Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 8 of 8
  1. #1
    Member
    Join Date
    Jan 2004
    Posts
    755

    Default Root access alert email

    I've had the server send me notification via email anytime root access to the server has occured. Since the move to CP11, I'm getting an email at 16 past midnight that root access has happened, but no IP address has been recorded, making me think it's something from a cron job... Here's an example:

    ALERT-Root Shell Access on: Thu May 24 00:16:17 CDT 2007

    While a normal email has:

    ALERT-Root Shell Access on: Thu May 24 08:05:39 CDT 2007 root pts/0 May
    24 08:05 (adsl-70-244-110-121.dsl.ksc2mo.swbell.net)

    Obviously, I'd like to eliminate the first, since it makes me jump everytime i see it...

  2. #2
    Member
    Join Date
    Apr 2004
    Location
    NJ
    Posts
    28

    Default

    Perhaps your script needs to be updated to reflect the new(?) location of the log file that recorded the ip address of the login?

    Would you share that script?

  3. #3
    Member gtgeorge's Avatar
    Join Date
    Feb 2007
    Posts
    89

    Default

    We get the same email that coincides with the upcp update each early AM. We have gotten them daily since the services done by ConfigServer.
    regards,
    George

  4. #4
    Member verdon's Avatar
    Join Date
    Nov 2003
    Location
    Northern Ontario, Canada
    Posts
    792

    Default

    try the forums at configserver for support for their scripts

  5. #5
    Member cpanelinfoseeker's Avatar
    Join Date
    Oct 2002
    Location
    NE Illinois
    Posts
    319

    Default

    I put a ticket in to Chirpy when this first happened as I was worried. This is normal when mailscanner is restarted. You can duplicate it by doing a manual restart in Mailscanner. I now just watch for the timestamp on the email to be sure that it happens during the nightly cycle only. At any other time, I would be extremely worried!

    Hope this helps,
    Ron

  6. #6
    Member
    Join Date
    Jan 2004
    Posts
    755

    Default

    Here's the code, taken directly from the 'secure your server' sticky:

    Code:
    Server e-mail everytime someone logs in as root
    
    To have the server e-mail you everytime someone logs in as root, SSH into server and login as root.
    
    At command prompt type: pico .bash_profile
    
    Scroll down to the end of the file and add the following line:
    
    echo 'ALERT - Root Shell Access on:' `date` `who` | mail -s "Alert: Root Access from `who | awk '{print $6}'`" your@email.com
    
    Save and exit.
    So, there's no script that's changed...

    Having said that, when CP11 got updated, MailScanner choked, so I reinstalled using CS MailScanner package, so perhaps that's what's triggering it...

    I'll have to try restarting MailScanner and see if that does as suggested.

    And since you mention it, I've not been receiving (that I recall) the normal upcp emails... have to look into that as well

  7. #7
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Our MailScanner script uses the su to root functionality in init to setup the correct environment on restart which is why you'll see a login for root.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  8. #8
    Member
    Join Date
    May 2003
    Posts
    208

    Default

    Quote Originally Posted by chirpy View Post
    Our MailScanner script uses the su to root functionality in init to setup the correct environment on restart which is why you'll see a login for root.
    This is happening for me too.

    Chirpy - Even though it only started since the upgrade to CP11 ??

    Thanks
    Daniel

Similar Threads & Tags
Similar threads

  1. Access root to a server in cluster -> access to dns ?
    By altomarketing2 in forum Security
    Replies: 1
    Last Post: 03-15-2011, 12:09 PM
  2. cPanel Access Alert/Notification
    By Vinayak in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-04-2009, 03:37 PM
  3. E-mail Alert on Root SSH Login
    By crazyaboutlinux in forum New User Questions
    Replies: 6
    Last Post: 06-09-2009, 06:42 AM
  4. cpanel bug / Get root access with root password
    By majidnt in forum cPanel and WHM Discussions
    Replies: 19
    Last Post: 08-24-2005, 12:12 PM
  5. addon domain alert email
    By LS_Drew in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 10-16-2003, 01:48 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube