Logging User Sessions

Logging User Sessions

Tue, 16 May 1995

I'm looking for suggestions on how to capture user log information for dial-in
users on my Linux system.
I have started by modifying the PPPlogin script I use to set up point-to-point
sessions. This script now captures the login name and time and writes them to a
However, to keep track of how long each user is on the system, I also need to
write the logout time to the same file.
This is the part I'm having trouble with - I'd appreciate hearing suggestions
anyone might have.
Please send them by e-mail.



Logging User Sessions

Fri, 26 May 1995

Depends how the users get into the system.
One solution is to use the wtmp file (try `last' to see the sort of
information it contains), or alternatively the /etc/ppp/ppp-log file.
Yet another solution is to utilise the `disconnect' option to pppd.

If you want more sophisticated information than the time online, then you
may take a look at the IP accounting kernel option.



1. how to log users session

I have a system with a few cracked accounts that I would like to see
what the crackers are doing before shutting the accounts down. What I am
looking for is something that does the equivalent of the "script" program,
mailing me the "typescript" file before deleting it after the intruder logs

Does anyone know of such a beast or even a version of "script" that would
compile under Solairs 5.1. It seems Solaris lacks some of the needed
library calls such as cfmakeraw that the FreeBSD and Linux versions need.

Any help would be much appreciated.

            Ackkk! It's...
 __  /|  /

 =(___)=        System Staff          |
    U       SUNY at Stony Brook       |

