Hello managers,
I think there is someone ilegally accessing my machine via an old
account. They are logining in from a remote machine. Before I deactivate the
account I want to find out who. My questions are:
1) Is there someone of tracking down the person? I just have the domain name
from where they login from.
2) How can I check to see if they haven't changed my system?
3) Is there a way to determine the geographical location of a machine using the
domain name?
My last question concerns whether I should summarize this info or not. I don't
think that the replies will posses any major security issues. Please advise.
Thanks in advance!
Marco Panzanella, Staff Engineer
Advanced Electronic Packging Facility
Email: marco_at_gore.afep.cornell.edu
http://www.afep.cornell.edu
171 Kimball Hall, Cornell University, Ithaca, NY 14853
Received on Fri Dec 13 1996 - 15:13:13 NZDT