the guy broke my password or the proftpd server (how?)
Then looking in message and secure logs I've found something I can't understand. It's about users opening proftp sessions, it looks like there are two users: one for session and one for proftpd
I have a domain and several subdomains. Every domain has its own user for ftp access.
Reading this logs you can see that in secure log appears one user in systemd-user:session (some domains has not his line), and messages log shows just session user.
I wonder why? I suppose that both logs should show the ftp_user
When I open a ftp connection from any subdomain or from the main domain I get :
secure log file:
Jul 31 18:37:01 myservername systemd[2757962]: pam_unix(systemd-user:session): session opened for user other_user_name(uid=10004) by other_user_name(uid=0)
Jul 31 18:37:01 myservername proftpd[2757954]: pam_unix(proftpd:session): session opened for user ftp_user(uid=10004) by (uid=0)
message log file
Jul 31 18:37:01 myservername systemd[1]: Started ProFTPD FTP Server (xxx.xxx.xxx.xxx:48303).
Jul 31 18:37:01 myservername systemd-logind[701]: New session c1586 of user other_user_name.
Jul 31 18:37:01 myservername systemd[1]: Created slice User Slice of UID 10004.
Jul 31 18:37:01 myservername systemd[1]: Starting User Runtime Directory /run/user/10004...
Jul 31 18:37:01 myservername systemd[1]: Finished User Runtime Directory /run/user/10004.
Jul 31 18:37:01 myservername systemd[1]: Starting User Manager for UID 10004...
Jul 31 18:37:01 myservername systemd[2757962]: Queued start job for default target Main User Target.
Jul 31 18:37:01 myservername systemd[2757962]: Created slice User Application Slice.
Jul 31 18:37:01 myservername systemd[2757962]: Started Mark boot as successful after the user session has run 2 minutes.
Jul 31 18:37:01 myservername systemd[2757962]: Started Daily Cleanup of User's Temporary Directories.
Jul 31 18:37:01 myservername systemd[2757962]: Reached target Paths.
Jul 31 18:37:01 myservername systemd[2757962]: Reached target Timers.
Jul 31 18:37:01 myservername systemd[2757962]: Starting D-Bus User Message Bus Socket...
Jul 31 18:37:01 myservername systemd[2757962]: Starting Create User's Volatile Files and Directories...
Jul 31 18:37:01 myservername systemd[2757962]: Listening on D-Bus User Message Bus Socket.
Jul 31 18:37:01 myservername systemd[2757962]: Reached target Sockets.
Jul 31 18:37:01 myservername systemd[2757962]: Finished Create User's Volatile Files and Directories.
Jul 31 18:37:01 myservername systemd[2757962]: Reached target Basic System.
Jul 31 18:37:01 myservername systemd[2757962]: Reached target Main User Target.
Jul 31 18:37:01 myservername systemd[2757962]: Startup finished in 88ms.
Jul 31 18:37:01 myservername systemd[1]: Started User Manager for UID 10004.
Jul 31 18:37:01 myservername systemd[1]: Started Session c1586 of User other_user_name.
Thanks