LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 10-25-2005, 09:41 PM   #1
jayj
LQ Newbie
 
Registered: Oct 2005
Posts: 3

Rep: Reputation: 0
Investigating missing files


I'm currently looking into a problem where files are missing on a server. This is a shared system with four users and after a couple months of operation, it was discovered that files were missing.

The files in particular are the database files for postgresql and the files for a Java SDK. They're owned by the postgres user and root respectively. Though that may not be as important as I'm just wondering how I can pinpoint what happened.

Besides reviewing history for all the users, including root, and checking the system messages /var/log/messages, I don't know where else to determine what happened to the missing files. What complicates this investigation further is that the system messages do not go far back enough.

So my question is really, are there any other places that I can look to find out what happened to these files? Any suggestions would be very grateful.
 
Old 10-26-2005, 02:02 PM   #2
Tinkster
Moderator
 
Registered: Apr 2002
Location: earth
Distribution: slackware by choice, others too :} ... android.
Posts: 23,067
Blog Entries: 11

Rep: Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928
Hi,

and welcome to LQ!

Well, if the logs don't reach back far enough, and the
users history files aren't conclusive there's not much
you can do unless you have tripwire or some other
file-system monitor set-up and are actually monitoring
the disappearance of given files.


Cheers,
Tink
 
Old 10-27-2005, 10:23 PM   #3
jayj
LQ Newbie
 
Registered: Oct 2005
Posts: 3

Original Poster
Rep: Reputation: 0
Thanks Tinkster. I was afraid that would be the case. Thanks for the response.
 
Old 10-27-2005, 10:33 PM   #4
ciotog
Member
 
Registered: Mar 2004
Location: Canada
Distribution: Slackware current
Posts: 728
Blog Entries: 2

Rep: Reputation: 43
If you know the names of the missing files you could always use slocate to build a file database and then search for them. I don't know why they would change their location but it's worth a shot.

Which filesystem are you using?
 
Old 10-28-2005, 09:35 PM   #5
jayj
LQ Newbie
 
Registered: Oct 2005
Posts: 3

Original Poster
Rep: Reputation: 0
Thnaks but I already tried that However I used locate, not slocate. Do you think slocate will reveal anything that locate wouldnt?

The question is how did these files get moved or delete (seems more like the later)? After spending a couple hours taking look at all the logs, I can't find anything suspicious either. Of course there was no audio system so who knows if someone just did a really good job covering their tracks.

I don't think I'm going to be able to figure this one out since the back-up was not set up properly and so I don't have that either. This is certainly a lesson learned.
 
Old 10-28-2005, 10:01 PM   #6
Tinkster
Moderator
 
Registered: Apr 2002
Location: earth
Distribution: slackware by choice, others too :} ... android.
Posts: 23,067
Blog Entries: 11

Rep: Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928
slocate has no more functionality in terms of locating files
than locate, the main difference is that slocate will only
report files back to a user that he has permissions to :}

If you're worried that the machine might have been exploited
you definitely want to run "rootkit hunter" and "chkrootkit"
on the box, preferably from a live CD. If you want to you
could report your own thread and have it moved to Linux-
Security rather than General, you may get other opinions
there in regards to the exploit


Cheers,
Tink
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
missing files waqer Mandriva 5 12-25-2004 04:33 AM
Web browser loses a secure (https) connection. How/where do I start investigating? hello321_1999 Linux - Networking 1 12-15-2004 11:47 AM
The SEC is investigating BayStar jailbait General 1 07-11-2004 02:42 AM
Missing files Thinkgeekness Linux - General 3 01-09-2003 07:49 PM
Files missing!!! kurgan70 Linux - General 0 06-29-2001 10:59 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 12:39 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration