LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-06-2004, 07:12 AM   #1
danielw
Member
 
Registered: Jul 2003
Location: Australia
Distribution: CRUX
Posts: 35

Rep: Reputation: 15
possible comprimise? files dissappearing... pls help.


hey there,

I have a linux server running SME 6.0 Linux and lately users have been complaining that certain files have gone missing or have been reverted to older versions of the file. These files are stored in i-bays (samba shares) and are accessed by windows users inside the network. I don't know if I've been comprised or if some dodgey worker is deleting these files and / or replacing them with older versions.

Is there any way I can view logs of when someone has logged in via ssh, and also if there are any logs for samba usage?

Users have been very vauge in the description of the problem so I've asked them to compile a list of files that have gone missing so I can restore them off a previous tape backup.

From my knowledge, files can't simply go missing like that. Server was working for over 3 weeks before this started to occur and this leads me to believe it's caused due to some human intervention.
If I'm also being vauge in the description pls tell me and I'll try and fill in the blanks.
 
Old 04-06-2004, 07:48 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
You can use the last -i command to see recent login activity. Samba should log all activity to /var/log/samba/ . If that doesn't exist, check your smb.conf file to see where it's logging:

# this tells Samba to use a separate log file for each machine
# that connects
log file = /var/log/samba/%m.log

Sounds more like a user doing something stupid (intentionally or not) rather than a cracker. I find it hard to believe someone would go through the trouble of breaking into your system and the only thing they do is delete files in a smb share and replace them with older versions.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
system comprimise vi kde desktop sharing ? nilleso Linux - Security 6 11-27-2004 02:30 PM
Question regarding files pls help!! steve_2010 Solaris / OpenSolaris 9 02-25-2004 03:27 PM
pls pls pls help me ! i'm tired with httpd config on fedora apache 2.0.48 AngelOfTheDamn Fedora 0 01-24-2004 05:12 PM
No files in an account!!! Pls. Help!!! swmok Linux - Software 2 12-12-2003 05:23 AM
listening to .pls files on RH9 PionexUser Linux - General 1 10-27-2003 03:50 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:24 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration