- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- is there a log for a root password change
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2004 02:45 AM
02-10-2004 02:45 AM
thanks,
scott
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2004 02:50 AM
02-10-2004 02:50 AM
Re: is there a log for a root password change
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2004 02:56 AM
02-10-2004 02:56 AM
SolutionIF the passwd change is accomplished via a sudo command, the sudo log would hold the command of course, but not the value.
But the standard passwd command does not log anywhere AFAIK.
You might consider monitoring root's .sh_history file, but that could be problematic as you'd need to insure it only flags on a passwd command for the root account *only*.
Rgds,
Jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2004 02:57 AM
02-10-2004 02:57 AM
Re: is there a log for a root password change
interesting question but as far as I know there isn't a log file for that on HP-UX.
Best regards,
Ettore
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2004 03:00 AM
02-10-2004 03:00 AM
Re: is there a log for a root password change
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2004 03:01 AM
02-10-2004 03:01 AM
Re: is there a log for a root password change
Simon
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2004 03:01 AM
02-10-2004 03:01 AM
Re: is there a log for a root password change
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2004 07:05 PM
02-10-2004 07:05 PM
Re: is there a log for a root password change
I'm araid I don't know the answer to your question - I looked at this thread in case I could learn something. But your idea of the points system differs from mine, so maybe it would be a good idea to clarify who is right.
My understanding is that if someone tries to help you, you should give them points even if their answer is not what you wanted to read. This means that Pete's original answer was worthy of points. By giving him 0 points you appear to have suggested that he did not even try to help you. His second posting suggests that he took offence - I suspect that giving him 1 point will add to his offence, rather than take away from it!
Pete has helped me in the past. He is knowledgable and helpful and not the sort of person you want to offend - he may not bother to reply next time you ask a question, and you would be the loser, not Pete.
Anyone else got any opinions on whose interpretation of the points system is correct? I would particularly like the opinion of a moderator.
Mark Syder (like the drink but spelt different)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2004 07:15 PM
02-10-2004 07:15 PM
Re: is there a log for a root password change
The passwd command is logged in the .sh_history or logfile if that is set.
If you logged the password change it could provide a hacker with something He or she couldl use to compare to the encrypted password and start taking guesses at the root password.
This is an activity that must have no record.
The /etc/passwd file does contain information on when the password expires(for most users) and when the password was last changed.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2004 11:01 PM
02-10-2004 11:01 PM
Re: is there a log for a root password change
Though I think the zero was a bit extreme, I have absolutely no problem with Scott assigning it.
The answer, while technically correct, offered no explanation as to how or why (I was busy and just threw out a quick response). My second response was strictly in jest and I should have put my typical, "I'm kidding" smiley face after it to indicate so but I forgot.
I've helped Scott before and been rewarded for my efforts. I appreciate Mark's point equity efforts but, from my viewpoint, they weren't really necessary.
Pete Randall (like the door knob, only spelled with an "r" instead of an "h" and the last three letters are different but sound the same . . . . . Oh, nevermind!) ;^)
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2004 11:11 PM
02-10-2004 11:11 PM
Re: is there a log for a root password change
Mark - How about my opinion? The point system is to mark replies that have value. Pete not only provided the correct response but did so within 5 seconds of the original post. That is value.
Cheryl
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2004 11:15 PM
02-10-2004 11:15 PM
Re: is there a log for a root password change
You can change the permission of that file to prevent users to read that info.
But sometimes superuser may need to know when a user changed its password.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2004 11:46 PM
02-10-2004 11:46 PM
Re: is there a log for a root password change
Run a script in the background that checks for change to file /tcb/auth/files/root. And this cript logs it the location you want.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2004 04:54 AM
02-11-2004 04:54 AM
Re: is there a log for a root password change
spwchg=Tue Dec 23 11:38:46 2003