Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

If a 'train station' is where a train stops, what's a 'workstation'?


devel / comp.unix.shell / Re: could anyone suggest why every single file in my directory was touched around the same time?

SubjectAuthor
* could anyone suggest why every single file in my directory wasanthony example
+* Re: could anyone suggest why every single file in my directory was touched arounKeith Thompson
|`* Re: could anyone suggest why every single file in my directory wasanthony example
| +* Re: could anyone suggest why every single file in my directory wasDavid W. Hodgins
| |+- Re: could anyone suggest why every single file in my directory wasKenny McCormack
| |`* Re: could anyone suggest why every single file in my directory wasanthony example
| | `* Re: could anyone suggest why every single file in my directory wasDavid W. Hodgins
| |  +* Re: could anyone suggest why every single file in my directory wasanthony example
| |  |`- Re: could anyone suggest why every single file in my directory wasDavid W. Hodgins
| |  `* Re: could anyone suggest why every single file in my directory wasJorgen Grahn
| |   +- Re: could anyone suggest why every single file in my directory wasanthony example
| |   `- Re: could anyone suggest why every single file in my directory wasanthony example
| `* Re: could anyone suggest why every single file in my directory wasKenny McCormack
|  `* Re: could anyone suggest why every single file in my directory wasanthony example
|   `* Re: could anyone suggest why every single file in my directory wasDavid W. Hodgins
|    `* Re: could anyone suggest why every single file in my directory wasanthony example
|     +* Re: could anyone suggest why every single file in my directory wasKenny McCormack
|     |`* Re: could anyone suggest why every single file in my directory wasanthony example
|     | `* Re: could anyone suggest why every single file in my directory was touched arounBen Bacarisse
|     |  `- Re: could anyone suggest why every single file in my directory was touched arounKenny McCormack
|     `- Re: could anyone suggest why every single file in my directory was touched arounBen Bacarisse
+* Re: could anyone suggest why every single file in my directory was touched arounBen Bacarisse
|`* Re: could anyone suggest why every single file in my directory wasanthony example
| `* Re: could anyone suggest why every single file in my directory wasanthony example
|  `- Re: could anyone suggest why every single file in my directory was touched arounBen Bacarisse
+- Re: could anyone suggest why every single file in my directory wasEd Morton
`* Re: could anyone suggest why every single file in my directory wasJosef Moellers
 +- Re: could anyone suggest why every single file in my directory wasJosef Moellers
 +- Re: could anyone suggest why every single file in my directory wasKenny McCormack
 `- Re: could anyone suggest why every single file in my directory was touched arounBen Bacarisse

Pages:12
Re: could anyone suggest why every single file in my directory was touched around the same time?

<t0urbk$1o4hg$1@news.xmission.com>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=5067&group=comp.unix.shell#5067

  copy link   Newsgroups: comp.unix.shell
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!xmission!nnrp.xmission!.POSTED.shell.xmission.com!not-for-mail
From: gaze...@shell.xmission.com (Kenny McCormack)
Newsgroups: comp.unix.shell
Subject: Re: could anyone suggest why every single file in my directory was
touched around the same time?
Date: Thu, 17 Mar 2022 08:26:28 -0000 (UTC)
Organization: The official candy of the new Millennium
Message-ID: <t0urbk$1o4hg$1@news.xmission.com>
References: <058fee24-a42e-4ded-b3ac-f5ca39c9cc68n@googlegroups.com> <j9g5i9Fatb3U1@mid.individual.net>
Injection-Date: Thu, 17 Mar 2022 08:26:28 -0000 (UTC)
Injection-Info: news.xmission.com; posting-host="shell.xmission.com:166.70.8.4";
logging-data="1839664"; mail-complaints-to="abuse@xmission.com"
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: gazelle@shell.xmission.com (Kenny McCormack)
 by: Kenny McCormack - Thu, 17 Mar 2022 08:26 UTC

In article <j9g5i9Fatb3U1@mid.individual.net>,
Josef Moellers <josef.moellers@invalid.invalid> wrote:
>
>On 16.03.22 18:55, anthony example wrote:
>> I am a user at an institution with a small, essentially hobbyist linux server
>which I access by ssh for email and some other work. Some hobbyist programming I
>do has generated a ton of files. Recently I noticed that every single one of my
>files (there are tens of thousands, in a spaghetti-like folder structure that has
>accumulated over the years) had an access time (viewed using ls -lau) of the
>night before, within a span of a couple of hours, at a time when I wasn't logged
>in.
>
>Do you have mlocate installed?
>It runs the "updatedb" program in regular intervals which may account
>for the access (I haven't checked this, though).

Yes, I mentioned this earlier, but the issue is still "Why only OP?".

That question seems to invalidate any possibility of it being some known
system process (e.g., backups or (m)locate).

--
This is the GOP's problem. When you're at the beginning of the year
and you've got nine Democrats running for the nomination, maybe one or
two of them are Dennis Kucinich. When you have nine Republicans, seven
or eight of them are Michelle Bachmann.

Re: could anyone suggest why every single file in my directory was touched around the same time?

<87r170zdjd.fsf@bsb.me.uk>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=5078&group=comp.unix.shell#5078

  copy link   Newsgroups: comp.unix.shell
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: ben.use...@bsb.me.uk (Ben Bacarisse)
Newsgroups: comp.unix.shell
Subject: Re: could anyone suggest why every single file in my directory was touched around the same time?
Date: Thu, 17 Mar 2022 17:36:54 +0000
Organization: A noiseless patient Spider
Lines: 22
Message-ID: <87r170zdjd.fsf@bsb.me.uk>
References: <058fee24-a42e-4ded-b3ac-f5ca39c9cc68n@googlegroups.com>
<j9g5i9Fatb3U1@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain
Injection-Info: reader02.eternal-september.org; posting-host="8179eac41ad0d4ebbe49b8fa97db0394";
logging-data="27551"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19M6VaT5Zy5r41WMGnJmLWKNVHKUV1kSmw="
Cancel-Lock: sha1:iWoeEvbDusQwJ9eEp90LD8XDHBU=
sha1:LfJhPFDl/zUwWwbr2gq7qGPYs/w=
X-BSB-Auth: 1.558345fbd9fc9d8d03a9.20220317173655GMT.87r170zdjd.fsf@bsb.me.uk
 by: Ben Bacarisse - Thu, 17 Mar 2022 17:36 UTC

Josef Moellers <josef.moellers@invalid.invalid> writes:

> On 16.03.22 18:55, anthony example wrote:
>> I am a user at an institution with a small, essentially hobbyist
>> linux server which I access by ssh for email and some other
>> work. Some hobbyist programming I do has generated a ton of
>> files. Recently I noticed that every single one of my files (there
>> are tens of thousands, in a spaghetti-like folder structure that has
>> accumulated over the years) had an access time (viewed using ls -lau)
>> of the night before, within a span of a couple of hours, at a time
>> when I wasn't logged in.
>
> Do you have mlocate installed?
> It runs the "updatedb" program in regular intervals which may account
> for the access (I haven't checked this, though).

I don't think updatedb reads files since all it needs to know is the
content of directories. I can "locate" files that have access dates
years in the past (so I know they are in the database).

--
Ben.

Re: could anyone suggest why every single file in my directory was touched around the same time?

<slrnt38fgm.1rfm.grahn+nntp@frailea.sa.invalid>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=5091&group=comp.unix.shell#5091

  copy link   Newsgroups: comp.unix.shell
Path: i2pn2.org!i2pn.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: grahn+n...@snipabacken.se (Jorgen Grahn)
Newsgroups: comp.unix.shell
Subject: Re: could anyone suggest why every single file in my directory was
touched around the same time?
Date: 18 Mar 2022 08:08:54 GMT
Lines: 35
Message-ID: <slrnt38fgm.1rfm.grahn+nntp@frailea.sa.invalid>
References: <058fee24-a42e-4ded-b3ac-f5ca39c9cc68n@googlegroups.com>
<875yod4ufb.fsf@nosuchdomain.example.com>
<fd1970f5-6c05-4644-8918-a262a84b5aa9n@googlegroups.com>
<op.1i4z84hfa3w0dxdave@hodgins.homeip.net>
<b8dbede7-c70e-42a8-b14d-6e8d106219a4n@googlegroups.com>
<op.1i433ecua3w0dxdave@hodgins.homeip.net>
X-Trace: individual.net fA8qQvYJyrsvZNKlpWAPeAH+On700S7J7VcisM9BCXedN9oj1m
Cancel-Lock: sha1:GwSLNrEz5SQbgVJVBHe7z1CXSU0=
User-Agent: slrn/1.0.3 (OpenBSD)
 by: Jorgen Grahn - Fri, 18 Mar 2022 08:08 UTC

On Wed, 2022-03-16, David W. Hodgins wrote:
> On Wed, 16 Mar 2022 15:48:21 -0400, anthony example <anthony974412@gmail.com> wrote:
>
>> On Wednesday, March 16, 2022 at 2:57:04 PM UTC-4, David W. Hodgins wrote:

>>> Is any indexing software installed such as Gnome's tracker2? Was
>>> the host system rebooted shortly before the files were accessed?
>>
>> I'll find out. But it seems hard to reconcile something like that
>> with the fact that other users' files were not accessed.
>>
>> Would the "strain" of transferring tens of thousands of files,
>> experienced by a server that typically handles very little traffic,
>> have to show up in any default logs?

If there's logging of network traffic and the server isn't doing much,
it would show up as a big download bump on the graph. Either the
sysadmin knows about the logging (because he set it up) or it's
sysstat which might, if you're lucky, be enabled "by accident".

> Another indexing system is kde's akonadi.

Not to mention locate/updatedb, which is widely deployed[1]. But that
one runs every night, doesn't access /files/, and either crawls all
home directories, or none of them.

/Jorgen

[1] I once found a porn collection at a workplace by typing "locate
pussy". The actual porn was gone, but the file names were still,
for whatever reason, in the index.

--
// Jorgen Grahn <grahn@ Oo o. . .
\X/ snipabacken.se> O o .

Re: could anyone suggest why every single file in my directory was touched around the same time?

<b0bedd22-5501-489c-b530-1d7cfcb6d5den@googlegroups.com>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=5104&group=comp.unix.shell#5104

  copy link   Newsgroups: comp.unix.shell
X-Received: by 2002:a05:6214:4104:b0:42c:1db0:da28 with SMTP id kc4-20020a056214410400b0042c1db0da28mr7917542qvb.67.1647625053954;
Fri, 18 Mar 2022 10:37:33 -0700 (PDT)
X-Received: by 2002:a0c:bf48:0:b0:42c:b061:f869 with SMTP id
b8-20020a0cbf48000000b0042cb061f869mr7972485qvj.98.1647625053788; Fri, 18 Mar
2022 10:37:33 -0700 (PDT)
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.misty.com!border2.nntp.dca1.giganews.com!nntp.giganews.com!news-out.google.com!nntp.google.com!postnews.google.com!google-groups.googlegroups.com!not-for-mail
Newsgroups: comp.unix.shell
Date: Fri, 18 Mar 2022 10:37:33 -0700 (PDT)
In-Reply-To: <slrnt38fgm.1rfm.grahn+nntp@frailea.sa.invalid>
Injection-Info: google-groups.googlegroups.com; posting-host=142.157.237.157; posting-account=satfYAoAAAC3KP6KFuI83GzQroozdC8l
NNTP-Posting-Host: 142.157.237.157
References: <058fee24-a42e-4ded-b3ac-f5ca39c9cc68n@googlegroups.com>
<875yod4ufb.fsf@nosuchdomain.example.com> <fd1970f5-6c05-4644-8918-a262a84b5aa9n@googlegroups.com>
<op.1i4z84hfa3w0dxdave@hodgins.homeip.net> <b8dbede7-c70e-42a8-b14d-6e8d106219a4n@googlegroups.com>
<op.1i433ecua3w0dxdave@hodgins.homeip.net> <slrnt38fgm.1rfm.grahn+nntp@frailea.sa.invalid>
User-Agent: G2/1.0
MIME-Version: 1.0
Message-ID: <b0bedd22-5501-489c-b530-1d7cfcb6d5den@googlegroups.com>
Subject: Re: could anyone suggest why every single file in my directory was
touched around the same time?
From: anthony9...@gmail.com (anthony example)
Injection-Date: Fri, 18 Mar 2022 17:37:33 +0000
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Lines: 18
 by: anthony example - Fri, 18 Mar 2022 17:37 UTC

On Friday, March 18, 2022 at 4:09:00 AM UTC-4, Jorgen Grahn wrote:

> If there's logging of network traffic and the server isn't doing much,
> it would show up as a big download bump on the graph. Either the
> sysadmin knows about the logging (because he set it up) or it's
> sysstat which might, if you're lucky, be enabled "by accident".
> > Another indexing system is kde's akonadi.
> Not to mention locate/updatedb, which is widely deployed[1]. But that
> one runs every night, doesn't access /files/, and either crawls all
> home directories, or none of them.

Here's another question, though it's probably hard to answer: if someone knew enough to break in and download files without leaving traces of a login, isn't it also likely that they would know enough to leave access times untouched? I imagine it would be simple to automate checking the last access time before downloading, then copying the file, then restoring the previous access time by using 'touch'? Wouldn't that be "hacking 101"? I'm grasping at straws, trying to find a way to believe I haven't had everything copied by a malicious actor.

Re: could anyone suggest why every single file in my directory was touched around the same time?

<391c27c4-4f9e-441e-8d8b-f93b8397613en@googlegroups.com>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=5105&group=comp.unix.shell#5105

  copy link   Newsgroups: comp.unix.shell
X-Received: by 2002:a05:620a:e1c:b0:47d:87eb:18b2 with SMTP id y28-20020a05620a0e1c00b0047d87eb18b2mr6784255qkm.527.1647638934971;
Fri, 18 Mar 2022 14:28:54 -0700 (PDT)
X-Received: by 2002:a05:622a:3c7:b0:2e1:cdf9:666b with SMTP id
k7-20020a05622a03c700b002e1cdf9666bmr8815338qtx.438.1647638934804; Fri, 18
Mar 2022 14:28:54 -0700 (PDT)
Path: i2pn2.org!i2pn.org!aioe.org!news.uzoreto.com!2.eu.feeder.erje.net!feeder.erje.net!proxad.net!feeder1-2.proxad.net!209.85.160.216.MISMATCH!news-out.google.com!nntp.google.com!postnews.google.com!google-groups.googlegroups.com!not-for-mail
Newsgroups: comp.unix.shell
Date: Fri, 18 Mar 2022 14:28:54 -0700 (PDT)
In-Reply-To: <slrnt38fgm.1rfm.grahn+nntp@frailea.sa.invalid>
Injection-Info: google-groups.googlegroups.com; posting-host=142.157.237.157; posting-account=satfYAoAAAC3KP6KFuI83GzQroozdC8l
NNTP-Posting-Host: 142.157.237.157
References: <058fee24-a42e-4ded-b3ac-f5ca39c9cc68n@googlegroups.com>
<875yod4ufb.fsf@nosuchdomain.example.com> <fd1970f5-6c05-4644-8918-a262a84b5aa9n@googlegroups.com>
<op.1i4z84hfa3w0dxdave@hodgins.homeip.net> <b8dbede7-c70e-42a8-b14d-6e8d106219a4n@googlegroups.com>
<op.1i433ecua3w0dxdave@hodgins.homeip.net> <slrnt38fgm.1rfm.grahn+nntp@frailea.sa.invalid>
User-Agent: G2/1.0
MIME-Version: 1.0
Message-ID: <391c27c4-4f9e-441e-8d8b-f93b8397613en@googlegroups.com>
Subject: Re: could anyone suggest why every single file in my directory was
touched around the same time?
From: anthony9...@gmail.com (anthony example)
Injection-Date: Fri, 18 Mar 2022 21:28:54 +0000
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
 by: anthony example - Fri, 18 Mar 2022 21:28 UTC

On Friday, March 18, 2022 at 4:09:00 AM UTC-4, Jorgen Grahn wrote:

> > Another indexing system is kde's akonadi.
> Not to mention locate/updatedb, which is widely deployed[1]. But that
> one runs every night, doesn't access /files/, and either crawls all
> home directories, or none of them.

Hi again everyone in this thread. I managed to get some more time with the sysadmin today after his other work, and he looked in some other users' directories -- people who hadn't logged in or modified any files for years and years -- and found that their files had all also been accessed in narrow time windows, similar to mine. Not all users though! And some at different times of day. Then he realised some users' files are stored on different servers and that might account for it -- his own user directory is on a different server than mine is. It still strikes him as very odd and he's going to try to find out what process could be doing it in this irregular way, but I'm starting to feel some relief that perhaps -- just perhaps -- I *wasn't* the victim of an elite international hacking squad.

It also made him realise that he should turn on some sort of sftp command logging and perhaps require a VPN for webmail access as he finds thousands of failed dovecot auth attempts for many users, from IP addresses all over the world.

Thanks everyone for weighing in.

Pages:12
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor