Received: by ATHENA-PO-1.MIT.EDU (5.45/4.7) id AA18155; Tue, 30 Apr 91 19:11:35 EDT
Received: from CHARON.MIT.EDU by MIT.EDU with SMTP
	id AA05346; Tue, 30 Apr 91 19:09:23 EDT
Received: by charon.MIT.EDU 
	id AA05636; Tue, 30 Apr 91 19:09:16 EDT
Date: Tue, 30 Apr 91 19:09:16 EDT
From: kerr@MIT.EDU (Deborah A Wallach)
Message-Id: <9104302309.AA05636@charon.MIT.EDU>
To: sipb@MIT.EDU
Subject: sipb*/breakin attempt


Who is administering the sipb* accounts?  Specifically the sipb29
account?  Someone has been trying to break into my machine from
charon.  

Apr 30 17:21:56 dim-sum login: REPEATED LOGIN FAILURES ON ttyp8 FROM CHARON.MIT.EDU, john

I looked at the lastlog, and this seems like the most likely culprit.  

sipb29    ttyp4    TERMINUS.LCS.MIT Tue Apr 30 17:22 - 17:25  (00:03)


Sorry, but I am suspicious of anyone logging in from terminus.  Did we
give this account out to someone (who would be logging into terminus)?
Or do we have a random breaking in?


			-Debby
