Re: User logins not appearing in wtmp?



On Wed, 06 Jun 2012 11:36:09 -0300, francis picabia wrote:

Today I see from logwatch report 28 sshd logins from one user at an IP
address in a different continent than usually seen here.

When I look up this user with last command to see if this is part of a
travel pattern or perhaps their account is compromised, I don't get any
matches. I've used last and last -f /var/log/wtmp.1 with the user name
and there are no matches.

OpenSSH logins fall under "/var/log/auth*" logs.

Yet finger shows a login from Apr 24, which jives with their last
.bash_history update

One way this could happen is by use of sftp/scp. Is there a way to get
last to record these sessions as well?

Mmm... any specific reason for wanting these logs available within
wtmp? :-?

Greetings,

--
Camaleón


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx
Archive: http://lists.debian.org/jqnvkc$u68$16@xxxxxxxxxxxxxxx



Relevant Pages

  • RE: redhat-list digest, Vol 1 #8511 - 29 msgs
    ... To subscribe or unsubscribe via the World Wide Web, ... Command running on terminal at some intervals (Reuben D. ... Re: bash shell ... rsync with public/private keys/no passwords ...
    (RedHat)
  • RE: redhat-list digest, Vol 1 #8511 - 29 msgs
    ... To subscribe or unsubscribe via the World Wide Web, ... Command running on terminal at some intervals (Reuben D. ... Re: bash shell ... rsync with public/private keys/no passwords ...
    (RedHat)
  • Re: vim like completion in bash?
    ... If the OP still wants to make bash behave the same as mine -- among ... output of the "shopt" command ... there might be compile-time options that are relevant to TAB ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: usb2 port gets very slow on 2-gig Flash Drive.
    ... You make all the filesystem changes to a disk image on your hard disk, ... It is July 24 and ps ax -Olstart shows me that tar has ... several minutes between the rm -r -f command to wipe the FAT ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • hard drive repair problem
    ... booting and partitioning software from other OSs ... (e.g., DOS FDISK, OS/2 FDISK) ... Command: p ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". ...
    (Debian-User)