<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: su without (-) where to check the log? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/su-without-where-to-check-the-log/m-p/4553769#M370892</link>
    <description>Hi Michael,&lt;BR /&gt;&lt;BR /&gt;history file was there in the profile of root and even from the normal account, but wonder if someone just su (w/out -) and knows passwd of root, then we cannot ablel to tract down what r the cmds that user's been executed. We're implementing some security root audit from d company. &lt;BR /&gt;&lt;BR /&gt;Hi Dennis,&lt;BR /&gt;&lt;BR /&gt;Yeah, but I noticed the env is still somehow strange for the given values and parameters that was set there.&lt;BR /&gt;&lt;BR /&gt;Is there any possible way that we can still tract who user accnt who su (w/o -) and able to get the history log of it.&lt;BR /&gt;</description>
    <pubDate>Tue, 22 Dec 2009 08:40:43 GMT</pubDate>
    <dc:creator>shardam</dc:creator>
    <dc:date>2009-12-22T08:40:43Z</dc:date>
    <item>
      <title>su without (-) where to check the log?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-without-where-to-check-the-log/m-p/4553766#M370889</link>
      <description>Hi Admin,&lt;BR /&gt;&lt;BR /&gt;How can I check the user's history log who su omitted (-)? The history is not able to capture from root and even user's history log.&lt;BR /&gt;&lt;BR /&gt;Appreciate your kind response.</description>
      <pubDate>Tue, 22 Dec 2009 03:59:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-without-where-to-check-the-log/m-p/4553766#M370889</guid>
      <dc:creator>shardam</dc:creator>
      <dc:date>2009-12-22T03:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: su without (-) where to check the log?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-without-where-to-check-the-log/m-p/4553767#M370890</link>
      <description>Hmm, I would expect that if you just use "su", your new history will be in the same file as previous, if there was one.</description>
      <pubDate>Tue, 22 Dec 2009 07:36:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-without-where-to-check-the-log/m-p/4553767#M370890</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-12-22T07:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: su without (-) where to check the log?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-without-where-to-check-the-log/m-p/4553768#M370891</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;Sounds like your not set up for the basic history file.  For either root or user's .profile and for Korn shell, 'export HISTFILE=.sh_history' should exist.  To verify from either, 'env | grep -i his'.</description>
      <pubDate>Tue, 22 Dec 2009 07:54:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-without-where-to-check-the-log/m-p/4553768#M370891</guid>
      <dc:creator>Michael Steele_2</dc:creator>
      <dc:date>2009-12-22T07:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: su without (-) where to check the log?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-without-where-to-check-the-log/m-p/4553769#M370892</link>
      <description>Hi Michael,&lt;BR /&gt;&lt;BR /&gt;history file was there in the profile of root and even from the normal account, but wonder if someone just su (w/out -) and knows passwd of root, then we cannot ablel to tract down what r the cmds that user's been executed. We're implementing some security root audit from d company. &lt;BR /&gt;&lt;BR /&gt;Hi Dennis,&lt;BR /&gt;&lt;BR /&gt;Yeah, but I noticed the env is still somehow strange for the given values and parameters that was set there.&lt;BR /&gt;&lt;BR /&gt;Is there any possible way that we can still tract who user accnt who su (w/o -) and able to get the history log of it.&lt;BR /&gt;</description>
      <pubDate>Tue, 22 Dec 2009 08:40:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-without-where-to-check-the-log/m-p/4553769#M370892</guid>
      <dc:creator>shardam</dc:creator>
      <dc:date>2009-12-22T08:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: su without (-) where to check the log?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-without-where-to-check-the-log/m-p/4553770#M370893</link>
      <description>&amp;gt;Is there any possible way that we can still tract who user account who su (w/o -) and able to get the history log of it.&lt;BR /&gt;&lt;BR /&gt;Not by using the shell history mechanism.&lt;BR /&gt;You may want to look into sudo or RBAC.&lt;BR /&gt;Some other threads:&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=649574" target="_blank"&gt;http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=649574&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=1357406" target="_blank"&gt;http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=1357406&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=1342438" target="_blank"&gt;http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=1342438&lt;/A&gt;</description>
      <pubDate>Tue, 22 Dec 2009 09:43:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-without-where-to-check-the-log/m-p/4553770#M370893</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-12-22T09:43:28Z</dc:date>
    </item>
  </channel>
</rss>

