Logging all commands
Results 1 to 5 of 5

Thread: Logging all commands

  1. #1

    Exclamation Logging all commands

    Good Afternoon Everyone.

    As most are aware, on the majority of *Nix Systems, all accounts have a history file that logs what they type.

    The problem I have with this, is that certain users connect, then SU to other users, and issue commands. History does not differentiate between those that logged in as the account and those that su-ed to the account.

    Is there any way of logging these?
    Can a connection history be logged to one file, no matter if they su-ed to another account?

    Any help, suggestions, tips are most welcome.

    Thanks
    Pink ribbon scars, That never forget
    I tried so hard, To cleanse these regrets
    My angel wings, Were bruised and restrained
    My belly stings

  2. #2
    Leftie Linux Lover the_JinX's Avatar
    Join Date
    Nov 2001
    Location
    Beverwijk Netherlands
    Posts
    2,534
    I don't think that can be done..

    But then again.. what do I know
    ASCII stupid question, get a stupid ANSI.
    When in Russia, pet a PETSCII.

    Get your ass over to SLAYRadio the best station for C64 Remixes !

  3. #3
    Junior Member
    Join Date
    Jan 2003
    Posts
    1
    not by default.. although you could code an LKM to log keys pressed, but this is messy. when a user su's to another account, the history will go into that account's history file.

  4. #4
    Banned
    Join Date
    Mar 2003
    Posts
    32
    you can use keylogger if your want. try www.invisblekeylogger.com

  5. #5
    Just a Virtualized Geek MrLinus's Avatar
    Join Date
    Sep 2001
    Location
    Redondo Beach, CA
    Posts
    7,324
    Actually, there is something that's being used by the HoneyNet Project. And it's a special bash shell keylogger.

    This patch relies on syslogd.

    http://www.honeynet.org/papers/honey...ols/bash.patch

    This second patch doesn't. The keystrokes can be sent elsewhere via UDP, ensuring that if the localhost's syslog get's pooched there still is a record of activity.
    http://www.honeynet.org/papers/honey...sh-anton.patch
    Goodbye, Mittens (1992-2008). My pillow will be cold without your purring beside my head
    Extra! Extra! Get your FREE copy of Insight Newsletter||MsMittens' HomePage

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •