Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Mystery Root user

    General pfSense Questions
    2
    4
    704
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      Rosla
      last edited by

      Hi all,

      On one of our firewalls running 2.4.4-RELEASE OS in our logs we can see the following:

      Dec 6 13:55:25 login login on ttyu0 as root
      Dec 6 13:55:29 login login on ttyu0 as root
      Dec 6 13:55:34 login login on ttyu0 as root
      Dec 6 13:55:38 login login on ttyu0 as root
      Dec 6 13:55:43 login login on ttyu0 as root
      Dec 6 13:55:47 login login on ttyu0 as root
      Dec 6 13:55:52 login login on ttyu0 as root
      Dec 6 13:55:56 login login on ttyu0 as root
      Dec 6 13:56:01 login login on ttyu0 as root
      Dec 6 13:56:05 login login on ttyu0 as root
      Dec 6 13:56:09 login login on ttyu0 as root
      Dec 6 13:56:14 login login on ttyu0 as root
      Dec 6 13:56:18 login login on ttyu0 as root
      Dec 6 13:56:23 login login on ttyu0 as root
      Dec 6 13:56:27 login login on ttyu0 as root

      And from CLI we see that it is running some shell:

      [2.4.4-RELEASE][admin@xxxx]/root: w
      1:57PM up 1:49, 3 users, load averages: 0.49, 0.61, 0.57
      USER TTY FROM LOGIN@ IDLE WHAT
      root u0 - 1:57PM - -sh (sh)

      From installed packages we have only OVPN and Zabbix agent.

      Any ideas what can cause this?

      1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan
        last edited by Gertjan

        Hi,

        ttyu0 = a real COM port (serial) device.
        So, check what's hooked up to the Serial (also known as RS232) and rip out the cable. No more logins ^^

        Btw : follow the cable and you'll find the device => you found the user. All this pretty close to your pfSense box.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 1
        • R
          Rosla
          last edited by

          Hi @Gertjan,

          Thank you for clarification and you where right there is a usb/serial connected to the box.
          After removal all is good! :)

          1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan
            last edited by

            👍

            You next question will be : my UPS doesn't shut down pfSense anymore ....
            (or : what was the usage of this cable ? )

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 2
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.