Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

.sh_history question

Posted on 2009-07-08
3
Medium Priority
?
818 Views
Last Modified: 2012-05-07
On our UNIX system , we have a common account. there are around 6 users who can log into that account. the $HOME/.sh_history file has shown some suspicious commands . ( somebody deleted important files using rm command)..   Through this .sh_history file can i get to know who was the user who ran the rm commands.

One thing to note is everybody first loginto thier indiviuval account and then by using su command they log into common account.

the .sh_history file shows only commands. Can me or adming with extra rights get to know who was the actual user who ran those commands.
0
Comment
Question by:n78298
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 68

Expert Comment

by:woolmilkporc
ID: 24801746
Hi,
with 'su' there should be a logfile called 'sulog' somewhere, depending on your OS.
In some systems, logging is controlled by the environment variable 'SULOG_FILE'
Additionally, there could be syslog entries.
Please check!
wmp
 
 
0
 

Author Comment

by:n78298
ID: 24801800
without su coming into picture , can;t we identify who was the user who issues those commands.
0
 
LVL 68

Accepted Solution

by:
woolmilkporc earned 2000 total points
ID: 24801955
No, unfortunately not, as the history files belong to the target user ('common account'). There is no information contained where the user came from.
You could check who logged in from where at which time using the 'last' command, given you keep the 'wtmp' file long enough.
See 'man last' for details.
wmp
 
 
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let's say you need to move the data of a file system from one partition to another. This generally involves dismounting the file system, backing it up to tapes, and restoring it to a new partition. You may also copy the file system from one place to…
FreeBSD on EC2 FreeBSD (https://www.freebsd.org) is a robust Unix-like operating system that has been around for many years. FreeBSD is available on Amazon EC2 through Amazon Machine Images (AMIs) provided by FreeBSD developer and security office…
This video shows how to set up a shell script to accept a positional parameter when called, pass that to a SQL script, accept the output from the statement back and then manipulate it in the Shell.
In a previous video, we went over how to export a DynamoDB table into Amazon S3.  In this video, we show how to load the export from S3 into a DynamoDB table.

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question