<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deleted /root directory in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/deleted-root-directory/m-p/4476171#M37865</link>
    <description>Most Linux distro's don't have auditing enabled by default, due to the need to setup for your needs.&lt;BR /&gt;&lt;BR /&gt;if /root was deleted, the root user's history file is gone as well, so nix that possibility.&lt;BR /&gt;&lt;BR /&gt;How many people know the root password? How many users are created that have uid 0? You could check various log files in /var, but if it was done intentionally, they more than likely modified the logs as well.</description>
    <pubDate>Mon, 10 Aug 2009 16:17:18 GMT</pubDate>
    <dc:creator>Thomas Callahan</dc:creator>
    <dc:date>2009-08-10T16:17:18Z</dc:date>
    <item>
      <title>Deleted /root directory</title>
      <link>https://community.hpe.com/t5/operating-system-linux/deleted-root-directory/m-p/4476169#M37863</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I have found that /root directory is deleted from one of our linux server (RHEL4).&lt;BR /&gt;&lt;BR /&gt;I have again created that file but i have lost some data.&lt;BR /&gt;&lt;BR /&gt;Is there any way we can check which user or from which machine he/she deleted /root directory.&lt;BR /&gt;&lt;BR /&gt;I want to see all commands executed using root account&lt;BR /&gt;&lt;BR /&gt;I want to check who is deleted /root or from which ip he logged in to the server.&lt;BR /&gt;&lt;BR /&gt;Is there any logs which shows all root related operations, i have seen one log in HP-UX which stores all root related operations.&lt;BR /&gt;&lt;BR /&gt;Please help me in this regard.&lt;BR /&gt;&lt;BR /&gt;Thanks in advance.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 10 Aug 2009 07:21:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/deleted-root-directory/m-p/4476169#M37863</guid>
      <dc:creator>WW288996</dc:creator>
      <dc:date>2009-08-10T07:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: Deleted /root directory</title>
      <link>https://community.hpe.com/t5/operating-system-linux/deleted-root-directory/m-p/4476170#M37864</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;It works just like HP-UX if command log auditing is not turned on.&lt;BR /&gt;&lt;BR /&gt;You need to check the sulog for who switched to root. Unless you have more than one user UID zero a regular user can not do this.&lt;BR /&gt;&lt;BR /&gt;last -R suppressed the hostname display. last by default shows the hostname or the ip address of the system logging in. IP only if hostname does not resolve.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Mon, 10 Aug 2009 08:45:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/deleted-root-directory/m-p/4476170#M37864</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2009-08-10T08:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Deleted /root directory</title>
      <link>https://community.hpe.com/t5/operating-system-linux/deleted-root-directory/m-p/4476171#M37865</link>
      <description>Most Linux distro's don't have auditing enabled by default, due to the need to setup for your needs.&lt;BR /&gt;&lt;BR /&gt;if /root was deleted, the root user's history file is gone as well, so nix that possibility.&lt;BR /&gt;&lt;BR /&gt;How many people know the root password? How many users are created that have uid 0? You could check various log files in /var, but if it was done intentionally, they more than likely modified the logs as well.</description>
      <pubDate>Mon, 10 Aug 2009 16:17:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/deleted-root-directory/m-p/4476171#M37865</guid>
      <dc:creator>Thomas Callahan</dc:creator>
      <dc:date>2009-08-10T16:17:18Z</dc:date>
    </item>
  </channel>
</rss>

