LinuxQuestions.org
Latest LQ Deal: Complete CCNA, CCNP & Red Hat Certification Training Bundle
Home Forums HCL Reviews Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Ubuntu
User Name
Password
Ubuntu This forum is for the discussion of Ubuntu Linux.

Notices


Reply
  Search this Thread
Old 11-14-2008, 02:20 PM   #1
sulekha
Member
 
Registered: Dec 2004
Location: India
Distribution: ubuntu 10.04 , centos 5.5 , Debian lenny, Freenas
Posts: 324

Rep: Reputation: 36
Question This incident will be reported


Hi all,

whenever an user who is not in /etc/sudoers file issues the sudo command
we will get the following message

" .... is not in the sudoers file. This incident will be reported"


now my question is where does this reporting take place ?

from which file an administrator can know who all tinkered with sudo command ?

Is it /var/log/auth.log file ?
 
Old 11-14-2008, 04:49 PM   #2
indienick
Senior Member
 
Registered: Dec 2005
Location: London, ON, Canada
Distribution: Arch, Ubuntu, Slackware, OpenBSD, FreeBSD
Posts: 1,853

Rep: Reputation: 65
It might be - it might also be sent to /var/mail/root.
 
Old 11-14-2008, 05:13 PM   #3
colucix
LQ Guru
 
Registered: Sep 2003
Location: Bologna
Distribution: CentOS 6.5 OpenSuSE 12.3
Posts: 10,509

Rep: Reputation: 1978Reputation: 1978Reputation: 1978Reputation: 1978Reputation: 1978Reputation: 1978Reputation: 1978Reputation: 1978Reputation: 1978Reputation: 1978Reputation: 1978
From the sudo man page:
Code:
If a user who is not listed in the sudoers file tries to run a command via sudo, mail is sent to
the proper authorities, as defined at configure time or in the sudoers file (defaults to root).
Note that the mail will not be sent if an unauthorized user tries to run sudo with the -l or -v
flags.  This allows users to determine for themselves whether or not they are allowed to use sudo.
The log file is usually auth.log, as you already stated. You can see some entry like this:
Code:
Nov 14 21:09:58 localhost sudo:    pippo : user NOT in sudoers ; TTY=pts/1 ; PWD =/home/pippo ; USER=root ; COMMAND=/usr/bin/vi /etc/passwd
 
Old 11-15-2008, 06:47 AM   #4
sulekha
Member
 
Registered: Dec 2004
Location: India
Distribution: ubuntu 10.04 , centos 5.5 , Debian lenny, Freenas
Posts: 324

Original Poster
Rep: Reputation: 36
Question

Quote:
Originally Posted by indienick View Post
It might be - it might also be sent to /var/mail/root.
I tried this: zodiac@ubuntu:~$ cat /var/mail/root

cat: /var/mail/root: No such file or directory

NB: I use ubuntu hardy
 
Old 11-15-2008, 07:31 AM   #5
repo
LQ 5k Club
 
Registered: May 2001
Location: Belgium
Distribution: Arch
Posts: 8,528

Rep: Reputation: 899Reputation: 899Reputation: 899Reputation: 899Reputation: 899Reputation: 899Reputation: 899
Quote:
I tried this: zodiac@ubuntu:~$ cat /var/mail/root
cat: /var/mail/root: No such file or directory
AFAIK in ubuntu the mail for root is forwarded to a user
This is set in /etc/aliases
You can install logcheck to recieve email allerts when something happens on your system.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Security incident ycosmic Linux - Security 5 10-18-2005 04:08 PM
Any incident linux was infected with Virus/Worm and crashed? TigerLinux Linux - General 4 10-08-2005 06:59 AM
Wierd Incident php General 26 12-15-2003 03:43 PM
Recommendations for per-incident paid support? aquaphile Linux - General 4 11-07-2003 10:46 AM
Virus Incident Information madness! itsjustme Linux - Security 2 11-07-2003 02:45 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Ubuntu

All times are GMT -5. The time now is 04:19 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration