<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checking user login in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546127#M875112</link>
    <description>Hi,&lt;BR /&gt;'last' command gives you who are all logged in. to know who are all presently loggedin and what they are doing use command'w'(just w).&lt;BR /&gt;To make out who shutdown the system look into /etc/shutdownlog file.&lt;BR /&gt;</description>
    <pubDate>Thu, 28 Jun 2001 06:44:14 GMT</pubDate>
    <dc:creator>Ravi_8</dc:creator>
    <dc:date>2001-06-28T06:44:14Z</dc:date>
    <item>
      <title>Checking user login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546123#M875108</link>
      <description>Dear Expert,&lt;BR /&gt;            How to check, who user telnet in, rlogin to the server and what are the user doing...?&lt;BR /&gt;So that, all the information will login to a log file.&lt;BR /&gt;Anything happend to the server, we can check back the log file that known who is causing the problems...&lt;BR /&gt;Because every time 2or3 users login using root to login.....Can we check who is using the root to login..?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Kenneth</description>
      <pubDate>Thu, 28 Jun 2001 01:20:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546123#M875108</guid>
      <dc:creator>Kenneth Yap</dc:creator>
      <dc:date>2001-06-28T01:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: Checking user login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546124#M875109</link>
      <description>Hi Yap,&lt;BR /&gt;Beside monitoring /var/adm/syslog/syslog.log,&lt;BR /&gt;and /var/adm/sulog,you can use 'last' command to track all the users.Other commands you can use 'whodo',who -u,&lt;BR /&gt;Even you can restrict use of super user using a script.&lt;BR /&gt;Hope this will help&lt;BR /&gt;Thanks&lt;BR /&gt;Animesh&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Jun 2001 01:58:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546124#M875109</guid>
      <dc:creator>Animesh Chakraborty</dc:creator>
      <dc:date>2001-06-28T01:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: Checking user login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546125#M875110</link>
      <description>Kenneth,&lt;BR /&gt;&lt;BR /&gt;Check the following files:&lt;BR /&gt;/var/adm/syslog/syslog.log&lt;BR /&gt;/var/adm/sulog&lt;BR /&gt;&lt;BR /&gt;The last command will reveal the direct&lt;BR /&gt;login of users, but not who they are if&lt;BR /&gt;they login as root.&lt;BR /&gt;&lt;BR /&gt;Suggest you change the root password&lt;BR /&gt;if you can't identify the people who have&lt;BR /&gt;access, also look at installing a well&lt;BR /&gt;proven product called 'sudo' which is free&lt;BR /&gt;off the following link.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.courtesan.com/sudo" target="_blank"&gt;http://www.courtesan.com/sudo&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Good luck&lt;BR /&gt;Michael</description>
      <pubDate>Thu, 28 Jun 2001 02:59:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546125#M875110</guid>
      <dc:creator>Michael Tully</dc:creator>
      <dc:date>2001-06-28T02:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: Checking user login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546126#M875111</link>
      <description>&lt;BR /&gt;HP has a product called IDS/9000 (you can download it for free frpm software.hp.com)&lt;BR /&gt;&lt;BR /&gt;This Intrusion detection system lets you monitor logins as well as removal of files and lot's of other things.&lt;BR /&gt;&lt;BR /&gt;Perhaps you should give it a try .&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Jun 2001 06:24:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546126#M875111</guid>
      <dc:creator>Rainer von Bongartz</dc:creator>
      <dc:date>2001-06-28T06:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Checking user login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546127#M875112</link>
      <description>Hi,&lt;BR /&gt;'last' command gives you who are all logged in. to know who are all presently loggedin and what they are doing use command'w'(just w).&lt;BR /&gt;To make out who shutdown the system look into /etc/shutdownlog file.&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Jun 2001 06:44:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546127#M875112</guid>
      <dc:creator>Ravi_8</dc:creator>
      <dc:date>2001-06-28T06:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: Checking user login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546128#M875113</link>
      <description>&lt;BR /&gt;Also finger can help you.</description>
      <pubDate>Thu, 28 Jun 2001 07:05:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546128#M875113</guid>
      <dc:creator>federico_3</dc:creator>
      <dc:date>2001-06-28T07:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: Checking user login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546129#M875114</link>
      <description>Hi &lt;BR /&gt;&lt;BR /&gt;If you want to audit users (and some others&lt;BR /&gt;things) you can transform your system to a &lt;BR /&gt;trusted system.&lt;BR /&gt;&lt;BR /&gt;You can find information in you docs...&lt;BR /&gt;&lt;BR /&gt;In sam :&lt;BR /&gt;Auditing and security -&amp;gt; Audited users (accept&lt;BR /&gt;to go in Trusted mode)&lt;BR /&gt;-&amp;gt; audit users &lt;BR /&gt;Choose a user and start audit. By reading log&lt;BR /&gt;file (in action menu) you can see differents &lt;BR /&gt;actions (login, ...).&lt;BR /&gt;&lt;BR /&gt;Remember that TS is a big modification in your&lt;BR /&gt;systeme... But you can go back (see in sam : &lt;BR /&gt;unconvert option, or /usr/lbin/tsconvert -r)  &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;&lt;BR /&gt;Herve</description>
      <pubDate>Thu, 28 Jun 2001 07:42:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546129#M875114</guid>
      <dc:creator>Herve BRANGIER</dc:creator>
      <dc:date>2001-06-28T07:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Checking user login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546130#M875115</link>
      <description>This is a policy suggestion as well as a technical suggestion:&lt;BR /&gt;1. I agree with Michael. Restrict the knowledge of the root password to the Unix administrator and his or her backup.&lt;BR /&gt;2. Make separate ids which have uid=0 for everyone (including yourself) who needs root authority (not necessarily everyone who WANTS it.)&lt;BR /&gt;An easy way to do this is to form the id by adding a zero at the end of their non-root ids (e.g. joe smith has an id, jsmith, with uid=201, and a "root" id, jsmith0, with uid=0.) This way, each user has a separate home directory and shell history file.&lt;BR /&gt;&lt;BR /&gt;Many users think that having root authority will make their lives easier but it can also be a huge liability (like if the user is not careful and executes rm -rf * while in /.)</description>
      <pubDate>Thu, 28 Jun 2001 19:17:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546130#M875115</guid>
      <dc:creator>John Sisak</dc:creator>
      <dc:date>2001-06-28T19:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: Checking user login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546131#M875116</link>
      <description>Hi Yap,&lt;BR /&gt;&lt;BR /&gt;What happened to you happens to me before.&lt;BR /&gt;&lt;BR /&gt;Aside from whats mentioned above monitoring syslog, sulog and last command. Try capturing the .sh_history file of root or user which you suspect is creating your problem. It will show you the commands they entered.&lt;BR /&gt;&lt;BR /&gt;.sh_history should be added to roots .profile or users .profile&lt;BR /&gt;&lt;BR /&gt;  HISTFILE=/.sh_history ; export HISTFILE&lt;BR /&gt;  HISTSIZE=128&lt;BR /&gt;&lt;BR /&gt;The last command will also show you the ip address or hostname where the other roots are logging in.&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Jun 2001 20:56:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546131#M875116</guid>
      <dc:creator>Wilmar Ricio</dc:creator>
      <dc:date>2001-06-28T20:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: Checking user login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546132#M875117</link>
      <description>One more thing I forgot, &lt;BR /&gt;&lt;BR /&gt;As soon as you pinpointed the culprit and located his ip address, you can go to a WinNT dos prompt and run,  &lt;BR /&gt;    nbtstat -A ip_adress&lt;BR /&gt;will show you the users users_name &amp;amp; pc_name.&lt;BR /&gt;&lt;BR /&gt;Hope this will help.</description>
      <pubDate>Thu, 28 Jun 2001 21:05:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546132#M875117</guid>
      <dc:creator>Wilmar Ricio</dc:creator>
      <dc:date>2001-06-28T21:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Checking user login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546133#M875118</link>
      <description>Two things...first thing first.&lt;BR /&gt;&lt;BR /&gt;Restrict who knows the root password by changing it.  And as a security measure.  Place a file called "securetty" in /etc.  This file contains nothing and the importance of this file is of its existence.  Run `chmod 600 /etc/securetty` as well to make it rw to owner only.  Make sure Root is the owner.  This will disallow root from being able to telnet into the machine.  This forces your users to log into your machines themselves and su to root.  The syslog should keep track of su's as well as their personal and root's .sh_history files that keeps track of all commands run.&lt;BR /&gt;&lt;BR /&gt;Second like ravi said run the command `w` to find who's doing what.  How often you want this checked is a different matter.  You can easily set a script up that run out of cron however often you want and writes the output of the `w` command into a log for a fairly good record of what is going on.</description>
      <pubDate>Thu, 28 Jun 2001 21:47:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546133#M875118</guid>
      <dc:creator>Jason Morgan_1</dc:creator>
      <dc:date>2001-06-28T21:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: Checking user login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546134#M875119</link>
      <description>Hello Kenneth,&lt;BR /&gt;&lt;BR /&gt;Have you considered using system accounting?  If you have system accounting turned on, you can issue the command:  acctcom -u username.  This will show all the processes that have been executed for a given user.  &lt;BR /&gt;&lt;BR /&gt;There are also many other useful reports that you can run with system accounting.  I don't know if this gives as much detail as you may be wanting, but I have found it very useful.  Other reports show the system resource usage, by user.  There is a report to show when and how long each user was logged in, a report to show a list of all commands that were run on the system.  As well as a few other nice things.&lt;BR /&gt;&lt;BR /&gt;I don't really know the impact on the system, as I am still evaluating it on our developement system. But, from other posts I've made on the subject, it should be minimal.&lt;BR /&gt;&lt;BR /&gt;Good Luck,&lt;BR /&gt;&lt;BR /&gt;Jared</description>
      <pubDate>Fri, 29 Jun 2001 14:46:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/checking-user-login/m-p/2546134#M875119</guid>
      <dc:creator>Jared Westgate_1</dc:creator>
      <dc:date>2001-06-29T14:46:11Z</dc:date>
    </item>
  </channel>
</rss>

