- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: chkrootkit lastlog
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2005 08:09 PM
10-12-2005 08:09 PM
chkrootkit lastlog
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2005 08:12 PM
10-12-2005 08:12 PM
Re: chkrootkit lastlog
-Arun
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2005 08:14 PM
10-12-2005 08:14 PM
Re: chkrootkit lastlog
hth.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2005 08:14 PM
10-12-2005 08:14 PM
Re: chkrootkit lastlog
hth.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2005 08:18 PM
10-12-2005 08:18 PM
Re: chkrootkit lastlog
/var/adm/btmp History of bad login attempts
/var/adm/wtmp History of logins, logouts, and date changes
To audit this you can use last / lastb. However, if you are having any different file then, use last or lastb with -f option as,
Example:
# last -f /tmp/successlogin
# lastb -f /tmp/badlogin
hth.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2005 08:22 PM
10-12-2005 08:22 PM
Re: chkrootkit lastlog
# man last or man lastb
-Arun
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2005 09:16 PM
10-12-2005 09:16 PM
Re: chkrootkit lastlog
I hope you are a newbie here. If the answer is correct then assign appropriate points.
See this:
http://forums1.itrc.hp.com/service/forums/helptips.do?#33
Every one in ITRC is great one and spending their time to share their GREAT technical skills to solve problem. ( I did not mean that it is me :)) )
Keep posting questions and assign points :)
thx.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2005 10:27 PM
10-12-2005 10:27 PM
Re: chkrootkit lastlog
The answer you people gave helped me a little bit. Thank u very much.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2005 10:33 PM
10-12-2005 10:33 PM
Re: chkrootkit lastlog
In between I am sorry. As MuthuKumar said, I donot know anything about assigning points. Please donot reject my questions in the future for this issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2005 11:20 PM
10-12-2005 11:20 PM
Re: chkrootkit lastlog
>The answer you people gave helped me a little bit. Thank u very much.
Please try to post full problem, so that we can discuss further in ITRC.
-Arun
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-13-2005 12:04 AM
10-13-2005 12:04 AM
Re: chkrootkit lastlog
------------------------------------------
#ifdef __FreeBSD__
#define WTMP_FILENAME "/var/log/wtmp"
#define LASTLOG_FILENAME "/var/log/lastlog"
#endif
#ifdef __OpenBSD__
#define WTMP_FILENAME "/var/log/wtmp"
#define LASTLOG_FILENAME "/var/log/lastlog"
#endif
#ifndef WTMP_FILENAME
#define WTMP_FILENAME "/var/adm/wtmp"
#endif
#ifndef LASTLOG_FILENAME
#define LASTLOG_FILENAME "/var/adm/lastlog"
#endif
.
.
.
Sinece there is no such file in hp-ux I need to replace a suitable file for that. Which one can I use? Is there any possibility to replace that? If I use /var/adm/wtmp as you people mentioned, I get irrelevant output.
Thanx in Advance
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-13-2005 12:12 AM
10-13-2005 12:12 AM
Re: chkrootkit lastlog
#ifdef __HPUX__
#ifndef WTMP_FILENAME "/var/adm/wtmp"
#define WTMP_FILENAME "/var/adm/wtmp"
#endif
What output you get ?
-Arun
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-13-2005 06:48 PM
10-13-2005 06:48 PM
Re: chkrootkit lastlog
user root deleted or never logged from lastlog!
user shyam deleted or never logged from lastlog!
user rita deleted or never logged from lastlog!
user reghu deleted or never logged from lastlog!
user pranesh deleted or never logged from lastlog!
user f deleted or never logged from lastlog!
user rama deleted or never logged from lastlog!
user kavitha deleted or never logged from lastlog!
user deepa deleted or never logged from lastlog!
I'am very much cruious to know what is the exact content of the files /var/adm/lastlog and /var/adm/wtmp.
If these contents differs, can the entries in wtmp file really replace lastlog entries.
Is this trial correct?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-13-2005 06:55 PM
10-13-2005 06:55 PM
Re: chkrootkit lastlog
# cat /var/adm/wtmp | /usr/sbin/acct/fwtmp |more
Also
man wtmp
man btmp
man utmp
should help. /var/adm/lastlog is not applicable to HP-UX..
-Arun