LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 08-18-2004, 10:04 PM   #1
disorderly
Member
 
Registered: Sep 2003
Location: NJ
Distribution: RHEL5
Posts: 154

Rep: Reputation: 30
determining who's been loggin in & doing what


hi guys,

i've just landed a new job and one of the things i have to do is to clear out all the old accounts on the linux box (running red hat 6). i'm not sure who's been using the system - how can i find out what activity has been going on? i have su privileges.

thanks!
disorderly
 
Old 08-18-2004, 10:15 PM   #2
btmiller
Senior Member
 
Registered: May 2004
Location: In the DC 'burbs
Distribution: Arch, Scientific Linux, Debian, Ubuntu
Posts: 4,290

Rep: Reputation: 378Reputation: 378Reputation: 378Reputation: 378
Look into the last, w, and who commands. If the system has process accounting enabled, you can use lastcomm to see what commands are being run. If not you'll have to root around the shell history files to see what people have been doing. RH6 is ancient. You should replace that machine with one running a modern OS. If that box hasn't been patched since install and it's unprotected by a firewall, it's probably been broken into many times by now.
 
Old 08-18-2004, 10:46 PM   #3
disorderly
Member
 
Registered: Sep 2003
Location: NJ
Distribution: RHEL5
Posts: 154

Original Poster
Rep: Reputation: 30
thanks for your quick reply btmiller - this is a big concern for me. i have no idea how to detect whether people have broken into the machine and the IT guy is no help. I'll try those command tomorrow morning and let you know what i find.

thanks a bunch,
disorderly
 
Old 08-18-2004, 11:07 PM   #4
btmiller
Senior Member
 
Registered: May 2004
Location: In the DC 'burbs
Distribution: Arch, Scientific Linux, Debian, Ubuntu
Posts: 4,290

Rep: Reputation: 378Reputation: 378Reputation: 378Reputation: 378
If you suspect a break-in, reboot the machine from known-good media and run tools like chkrootkit or rkhunter on it. You can also sniff and analyze the network traffic coming in and out of the machine withsomething like tcpdump or ethereal. But definitely take a good look around the system before deciding what to do. As I said, though, your goal should be to get such an old, unsupported OS off of your company's network.
 
Old 08-19-2004, 08:42 PM   #5
disorderly
Member
 
Registered: Sep 2003
Location: NJ
Distribution: RHEL5
Posts: 154

Original Poster
Rep: Reputation: 30
hello btmiller,

i used those commands and it looked like i was the only one logged in. only other person that had logged in was the hosting company's administrator ( i found out that the box is hosted remotely so i don't have physical access to it) and when i logged in and looked through files n stuff i saw the guy before me had left passwords like root's right in the open! geez ... anyway i called the hosting company and they told me that they filter by IP address so that made me feel better - hope that means only port 80 is open to public...

i now have to make the decision as to what OS to put on the sys and maybe what new hardware to order

thanks for your advice!
- disorderly
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
loggin on to my com from college docetes Linux - Newbie 4 07-03-2005 08:19 PM
Phục hồi dữ liệu bị mất???, cứ pollsite General 1 06-27-2005 12:39 PM
who has been loggin on? nukeu666 Linux - Newbie 3 09-12-2004 11:46 PM
loggin in as superuser? BajaNick Linux - Security 5 08-06-2003 09:56 PM
help! can't loggin islandkid Linux - General 1 03-16-2002 12:16 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 10:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration