Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

.sh_history question

Posted on 2009-07-08
3
Medium Priority
?
826 Views
Last Modified: 2012-05-07
On our UNIX system , we have a common account. there are around 6 users who can log into that account. the $HOME/.sh_history file has shown some suspicious commands . ( somebody deleted important files using rm command)..   Through this .sh_history file can i get to know who was the user who ran the rm commands.

One thing to note is everybody first loginto thier indiviuval account and then by using su command they log into common account.

the .sh_history file shows only commands. Can me or adming with extra rights get to know who was the actual user who ran those commands.
0
Comment
Question by:n78298
  • 2
3 Comments
 
LVL 68

Expert Comment

by:woolmilkporc
ID: 24801746
Hi,
with 'su' there should be a logfile called 'sulog' somewhere, depending on your OS.
In some systems, logging is controlled by the environment variable 'SULOG_FILE'
Additionally, there could be syslog entries.
Please check!
wmp
 
 
0
 

Author Comment

by:n78298
ID: 24801800
without su coming into picture , can;t we identify who was the user who issues those commands.
0
 
LVL 68

Accepted Solution

by:
woolmilkporc earned 2000 total points
ID: 24801955
No, unfortunately not, as the history files belong to the target user ('common account'). There is no information contained where the user came from.
You could check who logged in from where at which time using the 'last' command, given you keep the 'wtmp' file long enough.
See 'man last' for details.
wmp
 
 
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Introduction Regular patching is part of a system administrator's tasks. However, many patches require that the system be in single-user mode before they can be installed. A cluster patch in particular can take quite a while to apply if the machine…
Every server (virtual or physical) needs a console: and the console can be provided through hardware directly connected, software for remote connections, local connections, through a KVM, etc. This document explains the different types of consol…
Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:
This video shows how to set up a shell script to accept a positional parameter when called, pass that to a SQL script, accept the output from the statement back and then manipulate it in the Shell.
Suggested Courses
Course of the Month11 days, 6 hours left to enroll

886 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question