LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-03-2008, 11:45 PM   #1
y_zl
LQ Newbie
 
Registered: Jan 2008
Posts: 8

Rep: Reputation: 0
fedora 8 lastlog file was removed, intrution?


Hi,

Last time when I tried to login into my server through ssh. I keyed my password four times, login failed every time. Eventually I logged into my system, I think the password I previously entered was correct. After I logged in, I found the lastlog file was newly created, and previous records got lost. But for other file like secure, there are some file with name like secure-20080101,... stile exist, only this lastlog file left one.

Just want to know does it indicate somebody got into my system? and how could I verify that?

Regards
 
Old 06-04-2008, 04:00 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by y_zl View Post
After I logged in, I found the lastlog file was newly created, and previous records got lost. But for other file like secure, there are some file with name like secure-20080101,... stile exist, only this lastlog file left one. Just want to know does it indicate somebody got into my system?
As a standalone event it does not, IMHO. If you read 'man lastlog' you see it is a sparse file that must not be rotated, after all it only holds a set of volatile data, much like utmp, and not the kind of accounting wtmp holds.


Quote:
Originally Posted by y_zl View Post
and how could I verify that?
Verify and correlate your other logs: wtmp (see 'man last'), btmp (if any, see 'man lastb'), faillog ('man faillog'), /var/log/secure for logins. For generic error messages see per daemon logs in /var/log/ and /var/log/messages. If SElinux is enabled see /var/log/messages (and /var/log/audit/audit.log if you run Auditd). If you have any doubts you best run your auditing from a booted Live CD and verify your installation first with 'rpm -qVa' ('man rpm' for explanation of output). Checking timestamps, shell history and more steps are in the Intruder Detection Checklist (CERT): http://www.cert.org/tech_tips/intrud...checklist.html which should be good to know anyway.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Hacker's Intrution Attempt aq_mishu Linux - Security 24 04-21-2008 07:38 AM
Lastlog file -> missing users??? goodrookie Linux - Security 2 07-20-2006 11:57 AM
Remove "lastlog" log file shipon_97 Linux - Security 1 07-19-2006 04:29 AM
Files removed from file system during Fedora Core Upgrade gryphonavocatio Linux - General 5 09-21-2005 12:27 PM
Intrution Detection using Packet Analysis johnnyde Linux - Security 1 03-26-2005 09:33 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:28 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration