<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: su: tty+ in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225709#M327941</link>
    <description>thx for your information,&lt;BR /&gt;&lt;BR /&gt;i'm not good in scripting, :D</description>
    <pubDate>Thu, 03 Jul 2008 02:32:52 GMT</pubDate>
    <dc:creator>yulianto piyut</dc:creator>
    <dc:date>2008-07-03T02:32:52Z</dc:date>
    <item>
      <title>su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225693#M327925</link>
      <description>all,&lt;BR /&gt;&lt;BR /&gt;in sulog and syslog.log, there are many messages:&lt;BR /&gt;SU 07/01 19:55 + tty?? root-johan&lt;BR /&gt;SU 07/01 19:56 + tty?? root-johan&lt;BR /&gt;SU 07/01 19:57 + tty?? root-johan&lt;BR /&gt;SU 07/01 19:58 + tty?? root-johan&lt;BR /&gt;SU 07/01 19:59 + tty?? root-johan&lt;BR /&gt;SU 07/01 20:00 + tty?? root-johan&lt;BR /&gt;SU 07/01 20:01 + tty?? root-johan&lt;BR /&gt;SU 07/01 20:01 + tty?? root-apps11i&lt;BR /&gt;SU 07/01 20:02 + tty?? root-johan&lt;BR /&gt;SU 07/01 20:03 + tty?? root-johan&lt;BR /&gt;SU 07/01 20:04 + tty?? root-johan&lt;BR /&gt;SU 07/01 20:05 + tty?? root-johan&lt;BR /&gt;&lt;BR /&gt;i have checked in cronjob and no script that run su to johan and apps11i. &lt;BR /&gt;anybody know about it?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 01 Jul 2008 11:45:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225693#M327925</guid>
      <dc:creator>yulianto piyut</dc:creator>
      <dc:date>2008-07-01T11:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225694#M327926</link>
      <description>hi&lt;BR /&gt;&lt;BR /&gt;to check who is on the server use:&lt;BR /&gt;who -u&lt;BR /&gt;&lt;BR /&gt;and maybe you can find out who it is.&lt;BR /&gt;&lt;BR /&gt;regards</description>
      <pubDate>Tue, 01 Jul 2008 11:49:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225694#M327926</guid>
      <dc:creator>Oviwan</dc:creator>
      <dc:date>2008-07-01T11:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225695#M327927</link>
      <description>thx oviwan for your quick reply,&lt;BR /&gt;&lt;BR /&gt;I have checked and only me that login to server.</description>
      <pubDate>Tue, 01 Jul 2008 12:00:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225695#M327927</guid>
      <dc:creator>yulianto piyut</dc:creator>
      <dc:date>2008-07-01T12:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225696#M327928</link>
      <description>ask johan, maybe he knows more ;)</description>
      <pubDate>Tue, 01 Jul 2008 12:13:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225696#M327928</guid>
      <dc:creator>Oviwan</dc:creator>
      <dc:date>2008-07-01T12:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225697#M327929</link>
      <description>There's got to be a script somewhere that does this.&lt;BR /&gt;&lt;BR /&gt;You should also check your 'at' jobs.  Do an 'at -l' and see if anything shows up.&lt;BR /&gt;</description>
      <pubDate>Tue, 01 Jul 2008 12:48:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225697#M327929</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2008-07-01T12:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225698#M327930</link>
      <description>Do the SU messages in syslog repeat forever or was this a one time, 11-minute  occurence? There is (was) definitely a script running. It could be a simple script with an endless loop and a 60 second delay in it that runs the su commands. If it is still running, check the "ps" listing for suspects. In addition to cron and at, it may have been started by a "nohup" command or from a /sbin/init.d/ startup script or inittab.</description>
      <pubDate>Tue, 01 Jul 2008 14:32:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225698#M327930</guid>
      <dc:creator>TTr</dc:creator>
      <dc:date>2008-07-01T14:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225699#M327931</link>
      <description>It could probably also be an application running as root making "su"s. However, johan and appps11i must exist as users; check their home directories for log files and other interesting stuff.&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;John K.</description>
      <pubDate>Tue, 01 Jul 2008 14:41:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225699#M327931</guid>
      <dc:creator>john korterman</dc:creator>
      <dc:date>2008-07-01T14:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225700#M327932</link>
      <description>no output from "at -l" command. User johan &amp;amp; apps11i doesn't know the root password, only me and other sysadmin that know the root password. I have tried in another server, firstly, I was direct login to root than run su - to another user, the log message in /var/adm/sulog :&lt;BR /&gt;SU 07/01 19:06 + tty?? root-yulianto. so, i think, the script is run by root.</description>
      <pubDate>Wed, 02 Jul 2008 02:12:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225700#M327932</guid>
      <dc:creator>yulianto piyut</dc:creator>
      <dc:date>2008-07-02T02:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225701#M327933</link>
      <description>&amp;gt;i think, the script is run by root.&lt;BR /&gt;&lt;BR /&gt;Exactly.  I assumed you knew this when you said "to johan and apps11i".&lt;BR /&gt;I'm surprised it had "tty??".</description>
      <pubDate>Wed, 02 Jul 2008 02:40:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225701#M327933</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2008-07-02T02:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225702#M327934</link>
      <description>Dennis,&lt;BR /&gt;&lt;BR /&gt;how to check script that run by root as background process? below the cronjob by root and process running by root:&lt;BR /&gt;# crontab -l root&lt;BR /&gt;# Entry(s) in /opt/hpservices/RemoteSupport are for HP Instant Support Enterprise Edition&lt;BR /&gt; 0  0  *  *  1  /opt/hpservices/RemoteSupport/config/pruneIncidents.sh &amp;gt; /dev/null 2&amp;gt;&amp;amp;1&lt;BR /&gt;# Set programmatically by setSysInfoCronEntry.sh: Thu Mar 29 14:05:17 TST 2007&lt;BR /&gt;00 23 * * 0 /opt/hpservices/contrib/SysInfo/bin/SysInfoRunMap.sh &amp;gt;&amp;gt; /var/opt/hpservices/contrib/SysInfo/adm/SysInfoRunMap.cronlog 2&amp;gt;&amp;amp;1 &amp;amp;&lt;BR /&gt;# sar command&lt;BR /&gt;0,5,10,15,20,25,30,35,40,45,50,55 * * * * /usr/lbin/sa/sa1&lt;BR /&gt;0 0 1 * * /usr/lbin/sa/sa2 -A&lt;BR /&gt;&lt;BR /&gt;# ps -ef|grep root&lt;BR /&gt;    root     0     0 13  Aug 16  ?        2177:49 swapper&lt;BR /&gt;    root     8     0  0  Aug 16  ?         0:00 supsched&lt;BR /&gt;    root     9     0  0  Aug 16  ?         0:00 strmem&lt;BR /&gt;    root    10     0  0  Aug 16  ?         0:00 strweld&lt;BR /&gt;    root    11     0  0  Aug 16  ?         0:00 strfreebd&lt;BR /&gt;    root     2     0 12  Aug 16  ?        107:54 vhand&lt;BR /&gt;    root     3     0  1  Aug 16  ?        778:38 statdaemon&lt;BR /&gt;    root     4     0  0  Aug 16  ?         7:59 unhashdaemon&lt;BR /&gt;    root    12     0  0  Aug 16  ?         0:00 ttisr&lt;BR /&gt;    root    13     0  0  Aug 16  ?         0:03 ioconfigd&lt;BR /&gt;    root     1     0  0  Aug 16  ?        12:11 init&lt;BR /&gt;    root    19     0  0  Aug 16  ?        24:21 lvmkd&lt;BR /&gt;    root    20     0  0  Aug 16  ?        24:14 lvmkd&lt;BR /&gt;    root    21     0  0  Aug 16  ?        24:16 lvmkd&lt;BR /&gt;    root    22     0  0  Aug 16  ?        24:13 lvmkd&lt;BR /&gt;    root    23     0  0  Aug 16  ?        24:20 lvmkd&lt;BR /&gt;    root    24     0  0  Aug 16  ?        24:13 lvmkd&lt;BR /&gt;    root    25     0  0  Aug 16  ?         0:00 lvmschedd&lt;BR /&gt;    root    26     0  0  Aug 16  ?         6:09 smpsched&lt;BR /&gt;    root    27     0  0  Aug 16  ?         6:09 smpsched&lt;BR /&gt;    root    28     0  0  Aug 16  ?         6:09 smpsched&lt;BR /&gt;    root    29     0  0  Aug 16  ?         6:09 smpsched&lt;BR /&gt;    root    30     0  0  Aug 16  ?         6:09 smpsched&lt;BR /&gt;    root    31     0  0  Aug 16  ?         6:09 smpsched&lt;BR /&gt;    root    32     0  0  Aug 16  ?         6:09 smpsched&lt;BR /&gt;    root    33     0  0  Aug 16  ?         6:08 smpsched&lt;BR /&gt;    root    34     0  0  Aug 16  ?         6:09 smpsched&lt;BR /&gt;    root    35     0  0  Aug 16  ?         6:08 smpsched&lt;BR /&gt;    root    36     0  0  Aug 16  ?         6:09 smpsched&lt;BR /&gt;    root    37     0  0  Aug 16  ?         6:09 smpsched&lt;BR /&gt;    root    38     0  0  Aug 16  ?         0:00 sblksched&lt;BR /&gt;    root    39     0  0  Aug 16  ?         0:00 sblksched&lt;BR /&gt;    root    40     0  0  Aug 16  ?         3:02 lvmdevd&lt;BR /&gt;    root    41     0  0  Aug 16  ?         0:00 lvmattachd&lt;BR /&gt;    root 22480     1  0  Jun 24  console   0:00 /usr/sbin/getty console console&lt;BR /&gt;    root   835     1  0  Aug 16  ?         0:00 /usr/sbin/rpcbind&lt;BR /&gt;    root  1179     1  0  Aug 16  ?         0:24 /usr/sbin/snmpdm&lt;BR /&gt;    root    47     0  0  Aug 16  ?        5336:59 vxfsd&lt;BR /&gt;    root    75     0  0  Aug 16  ?         2:48 lvmdevd&lt;BR /&gt;    root    76     0  0  Aug 16  ?         0:00 lvmattachd&lt;BR /&gt;    root    77     0  0  Aug 16  ?         3:18 lvmdevd&lt;BR /&gt;    root    78     0  0  Aug 16  ?         0:00 lvmattachd&lt;BR /&gt;    root    79     0  0  Aug 16  ?         3:22 lvmdevd&lt;BR /&gt;    root    80     0  0  Aug 16  ?         0:00 lvmattachd&lt;BR /&gt;    root    81     0  0  Aug 16  ?         2:39 lvmdevd&lt;BR /&gt;    root    82     0  0  Aug 16  ?         0:00 lvmattachd&lt;BR /&gt;    root   537     1  0  Aug 16  ?        66:18 /usr/sbin/syncer&lt;BR /&gt;    root   553     0  0  Aug 16  ?         0:03 dmprestored&lt;BR /&gt;    root  1382     1  0  Aug 16  ?         5:56 /usr/sbin/cron&lt;BR /&gt;    root   648     1  0  Aug 16  ?         0:00 /usr/sbin/hotplugd /var/adm/hotplugd.log trunc&lt;BR /&gt;    root   661     1  0  Aug 16  ?         0:00 /usr/lbin/nktl_daemon 0 0 0 0 0 1 -2 0&lt;BR /&gt;    root  1196     1  0  Aug 16  ?         0:00 /usr/sbin/hp_unixagt&lt;BR /&gt;    root   671     1  0  Aug 16  ?         0:00 /usr/lbin/ntl_reader 0 1 1 1 1000 2 /var/adm/nettl /var/adm/con&lt;BR /&gt;    root   672   671  0  Aug 16  ?        43:13 /usr/sbin/netfmt -C -F -f /var/adm/nettl.LOG000 -c /var/adm/con&lt;BR /&gt;    root   840     0  0  Aug 16  ?         0:00 nfskd&lt;BR /&gt;    root   884     1  0  Aug 16  ?         0:04 /usr/sbin/inetd&lt;BR /&gt;    root   666   134  1 11:08:10 pts/7     0:00 ps -ef&lt;BR /&gt;    root  1207     1  0  Aug 16  ?        18:54 /usr/sbin/mib2agt&lt;BR /&gt;    root  1218     1  0  Aug 16  ?         0:00 /usr/sbin/trapdestagt&lt;BR /&gt;    root  1243     1  0  Aug 16  ?         0:00 /usr/sbin/fddi4subagt&lt;BR /&gt;    root  1266     1  0  Aug 16  ?         2:40 /opt/wbem/lbin/cimserver&lt;BR /&gt;    root  1260     1  0  Aug 16  ?         5:57 /opt/dce/sbin/rpcd&lt;BR /&gt;    root  1267  1266  0  Aug 16  ?         0:00 /opt/wbem/lbin/cimservera&lt;BR /&gt;    root  1268  1266  0  Aug 16  ?         0:19 /opt/wbem/lbin/cimprovagt 11 10 EMSHAProviderModule&lt;BR /&gt;    root  1354     1  0  Aug 16  ?        97:25 /usr/sbin/pwgrd&lt;BR /&gt;    root  1402     1  0  Aug 16  ?         0:00 /usr/sbin/envd&lt;BR /&gt;    root  1326     1  0  Aug 16  ?         0:07 /usr/sbin/rbootd&lt;BR /&gt;    root  1728     1  0  Aug 16  ?         0:00 /opt/hpservices/contrib/emsListener/bin/rstlistener&lt;BR /&gt;    root  2022     1  0  Aug 16  ?         0:34 /sbin/krsd -i&lt;BR /&gt;    root  1892     1  0  Aug 16  ?         0:00 /sbin/sh /usr/dt/bin/dtrc&lt;BR /&gt;    root  2023     1  0  Aug 16  ?         0:00 /sbin/sfd&lt;BR /&gt;    root  1399     1  0  Aug 16  ?        26:49 /usr/sbin/stm/uut/bin/sys/diagmond&lt;BR /&gt;    root 29251     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root  1840     1  0  Aug 16  ?        26:52 /opt/VRTSob/bin/vxsvc -r /opt/VRTSob/config/Registry&lt;BR /&gt;    root  1552     1  0  Aug 16  ?         6:06 /usr/sbin/swagentd -r&lt;BR /&gt;    root  1907     1  0  Aug 16  ?        28:54 /opt/openssl/prngd/prngd -n -c /opt/openssl/prngd/prngd.conf /v&lt;BR /&gt;    root  1597     1  0  Aug 16  ?         0:00 /etc/opt/resmon/lbin/emsagent&lt;BR /&gt;    root  1916  1892  0  Aug 16  ?         0:00 /usr/dt/bin/dtlogin&lt;BR /&gt;    root  2011  1399  0  Aug 16  ?         2:03 memlogd&lt;BR /&gt;    root  2010  1399  0  Aug 16  ?        21:09 diaglogd&lt;BR /&gt;    root  2024     1  0  Aug 16  ?         4:11 /opt/wbem/lbin/cimserverd&lt;BR /&gt;    root  2028     1  0  Aug 16  ?         9:37 /etc/opt/resmon/lbin/p_client&lt;BR /&gt;    root  2029     1  0  Aug 16  ?        348:53 /usr/lbin/utild&lt;BR /&gt;    root 29275     1  0  Aug 21  ?         0:00 /usr/sbin/rpc.lockd&lt;BR /&gt;    root 29260     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root 29252     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root 26951 26914  0  Dec  5  ?        2015:24 /bea_shinta/connect1/bea/jdk142_05/bin/PA_RISC2.0/java -server&lt;BR /&gt;    root  9629  9625  0  May 26  ?         0:00 /opt/OV/lbin/conf/ovconfd&lt;BR /&gt;    root 29286     1  0  Aug 21  ?         9:06 /usr/lib/netsvc/fs/automount/automount -f /etc/auto_master&lt;BR /&gt;    root 26925     1  0 19:34:37 ?         0:00 /opt/ssh/sbin/sshd&lt;BR /&gt;    root 29261     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root 29247     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root 29256     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root 29253     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root  9679  9625  0  May 26  ?        14:08 /opt/OV/lbin/eaagt/opcmsga&lt;BR /&gt;    root  9627  9625  0  May 26  ?         3:27 /opt/OV/bin/ovbbccb -nodaemon&lt;BR /&gt;    root   134 16205  0 11:06:24 pts/7     0:00 -sh&lt;BR /&gt;    root 29248     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root  9675     1  0  Sep  3  ?         0:49 /usr/sbin/syslogd -D&lt;BR /&gt;    root 29259     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root 29258     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root 29269     1  0  Aug 21  ?         0:00 /usr/sbin/rpc.statd&lt;BR /&gt;    root 29246     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root  3846     1  0  Sep 25  ?        513:08 sendmail: accepting connections on port 25&lt;BR /&gt;    root 29257     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root 29254     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root 29250     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root 29255     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root  9625     1  0  May 26  ?        16:53 /opt/OV/bin/ovcd&lt;BR /&gt;    root 29249     1  0  Aug 21  ?         0:26 /usr/sbin/biod 16&lt;BR /&gt;    root   668   134  1 11:08:10 pts/7     0:00 grep root&lt;BR /&gt;    root 13838     1  0  Jun 24  ?         0:00 sshd: adityaws@pts/0&lt;BR /&gt;    root  8377     1  0  Apr 21  ?         0:00 /opt/perf/bin/ttd&lt;BR /&gt;    root  9685  9625  0  May 26  ?        33:22 /opt/OV/lbin/eaagt/opcmona&lt;BR /&gt;    root 16191 26925  0 10:18:01 ?         0:00 sshd: yulianto@pts/7&lt;BR /&gt;    root  9681  9625  0  May 26  ?        11:18 /opt/OV/lbin/eaagt/opcacta&lt;BR /&gt;    root 24609 24607  0  Jan 15  ?        249:51 /opt/APPQcime/jre/bin/PA_RISC/java -Dprogram.name=../tools/star&lt;BR /&gt;    root 26914     1  0  Dec  5  ?         0:00 /bin/sh ./startWebLogic.sh&lt;BR /&gt;    root 22182     1  4  Nov 14  ?        82:23 p_ctmat&lt;BR /&gt;    root 24607     1  0  Jan 15  ?        147:21 ../lib/wrapper ../conf/jswwrapper.conf wrapper.pidfile=../lib//&lt;BR /&gt;    root 19760     1  0  Jun 30  ?         0:33 mad -u root -g bin&lt;BR /&gt;    root  9683  9625  0  May 26  ?         0:00 /opt/OV/lbin/eaagt/opcmsgi&lt;BR /&gt;    root  5118     1  0  May 26  ?         4:41 /opt/OV/lbin/xpl/trc/ovtrcd&lt;BR /&gt;    root  8395 26925  0 09:50:57 ?         0:01 sshd: johan@pts/1&lt;BR /&gt;    root 22030     1  0  Nov 14  ?         8:59 p_ctmag&lt;BR /&gt;    root  9677  9625  0  May 26  ?        14:30 /opt/OV/lbin/perf/coda&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 02 Jul 2008 02:45:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225702#M327934</guid>
      <dc:creator>yulianto piyut</dc:creator>
      <dc:date>2008-07-02T02:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225703#M327935</link>
      <description>&amp;gt;how to check script that run by root as background process? below the cronjob by root and process running by root:&lt;BR /&gt;&lt;BR /&gt;Well you can grep the crontab scripts:&lt;BR /&gt;/opt/hpservices/RemoteSupport/config/pruneIncidents.sh&lt;BR /&gt;/opt/hpservices/contrib/SysInfo/bin/SysInfoRunMap.sh&lt;BR /&gt;&lt;BR /&gt;I wouldn't think these would do it.&lt;BR /&gt;&lt;BR /&gt;root 134 16205 0 11:06:24 pts/7 0:00 -sh&lt;BR /&gt;&lt;BR /&gt;I don't see the parent 16205 here, you should see what it is: ps -fp 16205&lt;BR /&gt;&lt;BR /&gt;root 26925 1 0 19:34:37 ? 0:00 /opt/ssh/sbin/sshd&lt;BR /&gt;root 13838 1 0 Jun 24 ? 0:00 sshd: adityaws@pts/0&lt;BR /&gt;root 16191 26925 0 10:18:01 ? 0:00 sshd: yulianto@pts/7&lt;BR /&gt;root 8395 26925 0 09:50:57 ? 0:01 sshd: johan@pts/1&lt;BR /&gt;&lt;BR /&gt;You might look at these?  Does root su to each user that uses ssh?&lt;BR /&gt;&lt;BR /&gt;root 24609 24607 0 Jan 15 ? 249:51 /opt/APPQcime/jre/bin/PA_RISC/java -Dprogram.name=../tools/star&lt;BR /&gt;root 26914 1 0 Dec 5 ? 0:00 /bin/sh ./startWebLogic.sh&lt;BR /&gt;root 22182 1 4 Nov 14 ? 82:23 p_ctmat&lt;BR /&gt;root 22030 1 0 Nov 14 ? 8:59 p_ctmag&lt;BR /&gt;root 19760 1 0 Jun 30 ? 0:33 mad -u root -g bin&lt;BR /&gt;&lt;BR /&gt;Not sure what these all do??</description>
      <pubDate>Wed, 02 Jul 2008 03:21:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225703#M327935</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2008-07-02T03:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225704#M327936</link>
      <description>hi dennis,&lt;BR /&gt;&lt;BR /&gt;no script consists of root su to another user.&lt;BR /&gt;# ps -ef|grep sshd&lt;BR /&gt;    root 16537 15681  0 12:10:24 pts/4     0:00 grep sshd&lt;BR /&gt;    root 15633  4134  0 12:06:17 ?         0:00 sshd: yulianto@pts/4&lt;BR /&gt;    root  8395     1  0 09:50:57 ?         0:02 sshd: johan@pts/1&lt;BR /&gt;    root  4134     1  0 11:20:20 ?         0:00 /opt/ssh/sbin/sshd&lt;BR /&gt;# date&lt;BR /&gt;Wed Jul  2 12:10:31 TST 2008&lt;BR /&gt;# tail /var/adm/sulog&lt;BR /&gt;SU 07/02 12:03 + 4 yulianto-root&lt;BR /&gt;SU 07/02 12:03 + tty?? root-johan&lt;BR /&gt;SU 07/02 12:04 + tty?? root-johan&lt;BR /&gt;SU 07/02 12:05 + tty?? root-johan&lt;BR /&gt;SU 07/02 12:06 + tty?? root-johan&lt;BR /&gt;SU 07/02 12:06 + 4 yulianto-root&lt;BR /&gt;SU 07/02 12:07 + tty?? root-johan&lt;BR /&gt;SU 07/02 12:08 + tty?? root-johan&lt;BR /&gt;SU 07/02 12:09 + tty?? root-johan&lt;BR /&gt;SU 07/02 12:10 + tty?? root-johan&lt;BR /&gt;&lt;BR /&gt;now, only me and user johan that login to server.</description>
      <pubDate>Wed, 02 Jul 2008 03:49:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225704#M327936</guid>
      <dc:creator>yulianto piyut</dc:creator>
      <dc:date>2008-07-02T03:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225705#M327937</link>
      <description>&amp;gt;no script consists of root su to another user.&lt;BR /&gt;&lt;BR /&gt;Could it be rcp/scp or ssh to your machine?&lt;BR /&gt;Can you (as yulianto) ssh back to your same machine and see if that is logged?&lt;BR /&gt;&lt;BR /&gt;SU 07/02 12:03 + tty?? root-johan&lt;BR /&gt;...&lt;BR /&gt;SU 07/02 12:10 + tty?? root-johan&lt;BR /&gt;&lt;BR /&gt;Like clockwork.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;user johan that login to server.&lt;BR /&gt;&lt;BR /&gt;Can you ask him if he doing any scripting for once a minute?</description>
      <pubDate>Wed, 02 Jul 2008 05:00:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225705#M327937</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2008-07-02T05:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225706#M327938</link>
      <description>thx dennis,&lt;BR /&gt;&lt;BR /&gt;I have asked to user johan and no script that running comman su to user johan. The other su messages is normal, based on sudoers file.</description>
      <pubDate>Wed, 02 Jul 2008 05:42:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225706#M327938</guid>
      <dc:creator>yulianto piyut</dc:creator>
      <dc:date>2008-07-02T05:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225707#M327939</link>
      <description>If you have given up on trying to play detective, it's time to have su tell you who is doing things.&lt;BR /&gt;&lt;BR /&gt;You need to write a su wrapper to log more things.  How good are you at scripting?  How secure to you need to make this wrapper?  (Where we are going to log more info.)</description>
      <pubDate>Wed, 02 Jul 2008 07:31:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225707#M327939</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2008-07-02T07:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225708#M327940</link>
      <description>&amp;gt;ME: You need to write a su wrapper to log more things.&lt;BR /&gt;&lt;BR /&gt;Here is a thread that has a wrapper:&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=1188448" target="_blank"&gt;http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=1188448&lt;/A&gt;</description>
      <pubDate>Thu, 03 Jul 2008 02:07:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225708#M327940</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2008-07-03T02:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225709#M327941</link>
      <description>thx for your information,&lt;BR /&gt;&lt;BR /&gt;i'm not good in scripting, :D</description>
      <pubDate>Thu, 03 Jul 2008 02:32:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225709#M327941</guid>
      <dc:creator>yulianto piyut</dc:creator>
      <dc:date>2008-07-03T02:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225710#M327942</link>
      <description>hi dennis,&lt;BR /&gt;&lt;BR /&gt;I have already tried to use the script wrapper based on link yo gave to me. after i replace /usr/bin/su with /usr/bin/su_my, there are no messages root su to johan in /var/adm/sulog and  /var/adm/syslog/syslog.log. If it solved my problem?</description>
      <pubDate>Thu, 03 Jul 2008 04:02:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225710#M327942</guid>
      <dc:creator>yulianto piyut</dc:creator>
      <dc:date>2008-07-03T04:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225711#M327943</link>
      <description>&amp;gt;there are no messages root su to johan in /var/adm/sulog and /var/adm/syslog/syslog.log. If it solved my problem?&lt;BR /&gt;&lt;BR /&gt;I'm not sure why they would stop?&lt;BR /&gt;Have you tried using su(1) to see if you get logged?  Perhaps that script is bad.  Especially the instructions to make it setuid.  That shouldn't be necessary, unless you want some type of security on the alternate logfile.</description>
      <pubDate>Thu, 03 Jul 2008 09:57:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225711#M327943</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2008-07-03T09:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: su: tty+</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225712#M327944</link>
      <description>One last thing to check is if root has a .rhosts (and for ssh, is it .shosts? i don't remember) file that allows other servers to run remote shells on this server. They may be doing this as well.</description>
      <pubDate>Thu, 03 Jul 2008 19:46:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-tty/m-p/4225712#M327944</guid>
      <dc:creator>TTr</dc:creator>
      <dc:date>2008-07-03T19:46:33Z</dc:date>
    </item>
  </channel>
</rss>

