Ahoj, prochazim si tak /var/auth/log a koukam, ze 4 dny zpatky (v tu dobu jsem nejak ubuntu instaloval) tam je toto:
Nov 8 12:12:18 minstrel useradd[19625]: new user: name=jetty, UID=112, GID=65534, home=/usr/share/jetty, shell=/bin/false
Nov 8 12:12:18 minstrel usermod[19630]: change user `jetty' password
Nov 8 12:12:18 minstrel chage[19635]: changed password expiry for jettya obcas se sem tam objevi toto:
Nov 9 23:27:14 minstrel su[5038]: Successful su for jetty by root
Nov 9 23:27:15 minstrel su[5038]: + console root:jetty
Nov 9 23:27:15 minstrel su[5037]: Successful su for jetty by root
Nov 9 23:27:15 minstrel su[5037]: + ??? root:jetty
Nov 9 23:27:15 minstrel su[5038]: pam_unix(su:session): session opened for user jetty by (uid=0)
Nov 9 23:27:16 minstrel su[5037]: pam_unix(su:session): session opened for user jetty by (uid=0)
Nov 9 23:27:16 minstrel su[5038]: pam_unix(su:session): session closed for user jetty
Nov 9 23:27:16 minstrel su[5037]: pam_unix(su:session): session closed for user jetty
je to neco systemoveho, nebo jde o neco podezreleho?