uname -a output
Linux server.domain.com 2.6.9-67.0.15.ELsmp #1 SMP Tue Apr 22 13:50:33 EDT 2008 i686 i686 i386 GNU/Linux
At our company, we have hundreds of employees that access this server for reporting purposes.
However, someone was familiar enough with sendmail and used it to send an email that was crafted to look like it came from a specific person and was sent to the entire company with private information. Huge security concern.
I have been tasked with helping figure out this spoof. Here is what I need to figure out.
The mail was sent at 11:12PM on May 17th.
I need to find the IP address of the system that made a shell/terminal connection to the server around this time and used the sendmail command to send an email to a specific mailing list.
Any ideas ? I'm not entirely familiar with logging yet. The mail log file doesn't seem to provide much useful information.
Perfect thanks! I was able to last -f that file and get what I was looking for. Now I have run into another road block with SunOS 5.8.
The wtmp file on the Linux server showed that a connection was made from another server at the time/date I was interested in.
So now I am tasked with figuring out the same thing on a SunOS box as I trace backwards in this mess.
The SunOS box doesn't have any wtmp files in /var/log , but it does have some large wtmpx and utmpx files in /var/adm
I cannot figure out how to view these files properly. There is no 'last' command on SunOS 5.8 (at least not this installation anyways). who -a doesn't give me any useful information.
I copied the wtmpx and utmpx files to a linux box and tried running 'last -f' on them, but the formatting is all screwed up. So I tried other tools like 'rawtmp' and 'dump-utmp' but they still do not look correct.
Is there any way I can dump or view wtmpx & utmpx on the SunOS box properly so that I can see who logged on and when?
There is a dumpadm tool, but I have no idea how to get it to work.
I tried to run the command " /usr/lib/acct/fwtmp", the curser just sat there. I looked at the file (ls -al), which was very small and should not have hanged. Can anyone tell me why this happened?
What exactly do you mean when you say "input file" being too big? Can you give me an example of input file?
---------- Post updated at 02:02 PM ---------- Previous update was at 01:55 PM ----------
---------- Post updated at 02:05 PM ---------- Previous update was at 02:02 PM ----------
I get this error when I log in through console "fatal: Read from socket failed: Connection reset by peer". Can you tell me what this is and why it happens, and how to stop it? Thank you.
You can ignore the second part of my question. It does not relate. It was a separate
question. I am new to this forum and was not sure how to post a new question.
---------- Post updated at 09:57 AM ---------- Previous update was at 09:38 AM ----------
Here is the output from date and
# date
Tue May 25 09:56:48 EDT 2010
# ls -lad /var/adm/* | grep tmp
-rw-r--r-- 1 root bin 2976 May 24 10:25 /var/adm/utmpx
-rw-r--r-- 1 adm adm 153264 May 24 10:25 /var/adm/wtmpx
---------- Post updated at 10:01 AM ---------- Previous update was at 09:57 AM ----------
I ran the command about "/var/adm/wtmpx | /usr/lib/acct/fwtmp" and it spit out a lot of information. Here is a piece of the output: run-level 3 Wed May 12 12:01:06 2010
LOGIN dt console 360 6 0000 0000 1273680066 0 0 3 :0 Wed May 12 12:01:06 2010
LOGIN dt console 360 8 0017 0000 1273680066 0 0 3 :0 Wed May 12 12:01:06 2010
LOGIN dt console 362 6 0000 0000 1273680066 0 0 3 :0 Wed May 12 12:01:06 2010
LOGIN dt console 362 8 0017 0000 1273680066 0 0 3 :0 Wed May 12 12:01:06 2010
root co console 349 7 0000 0000 1273680076 0 0 0 Wed May 12 12:01:16 2010