LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise
User Name
Password
Linux - Enterprise This forum is for all items relating to using Linux in the Enterprise.

Notices


Reply
  Search this Thread
Old 12-09-2008, 02:55 PM   #1
avklinux
Member
 
Registered: Nov 2008
Posts: 32

Rep: Reputation: 15
How to : Identify changes made with root ?


Hello friends ,

Any one have an idea for

How to : Identify changes made with root ?

For all Unix OS platform .


Thanks

AVKlinux
 
Old 12-10-2008, 07:54 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
During operations, after it happened, what? Please elaborate.
 
Old 12-10-2008, 09:02 AM   #3
rweaver
Senior Member
 
Registered: Dec 2008
Location: Louisville, OH
Distribution: Debian, CentOS, Slackware, RHEL, Gentoo
Posts: 1,833

Rep: Reputation: 167Reputation: 167
Quote:
Originally Posted by avklinux View Post
Hello friends ,

Any one have an idea for

How to : Identify changes made with root ?

For all Unix OS platform .


Thanks

AVKlinux
If you don't suspect malicious activity then you can look at the /root/.bash_history if you're using bash (if its malicious it won't show what you're looking for in all likelihood.) You could also identify all files on the drive that have been changed in a given time frame using find. If you suspect malicious activity and aren't a security expert I would suggest using rkhunter/chkrootkit at the least and verifying the integrity of ps and ls using your package manager (eg: rpm -v).

If you wish to provide additional information on exactly what you mean, I'm sure we can provide more information.
 
Old 12-11-2008, 12:15 PM   #4
avklinux
Member
 
Registered: Nov 2008
Posts: 32

Original Poster
Rep: Reputation: 15
Changes In Root

Sorry for insufficient information .

But i just want to know how can we check the changes after login as a root .

Its applicable for changes in file permissions , security setting etc...

Thanks
AVKlinux
 
Old 12-11-2008, 12:18 PM   #5
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,635

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by avklinux View Post
Sorry for insufficient information .

But i just want to know how can we check the changes after login as a root .

Its applicable for changes in file permissions , security setting etc...
And yet you still don't provide any information. See the post from unSpawn....

WHAT CHANGES? WHAT ARE YOU LOOKING FOR???

You're question is very vague. If you want to know EVERYTHING that changed, you'll have to install something like Tripwire, and have it check on a routine basis. Otherwise, like rweaver told you, check the .bash_history, and follow the other suggestions that were made to you.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Why is access denied to files I haven't made but I'm the owner, I'm the root. Sonhi Fedora 8 08-12-2008 07:11 AM
Cannt login as root . made changes to .bash_profile hotbacteria Linux - General 5 02-01-2006 03:24 AM
Cannt login as root . made changes to .bash_profile hotbacteria Linux - Newbie 3 01-31-2006 10:03 PM
Cannt login as root . made changes to .bash_profile hotbacteria Linux - Newbie 3 01-31-2006 10:02 PM
Only root can do that! (but i made it SUID root ?) qwijibow Linux - General 4 07-07-2004 10:51 AM

LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise

All times are GMT -5. The time now is 12:20 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration