Solved

which IP

Posted on 2014-02-12
7
261 Views
Last Modified: 2014-02-16
Dear Experts,

Is it possible to know which IP address modified a script file in Solaris?

Thanks,
0
Comment
Question by:oamal2001
  • 4
  • 2
7 Comments
 
LVL 38

Expert Comment

by:Gerwin Jansen, EE MVE
ID: 39852894
Files are modified by users, not IP addresses.

In case you have logging enabled that shows you when a user logged on from which IP address then you could match the time stamp of the file to that of the logon time.

But if you have multiple logons at the same with the same user-id (functional use) then this will be impossible.
0
 
LVL 8

Accepted Solution

by:
Pepe2323 earned 500 total points
ID: 39854088
That can be a real challenge, all depends of how many user access to your server

if i ware you i will try first check when this script was changed

ls -lc or ls -ltr filename -- you will get the date and time of the last change of that filename

you will need to try to match that time with user connected at that time

last  command can help you but if you have many connections at that time well, this will be difficult

My guess is that script only a few persons have rights to modify it i guess  -- example if its a  script that only root can modify then means not all user have root account ( i hope so )

i hope remote access to the server with root account is not allowed

You policies on that server can make this research  more simple or something impossible.

Regards.
0
 
LVL 38

Expert Comment

by:Gerwin Jansen, EE MVE
ID: 39862407
@oamal2001 - Can you elaborate on how the solution you've selected solves your question?
0
Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

 

Author Comment

by:oamal2001
ID: 39862417
I checked when the file last modified , checked who were logged in at that time and matched that time with user connected at that time
0
 
LVL 38

Expert Comment

by:Gerwin Jansen, EE MVE
ID: 39862422
@oamal2001 - Ok, so you got an answer to which user modified the file. That is an answer to a different question (Who modified ... instead of Which IP modified ...), I suggest that you have this question deleted.
0
 

Author Comment

by:oamal2001
ID: 39862427
You are right I needed from the beginning the IP address , but it happen that modification of the file were on a time only one user logged to the system and because I'm not familiar with UNIX administration I did not think about the time of modification.
0
 
LVL 38

Expert Comment

by:Gerwin Jansen, EE MVE
ID: 39862682
Ok, you've got your answer in the end, I'll just make sure this question is removed from search results. Thanks.
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

One of the biggest threats facing all high-value targets are APT's.  These threats include sophisticated tactics that "often starts with mapping human organization and collecting intelligence on employees, who are nowadays a weaker link than network…
Data breaches are on the rise, and companies are preparing by boosting their cybersecurity budgets. According to the Cybersecurity Market Report (http://www.cybersecurityventures.com/cybersecurity-market-report), worldwide spending on cybersecurity …
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
In a previous video, we went over how to export a DynamoDB table into Amazon S3.  In this video, we show how to load the export from S3 into a DynamoDB table.

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question