I got a fail2ban alert that yesterday these 3 services restarted. I did not restart those myself. First time I see this and this server has been up for over 500 days. I'm just paranoid maybe I got hacked or something. I don't see anything unusual in logs other than successful authentications at times that I would have been in bed but it could be backup jobs that were logging in and it does not coincide with the time the restarts happened. (they happened before)
Is there anything I can check to ensure I did not get compromised? I looked for any new users, or other stuff like that, and don't see any unusual processes, but then again that's not saying much as they could be hiding themselves well. Root is not allowed to login to SSH so for someone to break in they'd have to know both the password of a user account AND root, so to me it seems unlikely.
Does logrotate have a tendancy of restarting services? First time I would see that happen though. But I do have a cron email for logrotate that happens around the same time the services restarted.
Also, I see lot of entries like this in dmesg, they are kinda alarming, is this someone trying to hack in somehow?
I've gotten those since day one of this server being deployed though so I'm guessing it's nothing major.
Is there anything I can check to ensure I did not get compromised? I looked for any new users, or other stuff like that, and don't see any unusual processes, but then again that's not saying much as they could be hiding themselves well. Root is not allowed to login to SSH so for someone to break in they'd have to know both the password of a user account AND root, so to me it seems unlikely.
Does logrotate have a tendancy of restarting services? First time I would see that happen though. But I do have a cron email for logrotate that happens around the same time the services restarted.
Also, I see lot of entries like this in dmesg, they are kinda alarming, is this someone trying to hack in somehow?
Code:
TCP: Treason uncloaked! Peer 216.185.83.238:50839/80 shrinks window 2978575884:2978575904. Repaired.
TCP: Treason uncloaked! Peer 216.185.83.238:1883/80 shrinks window 4225344903:4225344951. Repaired.
TCP: Treason uncloaked! Peer 216.185.83.238:1883/80 shrinks window 4225566823:4225566871. Repaired.
TCP: Treason uncloaked! Peer 216.185.83.238:1883/80 shrinks window 4226526043:4226526091. Repaired.
TCP: Treason uncloaked! Peer 216.185.83.238:46660/80 shrinks window 1712997817:1712997865. Repaired.
TCP: Treason uncloaked! Peer 216.185.83.238:46660/80 shrinks window 1713194633:1713194681. Repaired.
TCP: Treason uncloaked! Peer 216.185.83.238:50839/80 shrinks window 2982776304:2982776352. Repaired.
I've gotten those since day one of this server being deployed though so I'm guessing it's nothing major.
