The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Top Forums > UNIX for Dummies Questions & Answers
Google UNIX.COM


UNIX for Dummies Questions & Answers If you're not sure where to post a UNIX or Linux question, post it here. All UNIX and Linux newbies welcome !!

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
restricting root access keith.m UNIX for Advanced & Expert Users 2 08-31-2006 04:56 AM
root access RBurer SCO 2 05-18-2005 10:36 AM
PHP - few things without root access Sergiu-IT Shell Programming and Scripting 4 04-05-2005 10:20 PM
how to access root priveliges if root password is lost wojtyla Linux 1 02-18-2005 02:24 AM
root access on sun os and permissions allinone UNIX for Dummies Questions & Answers 2 03-12-2002 06:34 AM

Reply
 
Submit Tools LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-30-2005
Registered User
 

Join Date: Aug 2005
Posts: 1
Stumble this Post!
Question log root access

Solaris 8 OS

I believe root access is being logged by my server but I only see it being written to the terminal. I want to know if there is a log file and how to not just log root access but if I can also log the IP address from which it is coming?

Thanks in advance.
Reply With Quote
Forum Sponsor
  #2 (permalink)  
Old 08-30-2005
Registered User
 

Join Date: Aug 2003
Location: NJ
Posts: 39
Stumble this Post!
hi start with eliminating need for access, if you feel that damage is being done to your server. If you think this is someone or something just being nosy, change root passwd and keep it to your self and senior management.
if yet you want to proceed....
next find out what process or script this root user is accessing....
most system logging takes place in /var/adm...Now prior to proceeding, change your root passwd so that you can definatly log failed entries ..
We want to add two additional log files there, sulog and loginlog. /var/adm/sulog logs all su attempts, both successful and failed. This allows you to monitor who is attempting to gain root access on your system. /var/adm/loginlog logs consecutive failed login attempts.

/etc/inetd.conf will tell you what all the services /etc/bin/inetd daemon listens for, since you only want to track ftp and telnet. Start with eliminating(commenting out) the other services (you or your app may need these services, but for now you can live without them)
Reply With Quote
Google The UNIX and Linux Forums
Reply

Thread Tools
Display Modes




All times are GMT -7. The time now is 10:51 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008 The CEP Blog All Rights Reserved -Ad Management by RedTyger Visit The Global Fact Book

Content Relevant URLs by vBSEO 3.2.0