<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to prove that the server is rebooted manually in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257558#M471682</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I'm not the admin but I used to have almost the same privileges as the admin but the Admin has now given me only restricted access.&lt;BR /&gt;&lt;BR /&gt;Note that the user giza can rlogin to s101 as root and from there, this account can rlogin to s7cs as root. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Robert Peregrin</description>
    <pubDate>Tue, 05 Oct 2010 09:18:40 GMT</pubDate>
    <dc:creator>Robert Peregrin</dc:creator>
    <dc:date>2010-10-05T09:18:40Z</dc:date>
    <item>
      <title>How to prove that the server is rebooted manually</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257549#M471673</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I'm investigating the reason for the reboot of our rp2405 server. There was a down time for another server in the same time that the rp2405 server was rebooted. But the people who did the down time does not want to admit that they rebooted the server.&lt;BR /&gt;&lt;BR /&gt;I have reason to believe that they rebooted the server based on the following:&lt;BR /&gt;&lt;BR /&gt;Reboot time from shutdownlog:&lt;BR /&gt;02:40  Sat Oct  2, 2010.  Reboot:  (by s7cs!root)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Users logged in at the time of reboot:&lt;BR /&gt;&lt;BR /&gt;root     pts/1        Sat Oct  2 02:52 - 06:06  (03:14)&lt;BR /&gt;giza     pts/0        Sat Oct  2 02:47 - 06:06  (03:18)&lt;BR /&gt;reboot   system boot  Sat Oct  2 02:45   still logged in&lt;BR /&gt;root     pts/3        Sat Oct  2 02:35 - 02:39  (00:03)&lt;BR /&gt;root     pts/2        Sat Oct  2 02:29 - 02:40  (00:10)&lt;BR /&gt;giza     pts/1        Sat Oct  2 02:28 - 02:40  (00:12)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;User activities at the time of reboot:&lt;BR /&gt;&lt;BR /&gt;                1              pts/1        25212  8 0000 0000 1285969471 Oct  2 00:44:31 2010&lt;BR /&gt;giza     1    pts/1         5021  7 0000 0000 1285975705 Oct  2 02:28:25 2010 157.234.229.16 157.234.229.16&lt;BR /&gt;LOGIN    2    pts/2         5103  6 0000 0000 1285975794 Oct  2 02:29:54 2010 172.24.30.40 s7s101&lt;BR /&gt;root     2    pts/2         5103  7 0000 0003 1285975794 Oct  2 02:29:54 2010 172.24.30.40 s7s101&lt;BR /&gt;LOGIN    3    pts/3         6564  6 0000 0000 1285976151 Oct  2 02:35:51 2010 172.20.238.156 s7sdb3&lt;BR /&gt;root     3    pts/3         6564  7 0000 0003 1285976151 Oct  2 02:35:51 2010 172.20.238.156 s7sdb3&lt;BR /&gt;root     3    pts/3         6564  8 0000 0000 1285976362 Oct  2 02:39:22 2010&lt;BR /&gt;root     td   pts/td         495  8 0000 0000 1285976435 Oct  2 02:40:35 2010&lt;BR /&gt;a7hcHttp a7fh               2088  8 0000 0000 1285976435 Oct  2 02:40:35 2010&lt;BR /&gt;krsd     krsd               2081  8 0000 0000 1285976435 Oct  2 02:40:35 2010&lt;BR /&gt;         1    pts/1         5021  8 0000 0000 1285976435 Oct  2 02:40:35 2010&lt;BR /&gt;         5    pts/5        21889  8 0000 0000 1285976435 Oct  2 02:40:35 2010&lt;BR /&gt;a7hcHttp a7hc               2084  8 0000 0000 1285976435 Oct  2 02:40:35 2010&lt;BR /&gt;LOGIN    cons console       2080  8 0000 0000 1285976435 Oct  2 02:40:35 2010&lt;BR /&gt;         7    pts/7         1271  8 0000 0000 1285976435 Oct  2 02:40:35 2010&lt;BR /&gt;root     2    pts/2         5103  8 0000 0000 1285976435 Oct  2 02:40:35 2010&lt;BR /&gt;errlogdW errd              23679  8 0000 0000 1285976435 Oct  2 02:40:35 2010&lt;BR /&gt;sfd      sfd                2082  8 0000 0000 1285976438 Oct  2 02:40:38 2010&lt;BR /&gt;root     0    pts/0        10031  8 0000 0000 1285976438 Oct  2 02:40:38 2010&lt;BR /&gt;root     p3   ttyp3        21830  8 0000 0000 1285976439 Oct  2 02:40:39 2010&lt;BR /&gt;root     p2   ttyp2        21831  8 0000 0000 1285976439 Oct  2 02:40:39 2010&lt;BR /&gt;root     p3   ttyp3        21830  8 0000 0000 1285976440 Oct  2 02:40:40 2010&lt;BR /&gt;root     p2   ttyp2        21831  8 0000 0000 1285976440 Oct  2 02:40:40 2010&lt;BR /&gt;              system boot      0  2 0000 0000 1285976723 Oct  2 02:45:23 2010&lt;BR /&gt;              run-level 3      0  1 0063 0123 1285976723 Oct  2 02:45:23 2010&lt;BR /&gt;vxenable vxen                 61  5 0000 0000 1285976723 Oct  2 02:45:23 2010&lt;BR /&gt;vxenable vxen                 61  8 0000 0000 1285976723 Oct  2 02:45:23 2010&lt;BR /&gt;bcheckrc brc1                 62  5 0000 0000 1285976723 Oct  2 02:45:23 2010&lt;BR /&gt;bcheckrc brc1                 62  8 0000 0000 1285976724 Oct  2 02:45:24 2010&lt;BR /&gt;cat      cprt                102  5 0000 0000 1285976724 Oct  2 02:45:24 2010&lt;BR /&gt;cat      cprt                102  8 0000 0000 1285976725 Oct  2 02:45:25 2010&lt;BR /&gt;giza     0    pts/0         1750  7 0000 0000 1285976879 Oct  2 02:47:59 2010 157.234.229.16 157.234.229.16&lt;BR /&gt;rc       sqnc                107  8 0000 0000 1285976935 Oct  2 02:48:55 2010&lt;BR /&gt;getty    cons               1999  5 0000 0000 1285976935 Oct  2 02:48:55 2010&lt;BR /&gt;krsd     krsd               2000  5 0000 0000 1285976935 Oct  2 02:48:55 2010&lt;BR /&gt;sfd      sfd                2001  5 0000 0000 1285976935 Oct  2 02:48:55 2010&lt;BR /&gt;errlogdW errd               2002  5 0000 0000 1285976935 Oct  2 02:48:55 2010&lt;BR /&gt;a7hcHttp a7hc               2003  5 0000 0000 1285976935 Oct  2 02:48:55 2010&lt;BR /&gt;a7hcHttp a7fh               2004  5 0000 0000 1285976935 Oct  2 02:48:55 2010&lt;BR /&gt;LOGIN    cons console       1999  6 0000 0000 1285976935 Oct  2 02:48:55 2010&lt;BR /&gt;LOGIN    1    pts/1         4243  6 0000 0000 1285977128 Oct  2 02:52:08 2010 172.24.30.40 s7s101&lt;BR /&gt;root     1    pts/1         4243  7 0000 0003 1285977129 Oct  2 02:52:09 2010 172.24.30.40 s7s101&lt;BR /&gt;         0    pts/0         1750  8 0000 0000 1285988810 Oct  2 06:06:50 2010&lt;BR /&gt;root     1    pts/1         4243  8 0000 0000 1285988810 Oct  2 06:06:50 2010&lt;BR /&gt;LOGIN    0    pts/0          373  6 0000 0000 1285998318 Oct  2 08:45:18 2010 10.32.99.98 10.32.99.98&lt;BR /&gt;giza     0    pts&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;History of user activities on pts/2:&lt;BR /&gt;&lt;BR /&gt;rcp /etc/group s7sdb3:/etc/group&lt;BR /&gt;rcp /etc/passwd s7sdb3:/etc/passwd&lt;BR /&gt;exit&lt;BR /&gt;&lt;BR /&gt;rlogin s7sdb3&lt;BR /&gt;rlogin s7sdb3&lt;BR /&gt;reboot -r&lt;BR /&gt;&lt;BR /&gt;rlogin as2&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Only giza user account is logged in at the time of Central Server reboot. But the user who owns this account is denying it. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I noticed that syslog went down on signal 15. Signal 15 is only issued manually by root user right?&lt;BR /&gt;&lt;BR /&gt;Oct  2 02:40:35 s7cs syslogd: going down on signal 15&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;There was no new files under /var/adm/crash.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I was trying to login to the console to look for possible power problems but the terminal is always giving the message to use Ecf but it doesn't work when I'm pressing ctrl Ecf.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Your help will be appreciated.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Robert Peregrin</description>
      <pubDate>Sun, 03 Oct 2010 06:59:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257549#M471673</guid>
      <dc:creator>Robert Peregrin</dc:creator>
      <dc:date>2010-10-03T06:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to prove that the server is rebooted manually</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257550#M471674</link>
      <description>[Read-only - use ^Ecf to attach to console.]&lt;BR /&gt;&lt;BR /&gt;Presss control+E together and cf&lt;BR /&gt;</description>
      <pubDate>Sun, 03 Oct 2010 08:20:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257550#M471674</guid>
      <dc:creator>SUDHAKAR_18</dc:creator>
      <dc:date>2010-10-03T08:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to prove that the server is rebooted manually</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257551#M471675</link>
      <description>So you are saying that this account rebooted the wrong server?&lt;BR /&gt;Does this account have root access or is it in the shutdown.allow file?&lt;BR /&gt;&lt;BR /&gt;Is the shell command history on? Look in the history file of the account to see if you find anything javascript&amp;amp;colon;postAnswerSubmit('submit');</description>
      <pubDate>Sun, 03 Oct 2010 13:02:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257551#M471675</guid>
      <dc:creator>TTr</dc:creator>
      <dc:date>2010-10-03T13:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to prove that the server is rebooted manually</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257552#M471676</link>
      <description>&amp;gt;Reboot time from shutdownlog:&lt;BR /&gt;&amp;gt;02:40 Sat Oct 2, 2010. Reboot: (by s7cs!root)&lt;BR /&gt;&lt;BR /&gt;This pretty much says the system was rebooted by root.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;User activities at the time of reboot:&lt;BR /&gt;&lt;BR /&gt;What produced this output?&lt;BR /&gt;&lt;BR /&gt;&amp;gt;History of user activities on pts/2:&lt;BR /&gt;&amp;gt;reboot -r&lt;BR /&gt;&lt;BR /&gt;What produced this?  This points to the reboot.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;Only giza user account is logged in at the time of Central Server reboot. But the user who owns this account is denying it. &lt;BR /&gt;&lt;BR /&gt;Well, there were two root logins at the same time.</description>
      <pubDate>Mon, 04 Oct 2010 02:14:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257552#M471676</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2010-10-04T02:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to prove that the server is rebooted manually</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257553#M471677</link>
      <description>Hi Robert,&lt;BR /&gt;&lt;BR /&gt;Reboot was initiated by root user , check root user login time and source IP by "last -R " &lt;BR /&gt;&lt;BR /&gt;regards&lt;BR /&gt;Johnson</description>
      <pubDate>Mon, 04 Oct 2010 03:57:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257553#M471677</guid>
      <dc:creator>johnsonpk</dc:creator>
      <dc:date>2010-10-04T03:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to prove that the server is rebooted manually</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257554#M471678</link>
      <description>Hi Guys,&lt;BR /&gt;&lt;BR /&gt;Here are the answers to your questions:&lt;BR /&gt;&lt;BR /&gt;It is possible that the giza account accidentally rebooted s7cs server or it could really have been done. This is why I need to verify if the shutdown log indicate that the reboot initiated by root was manual or automatic?&lt;BR /&gt;&lt;BR /&gt;The giza account was now disabled by the Admin because of the incident so I'm unable to verify the command history for that account at this time.&lt;BR /&gt;&lt;BR /&gt;User activities details were from the wtmp file.&lt;BR /&gt;&lt;BR /&gt;History of user activities came from pts/2 file under .sh_history folder.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Robert Peregrin</description>
      <pubDate>Mon, 04 Oct 2010 08:31:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257554#M471678</guid>
      <dc:creator>Robert Peregrin</dc:creator>
      <dc:date>2010-10-04T08:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to prove that the server is rebooted manually</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257555#M471679</link>
      <description>Hi Guys,&lt;BR /&gt;&lt;BR /&gt;Here is the output of last -R.&lt;BR /&gt;&lt;BR /&gt;root     pts/1        s7s101           Sat Oct  2 02:52 - 06:06  (03:14)&lt;BR /&gt;giza     pts/0        157.234.229.16   Sat Oct  2 02:47 - 06:06  (03:18)&lt;BR /&gt;reboot   system boot                   Sat Oct  2 02:45   still logged in&lt;BR /&gt;root     pts/3        s7sdb3           Sat Oct  2 02:35 - 02:39  (00:03)&lt;BR /&gt;root     pts/2        s7s101           Sat Oct  2 02:29 - 02:40  (00:10)&lt;BR /&gt;giza     pts/1        157.234.229.16   Sat Oct  2 02:28 - 02:40  (00:12)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Robert Peregrin</description>
      <pubDate>Mon, 04 Oct 2010 09:10:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257555#M471679</guid>
      <dc:creator>Robert Peregrin</dc:creator>
      <dc:date>2010-10-04T09:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to prove that the server is rebooted manually</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257556#M471680</link>
      <description>&amp;gt;Only giza user account is logged in at the time of Central Server reboot. But the user who owns this account is denying it. &lt;BR /&gt;&lt;BR /&gt;well there was two sessions initiated from IP 157.234.229.16, trace that IP address &lt;BR /&gt;&lt;BR /&gt;&amp;gt;History of user activities on pts/2:&lt;BR /&gt;&amp;gt;reboot -r&lt;BR /&gt;&lt;BR /&gt;&amp;gt;root pts/2 s7s101 Sat Oct 2 02:29 - 02:40 (00:10)&lt;BR /&gt;&lt;BR /&gt;some one logged in from  "s7s101 "  and executed a reboot , so you may need to go through the user's command history and wtmp on that s7s101 as well to find out the source IP/hostname from the user logged in&lt;BR /&gt;</description>
      <pubDate>Mon, 04 Oct 2010 09:36:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257556#M471680</guid>
      <dc:creator>johnsonpk</dc:creator>
      <dc:date>2010-10-04T09:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to prove that the server is rebooted manually</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257557#M471681</link>
      <description>&amp;gt;This is why I need to verify if the shutdown log indicate that the reboot initiated by root was manual or automatic?&lt;BR /&gt;&lt;BR /&gt;There is no difference.  All we know is a reboot was done.  (What do you mean by automatic, a cron job?)&lt;BR /&gt;&lt;BR /&gt;&amp;gt;The giza account was now disabled by the Admin because of the incident so I'm unable to verify the command history for that account at this time.&lt;BR /&gt;&lt;BR /&gt;It seems Admin should disable the Admin account since root did it.  :-)  Unless you have shutdown.allow.&lt;BR /&gt;&lt;BR /&gt;Why can't you see the history for that account?  You are the admin aren't you?</description>
      <pubDate>Mon, 04 Oct 2010 11:24:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257557#M471681</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2010-10-04T11:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to prove that the server is rebooted manually</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257558#M471682</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I'm not the admin but I used to have almost the same privileges as the admin but the Admin has now given me only restricted access.&lt;BR /&gt;&lt;BR /&gt;Note that the user giza can rlogin to s101 as root and from there, this account can rlogin to s7cs as root. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Robert Peregrin</description>
      <pubDate>Tue, 05 Oct 2010 09:18:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257558#M471682</guid>
      <dc:creator>Robert Peregrin</dc:creator>
      <dc:date>2010-10-05T09:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to prove that the server is rebooted manually</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257559#M471683</link>
      <description>There is no way I can prove the manual reboot as my access privillege has been restricted.</description>
      <pubDate>Tue, 05 Oct 2010 10:16:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-prove-that-the-server-is-rebooted-manually/m-p/5257559#M471683</guid>
      <dc:creator>Robert Peregrin</dc:creator>
      <dc:date>2010-10-05T10:16:42Z</dc:date>
    </item>
  </channel>
</rss>

