How can I find out ANYTHING a user is doing?
Hi all,
I'm looking for a command to find out what anything a user is doing from an ssh terminal, basically beyond the scope of w or who. I'd like to know.. say, which folder a user is viewing, what command is being executed, what files are being accessed or copied, etc. If a user is using ssh, the only process listed with w is 'sshd'. When a friend is logged in, I'd like to know exactly what they're doing. Is there a log that keeps this information, a command that will list it, or is that limited by the ssh protocol? Thanks, ~icy |
the grsec patch's for the kernel include extra loging features, one you might find useful is the exec logging, basically every command executed will be recoded in the log .... makes reading a pain so you will probably want to get a log viewer
|
You may want to try Snare for Linux
http://www.intersectalliance.com/projects/Snare/ |
you could use top and filter out one username by pressing u
|
If they're not using a GUI and they are using the command line same as you are, another thing you could do to see exactially what they were up to is.
Code:
If they are running the GUI perhaps you could install something like VNC so that you can watch them, or even take control of them if need be. Hope that helped a bit. Cheers Tap :D |
All times are GMT -5. The time now is 08:56 PM. |