We have a system that rebooted over the weekend. There is no sign of
logins anywhere except in /var/log/authlog, which has the entry:
Jul 29 06:54:10 myhost su: SU root on /dev/console
There is no associated "last" entry.
It is our believe that a /dev/console access is just that - physical
access - in which case someone local did something and covered
most, but not all their tracks.
Is there a way a remote access can cause this kind of log entry??
TIA
--
Judith Reed
jreed_at_appliedtheory.com
(315) 453-2912 x5835
Received on Tue Aug 01 2000 - 18:58:19 NZST