Hi,
Please can someone point me in the right direction.
Proxmox 4.4
Today one of our VM's experienced extremely high CPU load causing many systems to fail.
Upon logging into the proxmox GUI, I could see three messages
service: pve daemon : 'successful auth for user 'validuserid@pam'
This occurred at a time when a legitimate login by that user was impossible, and co-incided with the start of the problems.
It was only one VM affected not the whole node.
I'm obviously concerned that this was a hack.
I have checked /var/log/secure and there is no log of a login with that user id at that time. Where else should I be looking to establish what occurred?
Please can someone point me in the right direction.
Proxmox 4.4
Today one of our VM's experienced extremely high CPU load causing many systems to fail.
Upon logging into the proxmox GUI, I could see three messages
service: pve daemon : 'successful auth for user 'validuserid@pam'
This occurred at a time when a legitimate login by that user was impossible, and co-incided with the start of the problems.
It was only one VM affected not the whole node.
I'm obviously concerned that this was a hack.
I have checked /var/log/secure and there is no log of a login with that user id at that time. Where else should I be looking to establish what occurred?