log telnet sessions

Hi All,

I want to log a telnet/ftp sessions to my box success/failed in a messages file or log, i tried to search google but not getting exact commands for that. kindly let me know how can it be done so that I can see authentication messages of telnet in my box. My OS is AIX 5.3.

Thanks
virgo
virgo0880Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

woolmilkporcCommented:
Hi again,

unfortunately you can't log telnet sessions on the server (besides the normal login/logout stuff in wtmp, of course, which you could view with "last". See "man last").

The ftp daemon does have a logging facility, however.

To activate it do the following:

- Edit /etc/inetd.conf and change

ftp     stream  tcp6    nowait  root    /usr/sbin/ftpd         ftpd
to
ftp     stream  tcp6    nowait  root    /usr/sbin/ftpd         ftpd -l

- Edit /etc/syslog.conf and add

daemon.info /var/adm/ftpd.log
(or choose a different filename/path according to your needs).

- Issue

touch /var/adm/ftpd.log
(or the filename/path you chose above)
and
refresh -s syslogd

From now on the ftpd log will be written to the file you configured.

wmp


0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
virgo0880Author Commented:
I will check the same and update

Thanks
virgo
0
woolmilkporcCommented:
Forgot to mention - after making changes to /etc/inetd.conf always isssue:

refresh -s inetd

wmp
0
virgo0880Author Commented:
I got a link while googling which says that telnet sessions can be logged. I tried this configuration and I see the sessions are getting logged :

http://www.aixmind.com/?p=650

This is just to share the information for all.

Virgo
0
woolmilkporcCommented:
The method you posted will record any successful login, be it via telnet or whatever.

This is basically not more information than is already contained in /var/adm/wtmp, viewable with "last", as I already wrote.

0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Unix OS

From novice to tech pro — start learning today.