Sep 25 00:44:49 dionysis rpc.statd[335]: gethostbyname error for [a very long non-conformant hostname] Sep 25 00:45:16 dionysis inetd[473]: extra conf for service telnet/tcp (skipped) Sep 25 00:45:28 dionysis in.telnetd[11554]: connect from 10.6.0.6 Sep 25 17:31:47 dionysis in.telnetd[12031]: connect from 10.6.0.6 Sep 25 17:32:08 dionysis in.telnetd[12035]: connect from 10.6.0.6
Figure 1: Initial break-in and later return by intruder. IP addresses have been replaced to protect the innocent.