<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Capture telnet session in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930535#M409907</link>
    <description>We have a requirement to capure user telnet sessions for SOX remediation. Now the easiest way to do this is to invoke script from a users profile. But it is not secure as the user has write access to the scriptlog file which can be easily modified. &lt;BR /&gt;&lt;BR /&gt;Is there any 3rd party tool out there that can do this?</description>
    <pubDate>Fri, 30 Sep 2005 13:01:01 GMT</pubDate>
    <dc:creator>Chetan_5</dc:creator>
    <dc:date>2005-09-30T13:01:01Z</dc:date>
    <item>
      <title>Capture telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930535#M409907</link>
      <description>We have a requirement to capure user telnet sessions for SOX remediation. Now the easiest way to do this is to invoke script from a users profile. But it is not secure as the user has write access to the scriptlog file which can be easily modified. &lt;BR /&gt;&lt;BR /&gt;Is there any 3rd party tool out there that can do this?</description>
      <pubDate>Fri, 30 Sep 2005 13:01:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930535#M409907</guid>
      <dc:creator>Chetan_5</dc:creator>
      <dc:date>2005-09-30T13:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: Capture telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930536#M409908</link>
      <description>If you make their profile invoke a script owned by root that they have execute permission on, that script will be able to write to a log file that is owned by root and they have no access to.  That's the way I would try to handle it.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Pete</description>
      <pubDate>Fri, 30 Sep 2005 13:10:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930536#M409908</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2005-09-30T13:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Capture telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930537#M409909</link>
      <description>if your user's do not have su to root capability, Pete's method is perfectly safe as long as you modified the permissions of this logfile and the user's profile properly to prevent the user's themselves from modifying it.&lt;BR /&gt;&lt;BR /&gt;If this is not an option, i.e., users need to modify their profiles or execute "su -" commands, then powerbroker is to the rescue. Be warned that it is not free or not even cheap for most people, but if you are concerned about SOX, your company is not a mom and pop shop and can afford it. Go to, &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.symark.com" target="_blank"&gt;http://www.symark.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;for more information. You can set up a remote log server where your users are not authorized to login. This is how you keep pristine logs of user activity. It captures on keystroke basis for finer granularity.&lt;BR /&gt;&lt;BR /&gt;Also you can do this locally via sudo, but if the users gain access to "su -" command, there is no longer any traceability at that moment.&lt;BR /&gt;&lt;BR /&gt;Hope this helps</description>
      <pubDate>Fri, 30 Sep 2005 14:36:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930537#M409909</guid>
      <dc:creator>Mel Burslan</dc:creator>
      <dc:date>2005-09-30T14:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: Capture telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930538#M409910</link>
      <description>Hi Chetan,&lt;BR /&gt;&lt;BR /&gt;Here is some thing that can help:&lt;BR /&gt;&lt;BR /&gt;i) set .sh_history &lt;BR /&gt;ii) put  script command in .profile to save all output.&lt;BR /&gt;&lt;BR /&gt;vi .profile &lt;BR /&gt;script $LOGNAME.log&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;iii) Check skymark.com , for skymark tools for further as per the above link&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;&lt;BR /&gt;Raj.</description>
      <pubDate>Fri, 30 Sep 2005 15:35:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930538#M409910</guid>
      <dc:creator>Raj D.</dc:creator>
      <dc:date>2005-09-30T15:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Capture telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930539#M409911</link>
      <description>&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=211879" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=211879&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://groups.google.com/group/comp.os.linux.misc/browse_thread/thread/276d0ae9aea16e8b/f71f8585a6ad8f62%23f71f8585a6ad8f62?sa=X&amp;amp;oi=groupsr&amp;amp;start=2&amp;amp;num=3" target="_blank"&gt;http://groups.google.com/group/comp.os.linux.misc/browse_thread/thread/276d0ae9aea16e8b/f71f8585a6ad8f62%23f71f8585a6ad8f62?sa=X&amp;amp;oi=groupsr&amp;amp;start=2&amp;amp;num=3&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;It may help.. &lt;BR /&gt;&lt;BR /&gt;-Arun</description>
      <pubDate>Sat, 01 Oct 2005 00:39:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930539#M409911</guid>
      <dc:creator>Arunvijai_4</dc:creator>
      <dc:date>2005-10-01T00:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: Capture telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930540#M409912</link>
      <description>Nop. If you do scripting in /etc/profile then normal user can not change it.&lt;BR /&gt;&lt;BR /&gt;You can capture telnet sessions simply as,&lt;BR /&gt;&lt;BR /&gt; -- /etc/profile --&lt;BR /&gt; ps | grep -q 'telnet'&lt;BR /&gt; if [ $? -eq 0 ]&lt;BR /&gt; then&lt;BR /&gt;   script -a /tmp/$USER_telnet.log&lt;BR /&gt; fi&lt;BR /&gt;&lt;BR /&gt;It will append telnet related login information to the user log file.&lt;BR /&gt;&lt;BR /&gt;You can as well as turn on history as,&lt;BR /&gt;&lt;BR /&gt;-- /etc/profile --&lt;BR /&gt; ps | grep -q 'telnet'&lt;BR /&gt; if [ $? -eq 0 ]&lt;BR /&gt; then&lt;BR /&gt;set -o vi&lt;BR /&gt;export HISTFILE=/tmp/$USER_telnet.his&lt;BR /&gt;export HISTSIZE=2000&lt;BR /&gt;echo "telnet login @ $(date)" &amp;gt;&amp;gt; $HISTFILE&lt;BR /&gt;fi&lt;BR /&gt;&lt;BR /&gt;hth.</description>
      <pubDate>Sat, 01 Oct 2005 01:40:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930540#M409912</guid>
      <dc:creator>Muthukumar_5</dc:creator>
      <dc:date>2005-10-01T01:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Capture telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930541#M409913</link>
      <description>You can use putty tool to capture all logins related with telnet based. However, this is client based tool.&lt;BR /&gt;&lt;BR /&gt;You can also use tee command something like,&lt;BR /&gt;&lt;BR /&gt;# telnet &lt;HOST&gt; | tee &lt;LOGFILE&gt;&lt;BR /&gt;&lt;BR /&gt;hth.&lt;/LOGFILE&gt;&lt;/HOST&gt;</description>
      <pubDate>Sat, 01 Oct 2005 01:41:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930541#M409913</guid>
      <dc:creator>Muthukumar_5</dc:creator>
      <dc:date>2005-10-01T01:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: Capture telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930542#M409914</link>
      <description>Thanks to all for their responses. I knew that none of the native UNIX utilities would do the job. With script, the user always will have write access to the file and we do not want that situation. &lt;BR /&gt;&lt;BR /&gt;  As per Ben's recommendation, I will check out skymark's powerbroker product.</description>
      <pubDate>Mon, 03 Oct 2005 09:39:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930542#M409914</guid>
      <dc:creator>Chetan_5</dc:creator>
      <dc:date>2005-10-03T09:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: Capture telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930543#M409915</link>
      <description>Sorry for the faux pas; skymark was Mel's recommendation.</description>
      <pubDate>Mon, 03 Oct 2005 09:40:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/capture-telnet-session/m-p/4930543#M409915</guid>
      <dc:creator>Chetan_5</dc:creator>
      <dc:date>2005-10-03T09:40:54Z</dc:date>
    </item>
  </channel>
</rss>

