Viewing previous activity

Posted on 1999-12-20
Medium Priority
Last Modified: 2013-12-27
I have a small Solaris workstation that, until now, allowed many people access to the root user account. I found that someone did something that deleted the entire /bin directory, preventing anyone from accessing the machine. Fortunately I had a telnet session running and was able to copy another machine's /bin files and get access restored; however, I cannot access it via any XDMCP clients.
Is there a SIMPLE way to get my system back to what it was or at least find a log file that can tell me what happened? I do not have a backup.
Question by:rsorrent

Accepted Solution

shlomoy earned 4000 total points
ID: 2297163
Basically it's not clear if you have rebooted your system since the
disaster. It seems some services has gone down due to the abnormal state.
I recommend rebooting, but if you are interested just in the XDMCP
service, then assuming you use CDE you should do (as root):
/etc/init.d/dtlogin stop
/etc/init.d/dtlogin start

Expert Comment

ID: 2297489
if you had accountig running, you can view the activity of processes terminated using the acctcom command on the pacct file (in /usr/adm).
if you had auditing running, use auditpr on the file (bin1, bin2, or trail)

Featured Post

[Webinar] Improve your customer journey

A positive customer journey is important in attracting and retaining business. To improve this experience, you can use Google Maps APIs to increase checkout conversions, boost user engagement, and optimize order fulfillment. Learn how in this webinar presented by Dito.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In tuning file systems on the Solaris Operating System, changing some parameters of a file system usually destroys the data on it. For instance, changing the cache segment block size in the volume of a T3 requires that you delete the existing volu…
A metadevice consists of one or more devices (slices). It can be expanded by adding slices. Then, it can be grown to fill a larger space while the file system is in use. However, not all UNIX file systems (UFS) can be expanded this way. The conca…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
This video shows how to set up a shell script to accept a positional parameter when called, pass that to a SQL script, accept the output from the statement back and then manipulate it in the Shell.
Suggested Courses
Course of the Month7 days, 10 hours left to enroll

607 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question