LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 07-11-2008, 10:26 AM   #1
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Rep: Reputation: 55
rootsh not logging the underprivledges username


I installed rootsh but when I run
sudo /usr/local/bin/rootsh
it logs everything as the username root, instead of the underprivliged user.

Jul 11 10:10:19 testsrv rootsh[063f4]: root: root=root,/dev/pts/0: logging new session (rootsh[063f4]) to /var/log/rootsh/root.20080711101019.063f4
Jul 11 10:10:23 testsrv rootsh[063f4]: root: 000: root@testsrv [/root/rootsh-1.5.3]# whoami
Jul 11 10:10:23 testsrv rootsh[063f4]: root: 001: root
Jul 11 10:10:24 testsrv rootsh[063f4]: root: 002: root@testsrv [/root/rootsh-1.5.3]# exit
Jul 11 10:10:24 testsrv rootsh[063f4]: root: 003: exit
Jul 11 10:10:24 testsrv rootsh[063f4]: root: 004: *** rootsh session ended by user
Jul 11 10:10:24 testsrv rootsh[063f4]: root: 005:
Jul 11 10:10:24 testsrv rootsh[063f4]: root: root,/dev/pts/0: closing rootsh session (rootsh[063f4])
Jul 11 10:11:29 testsrv rootsh[0640b]: root: root=root,/dev/pts/0: logging new session (rootsh[0640b]) to /var/log/rootsh/root.20080711101129

Also all the files in /var/log/rootsh/ start with root.
even those that is suppose to be the underprivliged username.

Any ideas why its doing that?

TIA!
 
Old 07-12-2008, 06:24 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Try this: login as unprivileged user, now issue 'sudo rootsh -u root'. Then type 'lsof -w -n -p $$'. On file descriptor 3 it should show a log in the output dir you configured with in the name of the file the unprivileged username. If it's not doing that, what does it show when you start rootsh without arguments or sudo as unprivileged user? And how did you install Rootsh? From source (which compile flags?) or as package (which one?).
 
Old 07-12-2008, 07:45 AM   #3
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Original Poster
Rep: Reputation: 55
Thanks, its working now, I had to login as the user, before, I was loggedin as root and then su'ed to my sudo user.
 
Old 07-12-2008, 07:59 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
If I read your reply right, you *know* you shouldn't ever login as root account user in the first place! In any case, logging in as unprivileged user has the added benefit that you can run rootsh as their default shell. This means you not only get the audit trail when they sudo to another account but the trail for the regular user account as well. That's not only a good thing when you need to monitor allowed access by employees but also for say auditing third party access. Of course the AUP slash system banners should make clear the system is monitored.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Differance between su <username> and su <username> - guguma Linux - General 3 08-19-2007 01:01 PM
LXer: Rootsh terminal logger keeps watch on root users LXer Syndicated Linux News 0 05-03-2007 03:31 PM
hide username when logging in jonfa Linux - Security 2 04-30-2007 08:03 AM
Problems with username and logging in taien Linux - General 10 03-18-2006 02:11 PM
useradd: invalid username username$ engyeow Fedora 5 12-05-2004 04:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 06:21 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration