PDA

View Full Version : Configuration for lastb / btmp



kirsooo
16-Apr-2015, 10:12
Hello Guys,

Could you please help me with my problem?

I would need to configure SLES 11 SP3 to log bad login attemps from GUI login screen (KDE). I created file "/var/log/btmp" with touch and set correct permissions. Problem is that with "lastb" command I can see only bad login from ssh in a form :

username ssh:notty localhost/IP date time

in manual pages to last command it is stated that:
"lastb Same as last, except that by default it shows a log of the file /var/log/btmp, which contains all the bad login attempts."

Audit works fine for me but if it is possible I would need to use lastb and btmp file..

Thanks a lot for any hint..

Regards
Peter

Automatic reply
22-Apr-2015, 05:30
kirsooo,

It appears that in the past few days you have not received a response to your
posting. That concerns us, and has triggered this automated reply.

Has your issue been resolved? If not, you might try one of the following options:

- Visit http://www.suse.com/support and search the knowledgebase and/or check all
the other support options available.
- You could also try posting your message again. Make sure it is posted in the
correct newsgroup. (http://forums.suse.com)

Be sure to read the forum FAQ about what to expect in the way of responses:
http://forums.suse.com/faq.php

If this is a reply to a duplicate posting, please ignore and accept our apologies
and rest assured we will issue a stern reprimand to our posting bot.

Good luck!

Your SUSE Forums Team
http://forums.suse.com

jmozdzen
22-Apr-2015, 12:02
Hi Peter,

Hello Guys,

Could you please help me with my problem?

I would need to configure SLES 11 SP3 to log bad login attemps from GUI login screen (KDE). I created file "/var/log/btmp" with touch and set correct permissions. Problem is that with "lastb" command I can see only bad login from ssh in a form :

username ssh:notty localhost/IP date time

in manual pages to last command it is stated that:
"lastb Same as last, except that by default it shows a log of the file /var/log/btmp, which contains all the bad login attempts."

Audit works fine for me but if it is possible I would need to use lastb and btmp file..

Thanks a lot for any hint..

Regards
Peter

AFAICT there's no support for btmp in PAM, which nowadays would be the place where this could get logged centrally. So (writing) btmp support currently needs to be provided by each and every application handling logins, with sshd being the most famous (and probably single) one doing so.

So if no-one else has more current information, I'd say you're out of luck with regards to btmp and will have to stick to auditing.

Regards,
Jens