Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-03-2009 05:53 AM
08-03-2009 05:53 AM
su log
I am a newbie to unix world and into security. can someone please help me with the below log.
Jul 24 11:55:50 su: - 8 username
Jul 24 12:12:40 su: - 10 username
Jul 26 11:15:32 su: - 7 username
I understand these are failed logins but what does that number (8,10,7) indicate??
Thanks for helping.
-Indra
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-03-2009 06:05 AM
08-03-2009 06:05 AM
Re: su log
Its your terminal number from which it tried.
And the "-" shows that it is failed.
Regards,
Sooraj
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-03-2009 06:06 AM
08-03-2009 06:06 AM
Re: su log
Number of logins using su
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-03-2009 06:10 AM
08-03-2009 06:10 AM
Re: su log
If they are the number of logins of su, do you think any one tried to login using a tool? coz manually 8 or 10 times is not possible within a second.
-Indra
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-03-2009 06:12 AM
08-03-2009 06:12 AM
Re: su log
SU 06/27 13:26 + ttyp2 root-informix
SU 07/08 11:53 + 2 tmr-root
SU 07/13 14:48 + 6 tmr-root
SU 07/16 12:43 + 2 tmr-root
SU 07/20 06:10 + ttyp1 root-jlp
SU 07/20 06:13 + ttyp8 root-jlp
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-03-2009 06:19 AM
08-03-2009 06:19 AM
Re: su log
Which is this OS?
Regards,
Sooraj
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-03-2009 06:20 AM
08-03-2009 06:20 AM
Re: su log
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-03-2009 06:34 AM
08-03-2009 06:34 AM
Re: su log
Which version?
Regards,
Sooraj
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-03-2009 06:56 AM
08-03-2009 06:56 AM
Re: su log
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-03-2009 08:05 AM
08-03-2009 08:05 AM
Re: su log
It is the terminal number from which it tried to login.
You may see the manpage here
http://docs.sun.com/app/docs/doc/816-5174/sulog-4?a=view ( SUN - but same format followed in HPUX also)
Here is the output from my servers,
11.11
-----------
-----------
hrprd2# tail -f sulog
SU 08/02 18:09 + tty?? root-naredlv
SU 08/02 18:09 + tty?? root-naredlv
SU 08/02 18:09 + tty?? root-nareshp
SU 08/02 18:09 + tty?? root-nareshp
SU 08/03 00:00 + 0 vbinees-root
SU 08/03 05:01 + ta KumarS3-root
SU 08/03 05:42 + ta KumarS3-root
SU 08/03 06:04 + ta lkumar-root
SU 08/03 06:36 + ta lkumar-root
SU 08/03 08:58 + ta lkumar-root
11.23
============
# cat /var/adm/sulog
SU 08/02 22:36 + tty?? root-sfmdb
SU 08/02 22:36 + ttyp1 root-root
SU 08/03 10:18 + ta root-sooraj
SU 08/03 10:18 + ta root-root
Regards,
Sooraj
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-03-2009 07:06 PM
08-03-2009 07:06 PM
Re: su log
You may assign some points if your question is answered . :)
Thank you
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-03-2009 11:40 PM
08-03-2009 11:40 PM
Re: su log
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-03-2009 11:43 PM
08-03-2009 11:43 PM