Title: Message
it would be a good start to check the sulog and the `last` log , in order to see who was logged in that time to the machine , since you have a time stamp - it should be rather simple to narrow it down to the relevent time frame and from there on tracing the address of the one looged in to the machine
 
then check with the ones you know to have the root password whom might have left an open session
 
But first change the password and keep track of whom you tell it to ( if you must at all).
 
Assaf
  -----Original Message-----
From: FW Admin [mailto:[EMAIL PROTECTED]]
Sent: Monday, January 27, 2003 5:12 PM
To: Linux-il@cs. Huji. Ac. Il (E-mail)
Subject: Who changed the root password

These are the suspisious records in the /var/log/messages:


messages.2:Jan 14 18:06:06 mail PAM_pwdb[5947]: password for (root/0) changed by ((null)/0)
messages.3:Jan  8 21:00:13 mail PAM_pwdb[2528]: password for (root/0) changed by ((null)/0)
[root@mail log]#

And the root password was indeed changed. By whom ?

==================================================
Evgeny Popov    Network and Security Administrator
Phone: 972-9-9594995   [EMAIL PROTECTED]
       Tecnomatix Tecnologies Ltd.  
==================================================
"Unix IS user friendly, it is just selective about who his friends are." Anonymous

**************************************************************************************************
** eSafe-IL scanned this outgoing email for viruses, vandals and malicious content **
**************************************************************************************************

---------------------------------------------------------------------------------------------------------------
This e-mail message may contain confidential, commercial and privileged information or data that constitute proprietary information of Cellcom Israel Ltd. Any review or distribution by others is strictly prohibited If you are not the intended recipient you are hereby notified that any use of this information or data by any other person is absolutely prohibited. If you are not the intended recipient, please delete all copies and contact us by e-mailing to: [EMAIL PROTECTED]
Thank You.


Reply via email to