(未知)用户始终登录到我的centos linux计算机

(未知)用户始终登录到我的centos linux计算机,linux,centos,Linux,Centos,我正在使用who命令检查登录到我的系统的用户。我发现一个名为unknown的用户登录了,这非常令人惊讶 myuser pts/1 localhost Thu Aug 6 20:27 still logged in myuser pts/2 :pts/1:S.0 Thu Aug 6 20:15 - 20:16 (00:00) myuser pts/1 localhost Thu Aug

我正在使用who命令检查登录到我的系统的用户。我发现一个名为unknown的用户登录了,这非常令人惊讶

myuser    pts/1        localhost        Thu Aug  6 20:27   still logged in
myuser    pts/2        :pts/1:S.0       Thu Aug  6 20:15 - 20:16  (00:00)
myuser    pts/1        localhost        Thu Aug  6 20:03 - 20:18  (00:15)
myuser    pts/2        :pts/1:S.0       Thu Aug  6 19:49 - 19:49  (00:00)
myuser    pts/1        localhost        Thu Aug  6 19:47 - 19:49  (00:02)
myuser    pts/1        localhost        Thu Aug  6 19:37 - 19:46  (00:09)
myuser    pts/1        localhost        Thu Aug  6 19:33 - 19:37  (00:03)
myuser    pts/1        :9               Thu Aug  6 19:32 - 19:33  (00:00)
myuser    pts/1        localhost        Thu Aug  6 19:26 - 19:32  (00:05)
myuser    pts/2        :pts/1:S.0       Thu Aug  6 19:22 - 19:22  (00:00)
myuser    pts/1        localhost        Thu Aug  6 19:22 - 19:22  (00:00)
myuser    pts/2        :pts/1:S.0       Thu Aug  6 19:15 - 19:16  (00:00)
myuser    pts/1        localhost        Thu Aug  6 19:15 - 19:16  (00:00)
myuser    pts/2        :pts/1:S.0       Thu Aug  6 19:13 - 19:13  (00:00)
myuser    pts/1        localhost        Thu Aug  6 19:13 - 19:13  (00:00)
myuser    pts/2        :pts/1:S.0       Thu Aug  6 19:12 - 19:13  (00:00)
myuser    pts/2        :pts/1:S.0       Thu Aug  6 19:11 - 19:11  (00:00)
myuser    pts/2        :pts/1:S.0       Thu Aug  6 19:10 - 19:10  (00:00)
myuser    pts/1        localhost        Thu Aug  6 18:37 - 19:13  (00:35)
myuser    pts/1        localhost        Thu Aug  6 18:17 - 18:21  (00:03)
myuser    pts/1        localhost        Thu Aug  6 18:09 - 18:13  (00:03)
myuser    pts/0        localhost.locald Thu Aug  6 00:48   still logged in
myuser    pts/0        localhost.locald Thu Aug  6 00:34 - 00:48  (00:14)
myuser    pts/1        :9               Wed Aug  5 23:01 - 23:01  (00:00)
myuser    pts/0        localhost.locald Wed Aug  5 22:00 - 00:34  (02:34)
myuser    pts/0        localhost        Wed Aug  5 21:06 - 21:06  (00:00)
myuser    pts/0        localhost        Wed Aug  5 20:57 - 20:59  (00:01)
myuser    pts/0        localhost        Wed Aug  5 20:56 - 20:56  (00:00)
myuser    pts/0        localhost        Wed Aug  5 20:56 - 20:56  (00:00)
myuser    pts/0        :9               Wed Aug  5 20:55 - 20:56  (00:00)
myuser    pts/4        localhost        Wed Aug  5 20:14 - 20:55  (00:40)
myuser    pts/4        localhost        Wed Aug  5 20:11 - 20:12  (00:00)
myuser    pts/5        localhost        Wed Aug  5 19:52 - 19:56  (00:04)
myuser    pts/4        localhost        Wed Aug  5 19:29 - 19:31  (00:02)
myuser    pts/2        localhost        Wed Aug  5 18:42 - 19:32  (00:49)
myuser    pts/2        localhost        Wed Aug  5 18:42 - 18:42  (00:00)
myuser    pts/3        :9               Wed Aug  5 18:38 - 18:42  (00:04)
myuser    pts/3        localhost        Wed Aug  5 16:28 - 16:28  (00:00)
myuser    pts/2        :9               Wed Aug  5 16:26 - 16:28  (00:02)
(unknown :0           :0               Wed Aug  5 16:25   still logged in
世卫组织命令的结果:

 myuser    pts/1        Aug  6 20:27 (localhost)
 (unknown) :0          Aug  5 16:25 (:0) 
 myuser    pts/0        Aug  6 00:48 (localhost.localdomain)
但当我尝试运行w时,结果不同:

20:46:53 up 1 day, 23:11,  3 users,  load average: 1.00, 1.01, 1.05
USER     TTY      FROM             LOGIN@   IDLE   JCPU   PCPU WHAT
myuser    pts/1    localhost        20:27    5.00s  0.20s  0.03s w
myuser    pts/0    localhost.locald 00:48   19:57m  0.08s  1.71s python2 -m guake.main
我无法在名为unknown的计算机上找到任何用户。关于审理sudo su unknown/(unknown)

我上次试过运行它显示未知用户仍在登录

myuser    pts/1        localhost        Thu Aug  6 20:27   still logged in
myuser    pts/2        :pts/1:S.0       Thu Aug  6 20:15 - 20:16  (00:00)
myuser    pts/1        localhost        Thu Aug  6 20:03 - 20:18  (00:15)
myuser    pts/2        :pts/1:S.0       Thu Aug  6 19:49 - 19:49  (00:00)
myuser    pts/1        localhost        Thu Aug  6 19:47 - 19:49  (00:02)
myuser    pts/1        localhost        Thu Aug  6 19:37 - 19:46  (00:09)
myuser    pts/1        localhost        Thu Aug  6 19:33 - 19:37  (00:03)
myuser    pts/1        :9               Thu Aug  6 19:32 - 19:33  (00:00)
myuser    pts/1        localhost        Thu Aug  6 19:26 - 19:32  (00:05)
myuser    pts/2        :pts/1:S.0       Thu Aug  6 19:22 - 19:22  (00:00)
myuser    pts/1        localhost        Thu Aug  6 19:22 - 19:22  (00:00)
myuser    pts/2        :pts/1:S.0       Thu Aug  6 19:15 - 19:16  (00:00)
myuser    pts/1        localhost        Thu Aug  6 19:15 - 19:16  (00:00)
myuser    pts/2        :pts/1:S.0       Thu Aug  6 19:13 - 19:13  (00:00)
myuser    pts/1        localhost        Thu Aug  6 19:13 - 19:13  (00:00)
myuser    pts/2        :pts/1:S.0       Thu Aug  6 19:12 - 19:13  (00:00)
myuser    pts/2        :pts/1:S.0       Thu Aug  6 19:11 - 19:11  (00:00)
myuser    pts/2        :pts/1:S.0       Thu Aug  6 19:10 - 19:10  (00:00)
myuser    pts/1        localhost        Thu Aug  6 18:37 - 19:13  (00:35)
myuser    pts/1        localhost        Thu Aug  6 18:17 - 18:21  (00:03)
myuser    pts/1        localhost        Thu Aug  6 18:09 - 18:13  (00:03)
myuser    pts/0        localhost.locald Thu Aug  6 00:48   still logged in
myuser    pts/0        localhost.locald Thu Aug  6 00:34 - 00:48  (00:14)
myuser    pts/1        :9               Wed Aug  5 23:01 - 23:01  (00:00)
myuser    pts/0        localhost.locald Wed Aug  5 22:00 - 00:34  (02:34)
myuser    pts/0        localhost        Wed Aug  5 21:06 - 21:06  (00:00)
myuser    pts/0        localhost        Wed Aug  5 20:57 - 20:59  (00:01)
myuser    pts/0        localhost        Wed Aug  5 20:56 - 20:56  (00:00)
myuser    pts/0        localhost        Wed Aug  5 20:56 - 20:56  (00:00)
myuser    pts/0        :9               Wed Aug  5 20:55 - 20:56  (00:00)
myuser    pts/4        localhost        Wed Aug  5 20:14 - 20:55  (00:40)
myuser    pts/4        localhost        Wed Aug  5 20:11 - 20:12  (00:00)
myuser    pts/5        localhost        Wed Aug  5 19:52 - 19:56  (00:04)
myuser    pts/4        localhost        Wed Aug  5 19:29 - 19:31  (00:02)
myuser    pts/2        localhost        Wed Aug  5 18:42 - 19:32  (00:49)
myuser    pts/2        localhost        Wed Aug  5 18:42 - 18:42  (00:00)
myuser    pts/3        :9               Wed Aug  5 18:38 - 18:42  (00:04)
myuser    pts/3        localhost        Wed Aug  5 16:28 - 16:28  (00:00)
myuser    pts/2        :9               Wed Aug  5 16:26 - 16:28  (00:02)
(unknown :0           :0               Wed Aug  5 16:25   still logged in

知道怎么做吗?

我在过去的Fedora安装中看到过这种情况,当时我从tty启动X(不是在init 5中) 在red hat中,存在一个与此问题相关的漏洞(但可能您甚至没有运行基于red hat的发行版)


看看它,有一些可能的解释,但取决于你在盒子里运行的是什么

我不久前在Fedora主机上遇到过类似的问题。 在我的例子中,我发现是X系统在/var/run/utmp中创建了一个错误的条目

这是本书的最后一页

也许您没有使用Fedora,但我建议尝试禁用X并检查您是否仍有(未知)用户登录


希望这能有所帮助。

我正在用gnome运行centos 7,因为bug说可能是gdm在/var/run/utmpyes上写错了东西。这基本上是因为gdm在/var/run/utmp中创建了错误的条目,但我需要运行vnc服务器,所以我需要这样做:)