LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Ubuntu
User Name
Password
Ubuntu This forum is for the discussion of Ubuntu Linux.

Notices

Reply
 
LinkBack Search this Thread
Old 11-14-2008, 01:20 PM   #1
sulekha
Member
 
Registered: Dec 2004
Location: India
Distribution: ubuntu 10.04 , centos 5.5 , Debian lenny, Freenas
Posts: 292

Rep: Reputation: 35
Question This incident will be reported


Hi all,

whenever an user who is not in /etc/sudoers file issues the sudo command
we will get the following message

" .... is not in the sudoers file. This incident will be reported"


now my question is where does this reporting take place ?

from which file an administrator can know who all tinkered with sudo command ?

Is it /var/log/auth.log file ?
 
Old 11-14-2008, 03:49 PM   #2
indienick
Senior Member
 
Registered: Dec 2005
Location: London, ON, Canada
Distribution: Arch, Ubuntu, Slackware, OpenBSD, FreeBSD
Posts: 1,853

Rep: Reputation: 64
It might be - it might also be sent to /var/mail/root.
 
Old 11-14-2008, 04:13 PM   #3
colucix
Moderator
 
Registered: Sep 2003
Location: Bologna
Distribution: OpenSUSE 12.1 CentOS 6.2
Posts: 9,010

Rep: Reputation: 1353Reputation: 1353Reputation: 1353Reputation: 1353Reputation: 1353Reputation: 1353Reputation: 1353Reputation: 1353Reputation: 1353Reputation: 1353
From the sudo man page:
Code:
If a user who is not listed in the sudoers file tries to run a command via sudo, mail is sent to
the proper authorities, as defined at configure time or in the sudoers file (defaults to root).
Note that the mail will not be sent if an unauthorized user tries to run sudo with the -l or -v
flags.  This allows users to determine for themselves whether or not they are allowed to use sudo.
The log file is usually auth.log, as you already stated. You can see some entry like this:
Code:
Nov 14 21:09:58 localhost sudo:    pippo : user NOT in sudoers ; TTY=pts/1 ; PWD =/home/pippo ; USER=root ; COMMAND=/usr/bin/vi /etc/passwd
 
Old 11-15-2008, 05:47 AM   #4
sulekha
Member
 
Registered: Dec 2004
Location: India
Distribution: ubuntu 10.04 , centos 5.5 , Debian lenny, Freenas
Posts: 292

Original Poster
Rep: Reputation: 35
Question

Quote:
Originally Posted by indienick View Post
It might be - it might also be sent to /var/mail/root.
I tried this: zodiac@ubuntu:~$ cat /var/mail/root

cat: /var/mail/root: No such file or directory

NB: I use ubuntu hardy
 
Old 11-15-2008, 06:31 AM   #5
repo
LQ 5k Club
 
Registered: May 2001
Location: Belgium
Distribution: Slackware current
Posts: 8,460

Rep: Reputation: 874Reputation: 874Reputation: 874Reputation: 874Reputation: 874Reputation: 874Reputation: 874
Quote:
I tried this: zodiac@ubuntu:~$ cat /var/mail/root
cat: /var/mail/root: No such file or directory
AFAIK in ubuntu the mail for root is forwarded to a user
This is set in /etc/aliases
You can install logcheck to recieve email allerts when something happens on your system.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Security incident ycosmic Linux - Security 5 10-18-2005 03:08 PM
Any incident linux was infected with Virus/Worm and crashed? TigerLinux Linux - General 4 10-08-2005 05:59 AM
Wierd Incident php General 26 12-15-2003 02:43 PM
Recommendations for per-incident paid support? aquaphile Linux - General 4 11-07-2003 09:46 AM
Virus Incident Information madness! itsjustme Linux - Security 2 11-07-2003 01:45 AM


All times are GMT -5. The time now is 02:09 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration