- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- security problem
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2006 07:48 PM
10-12-2006 07:48 PM
Customer want to log everything that the users does on the system such as who, when login and logoff, what he does, etc.
Can we do these without third part software?
Is nettl or auditting system for this?
Thanks.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2006 07:55 PM
10-12-2006 07:55 PM
Re: security problem
You can check user's .sh_history file for all commands he/she typed but there is not time stamp.
You can also turn on the system audit from sam
Yang
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2006 07:59 PM
10-12-2006 07:59 PM
Re: security problem
Modify /etc/rc.config.d/netdaemons file and include:
export INETD_ARGS="-l"
Reestart "inetd" daemon with option "-l"
# ps -ef|grep -i inet
root 1452 1 0 Sep 21 ? 1:10 /usr/sbin/inetd -l
rgs,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2006 08:06 PM
10-12-2006 08:06 PM
Re: security problem
View information in /var/adm/syslog/syslog.log file. Sample ssh login:
Oct 13 10:03:11 minerva sshd[2229]: Accepted publickey for userfrom 172.16.0.41
port 54829 ssh2
rgs
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-13-2006 05:43 AM
10-13-2006 05:43 AM
Solutionlast -R user1
cat ~user1/.sh_history
Now these are not a complete picture at all. For instance, the user may edit a file with vi, then issue the vi command :!sh and now the user can run any commands without a trace.
You could setup the script command to track all the keystrokes and text sent to the screen but plan to spend a lot of time looking over all the output. It sounds like your customer does not trust a user. Rather than fixing the blame due to a mistake, tell your customer to create a safe menu rather than giving the problem user(s) a shell login.
Bill Hassell, sysadmin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-13-2006 07:55 AM
10-13-2006 07:55 AM