Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > macOS > SSH history

SSH history
Thread Tools
absmiths
Mac Elite
Join Date: Sep 2000
Location: Edmond, OK USA
Status: Offline
Reply With Quote
May 30, 2002, 12:42 PM
 
How can I see an audit of how and when users have logged into my machine? I would like to just verify that noone has connected when I didn't suspect it.
     
johann
Forum Regular
Join Date: Nov 2000
Location: Seattle, Wa, USA
Status: Offline
Reply With Quote
May 30, 2002, 01:28 PM
 
in the terminal type 'last'

does that help?
     
absmiths  (op)
Mac Elite
Join Date: Sep 2000
Location: Edmond, OK USA
Status: Offline
Reply With Quote
May 30, 2002, 03:56 PM
 
</font><blockquote><font size="1" face="Geneva, Verdana, Arial, sans-serif">quote:</font><hr /><font size="1" face="Geneva, Verdana, Arial, sans-serif">Originally posted by johann:
<strong>in the terminal type 'last'

does that help?</strong></font><hr /></blockquote><font size="1" face="Geneva, Verdana, Arial, sans-serif">Yes, that's very nice. Does this data come from a file somewhere? Some of the domain names are too long and I would like to see all of them.

Nevermind, I guess it uses /var/log/wtmp, but I can't make much sense of it.

<small>[ 05-30-2002, 03:58 PM: Message edited by: absmiths ]</small>
     
Camelot
Mac Elite
Join Date: May 1999
Location: San Jose, CA
Status: Offline
Reply With Quote
Jun 2, 2002, 02:13 AM
 
</font><blockquote><font size="1" face="Geneva, Verdana, Arial, sans-serif">quote:</font><hr /><font size="1" face="Geneva, Verdana, Arial, sans-serif">Originally posted by absmiths:
<strong> </font><blockquote><font size="1" face="Geneva, Verdana, Arial, sans-serif">quote:</font><hr /><font size="1" face="Geneva, Verdana, Arial, sans-serif">Originally posted by johann:
<strong>in the terminal type 'last'

does that help?</strong></font><hr /></blockquote><font size="1" face="Geneva, Verdana, Arial, sans-serif">Yes, that's very nice. Does this data come from a file somewhere? Some of the domain names are too long and I would like to see all of them.

Nevermind, I guess it uses /var/log/wtmp, but I can't make much sense of it.</strong></font><hr /></blockquote><font size="1" face="Geneva, Verdana, Arial, sans-serif">/var/log/wtmp is indeed the file, but you're not supposed to be able to make sense or it. If it were a plain text file (for example, in the same format as the output of the 'last' command) it would be too easy for a hacker to edit the file and remove all trace of his login.
Gods don't kill people - people with Gods kill people.
     
petej
Dedicated MacNNer
Join Date: Oct 2001
Location: Baltimore, MD, US
Status: Offline
Reply With Quote
Jun 3, 2002, 12:42 PM
 
It's not that hard anyway. The format of wtmp is well-documented, and it's pretty easy to remove records. Since the records are fixed-length, you can even use the dd command to edit out parts you want to hide, so you don't have to write a program.
     
   
 
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Top
Privacy Policy
All times are GMT -4. The time now is 09:29 PM.
All contents of these forums © 1995-2017 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2017, Jelsoft Enterprises Ltd.,