Solved

How to track who tried to login my server and from which ip

Posted on 2006-11-29
6
244 Views
Last Modified: 2013-12-27
I wd like to know is any way to find out in solaris who tried to login our server with which user, from which ip and when what times and date.

if any script i need that if any one can provide this.

regards
vivek jauhari
0
Comment
Question by:VivekJauhari
6 Comments
 
LVL 34

Expert Comment

by:PsiCop
ID: 18039131
Depends on the access methods, e.g. telnet, SSH, FTP, NFS, etc.

Each access method logs different information, and different levels of detail.

Which access method(s) do you want to analyze?
0
 
LVL 48

Accepted Solution

by:
Tintin earned 35 total points
ID: 18040900
As PsiCop says, it depends on the method used to log in.

You can list all successful logins with the 'last' command.

0
 
LVL 51

Expert Comment

by:ahoffmann
ID: 18043491
more /var/log/messages
more /var/adm/messages
more /var/adm/syslog
# path depends on your system version/setup
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:VivekJauhari
ID: 18044804
It is ok.. we can check with Last command but i wd like to knwo who tryied to login from which ip if login not success also. so that we can track which ip tring to breck our passwd/server.

is we can find this via any script? and if yes i need that script

regards
vivek jauhari
0
 
LVL 48

Expert Comment

by:Tintin
ID: 18048453
To log failed logins (via telnet/ssh), edit /etc/default/logins and set

SYSLOG_FAILED_LOGINS=0

Then do:

touch /var/adm/loginlog
chown root:sys /var/adm/loginlog
chmod 600 /var/adm/loginlog

0
 
LVL 48

Expert Comment

by:Tintin
ID: 18048455
ssh attempts will be in /var/adm/messages or /var/adm/syslog
0

Featured Post

Secure Your Active Directory - April 20, 2017

Active Directory plays a critical role in your company’s IT infrastructure and keeping it secure in today’s hacker-infested world is a must.
Microsoft published 300+ pages of guidance, but who has the time, money, and resources to implement? Register now to find an easier way.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
netstat -a in AIX unix 8 52
AIX Server 10 91
Java core in Solaris 10 1 313
auto mounter on solaris 1 74
Attention: This article will no longer be maintained. If you have any questions, please feel free to mail me. jgh@FreeBSD.org Please see http://www.freebsd.org/doc/en_US.ISO8859-1/articles/freebsd-update-server/ for the updated article. It is avail…
This tech tip describes how to install the Solaris Operating System from a tape backup that was created using the Solaris flash archive utility. I have used this procedure on the Solaris 8 and 9 OS, and it shoudl also work well on the Solaris 10 rel…
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
This video shows how to set up a shell script to accept a positional parameter when called, pass that to a SQL script, accept the output from the statement back and then manipulate it in the Shell.

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question