LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 08-17-2009, 08:21 AM   #1
yuanjunliang
LQ Newbie
 
Registered: Apr 2009
Posts: 21

Rep: Reputation: 0
How to find out if last history records were modified?


For example, user root log in the system at 3:00 AM, want to change or remove the record in the log in history.


Thanks
 
Old 08-17-2009, 04:20 PM   #2
catkin
LQ 5k Club
 
Registered: Dec 2008
Location: Tamil Nadu, India
Distribution: Slackware 13.37, Debian Squeeze
Posts: 7,987
Blog Entries: 25

Rep: Reputation: 1009Reputation: 1009Reputation: 1009Reputation: 1009Reputation: 1009Reputation: 1009Reputation: 1009Reputation: 1009
What do you mean by "log in history" and why do you want to remove the log in record from itit?
 
Old 08-17-2009, 05:09 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 21,599
Blog Entries: 47

Rep: Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413
Uh. No. Actually it's about wtmp and him needing to find out if/who changed any records.
 
Old 08-17-2009, 09:19 PM   #4
TB0ne
Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 10,003

Rep: Reputation: 1189Reputation: 1189Reputation: 1189Reputation: 1189Reputation: 1189Reputation: 1189Reputation: 1189Reputation: 1189Reputation: 1189
Quote:
Originally Posted by yuanjunliang View Post
For example, user root log in the system at 3:00 AM, want to change or remove the record in the log in history.


Thanks
As unSpawn pointed out, it's about wtmp. If someone with root level access logs in, they can remove/reset that history, and edit the log files accordingly, to remove all traces.

Your only real hope, is to mirror your system log files to another server, with some really good security, so that not ALL traces can be removed. Otherwise, there really isn't a good way. Root can do ANYTHING.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Is there a history file that records logons in AIX 4.3 digitalgravy AIX 3 10-12-2006 12:24 PM
FIND files modified 1 hour before sachinh Linux - General 3 05-20-2006 04:42 AM
find today's modified files cranium2004 Linux - General 2 03-08-2006 09:24 PM
Find out if a file was modified in the last 2 minutes.... cricos Programming 5 04-06-2005 02:57 PM


All times are GMT -5. The time now is 09:51 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration