- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- How do you determine what IP address deactivated a...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-14-2002 08:48 AM
03-14-2002 08:48 AM
How do you determine what IP address deactivated an ftp account
ftp userid has /bin/false shell. Any help would be appreciated.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-14-2002 08:59 AM
03-14-2002 08:59 AM
Re: How do you determine what IP address deactivated an ftp account
You'll want to turn logging on for ftp in inetd.conf. Add an -l (that's ell not one) to the ftp line & bounce inetd.
You can also turn on more specific options with /etc/ftpd/ftpaccess - see the following links
http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/B2355-90685/B2355-90685_top.html&con=/hpux/onlinedocs/B2355-90685/00/00/14-con.html&toc=/hpux/onlinedocs/B2355-90685/00/00/14-toc.html&searchterms=ftpd&queryid=20020314-085906
http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/B2355-90696/B2355-90696_top.html&con=/hpux/onlinedocs/B2355-90696/00/00/36-con.html&toc=/hpux/onlinedocs/B2355-90696/00/00/36-toc.html&searchterms=ftpaccess&queryid=20020314-090102
This will explain how to increase the value of allowed incorrect logins.
With a generic login the best you'll be able to determine is source IP of the login. Then you'll have to track down the workstation with that IP. I never use genric IDs when at all possible for this exact reason.
HTH,
Jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-14-2002 09:04 AM
03-14-2002 09:04 AM
Re: How do you determine what IP address deactivated an ftp account
I dont think -l option helps in this case. Even when -l option is there, the syslog does not record the IP address if the login id access is incorrect!! . Only when the ftp can login successfully, does it show the IP address from which the connection was done.
-raj
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-14-2002 09:05 AM
03-14-2002 09:05 AM
Re: How do you determine what IP address deactivated an ftp account
fd_unsuctty (man getprpwent) may store the hostname of the last unsuccessful login:
The next fields are used to protect against login spoofing, listing
the time and location of last login. fd_slogin and fd_ulogin are time
stamps of the last successful and unsuccessful login attempts.
fd_suctty and fd_unsuctty are the terminal device or (if supported)
host names of the terminal or host from which the last login attempt
occurred.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-14-2002 11:50 AM
03-14-2002 11:50 AM
Re: How do you determine what IP address deactivated an ftp account
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-14-2002 11:59 AM
03-14-2002 11:59 AM
Re: How do you determine what IP address deactivated an ftp account
But for the future just give #inetd -l it will keep the message in syslog.log file about
1. The pid
2. The Host Name
3. The IP Add of the host Name
4. The User Name
Sandip
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-14-2002 12:51 PM
03-14-2002 12:51 PM
Re: How do you determine what IP address deactivated an ftp account
Ron
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-14-2002 12:51 PM
03-14-2002 12:51 PM
Re: How do you determine what IP address deactivated an ftp account
The command /usr/lbin/getprpw
Prashant.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-14-2002 03:27 PM
03-14-2002 03:27 PM
Re: How do you determine what IP address deactivated an ftp account
FTP would have to be tweaked to write failed login attempts (and log the host) to the tcb - it's not to hard of a modification.