LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-17-2009, 08:21 AM   #1
yuanjunliang
LQ Newbie
 
Registered: Apr 2009
Posts: 22

Rep: Reputation: 0
How to find out if last history records were modified?


For example, user root log in the system at 3:00 AM, want to change or remove the record in the log in history.


Thanks
 
Old 08-17-2009, 04:20 PM   #2
catkin
LQ 5k Club
 
Registered: Dec 2008
Location: Tamil Nadu, India
Distribution: Debian
Posts: 8,578
Blog Entries: 31

Rep: Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208
What do you mean by "log in history" and why do you want to remove the log in record from itit?
 
Old 08-17-2009, 05:09 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Uh. No. Actually it's about wtmp and him needing to find out if/who changed any records.
 
Old 08-17-2009, 09:19 PM   #4
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,622

Rep: Reputation: 7964Reputation: 7964Reputation: 7964Reputation: 7964Reputation: 7964Reputation: 7964Reputation: 7964Reputation: 7964Reputation: 7964Reputation: 7964Reputation: 7964
Quote:
Originally Posted by yuanjunliang View Post
For example, user root log in the system at 3:00 AM, want to change or remove the record in the log in history.


Thanks
As unSpawn pointed out, it's about wtmp. If someone with root level access logs in, they can remove/reset that history, and edit the log files accordingly, to remove all traces.

Your only real hope, is to mirror your system log files to another server, with some really good security, so that not ALL traces can be removed. Otherwise, there really isn't a good way. Root can do ANYTHING.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Is there a history file that records logons in AIX 4.3 digitalgravy AIX 3 10-12-2006 12:24 PM
FIND files modified 1 hour before sachinh Linux - General 3 05-20-2006 04:42 AM
find today's modified files cranium2004 Linux - General 2 03-08-2006 09:24 PM
Find out if a file was modified in the last 2 minutes.... cricos Programming 5 04-06-2005 02:57 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:31 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration