Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member ozmo's Avatar
    Join Date
    Jul 2007
    Location
    Australia
    Posts
    32

    Default WHM activity / SSH activity

    Hi all,

    I have recently employed a company to perform a security audit on one of my servers. They claim they have been working on the server for aprox. one week.

    I have seen no activity on the server via ssh. I simply ran the command (last -20) to see how long they had actually been working and low and behold there was absolutely no record of any other IP addresses apart from my home and my office.

    So my question is...

    I assume if they were accessing WHM to perform part of their audit, performance tweaking and installing software, I would be able find record of their activity somewhere, correct?

    Any advise would be very much appreciated.

    Thanks,

    oz

  2. #2
    Member
    Join Date
    Aug 2002
    Posts
    1,120

    Default

    WHM access logs are located at /usr/local/cpanel/logs/access_log

    It will contain a log of all WHM, cPanel, and Webmail activity.

  3. #3
    Member
    Join Date
    Jan 2004
    Posts
    33

    Default

    Quote Originally Posted by ozmo View Post
    Hi all,

    I have recently employed a company to perform a security audit on one of my servers. They claim they have been working on the server for aprox. one week.

    I have seen no activity on the server via ssh. I simply ran the command (last -20) to see how long they had actually been working and low and behold there was absolutely no record of any other IP addresses apart from my home and my office.

    So my question is...

    I assume if they were accessing WHM to perform part of their audit, performance tweaking and installing software, I would be able find record of their activity somewhere, correct?

    Any advise would be very much appreciated.

    Thanks,

    oz
    I would say that they would find it very difficult to achieve much without shell....
    I'd be asking for a log of changes - they should be able to provide this (or else what plan were they working to - to secure the box).

    Consider getting chirpy to look at the box, the configserver services have been excellent and invaluable to me.

    Just my 2c/2p
    I know nothing but I'm handy with the search button! (Try it, you might like it)

  4. #4
    Member
    Join Date
    Feb 2003
    Location
    Texas
    Posts
    73

    Default

    I personally would recommend PSM myself, they tell you exactly what they are doing and when they are doing

  5. #5
    Member ozmo's Avatar
    Join Date
    Jul 2007
    Location
    Australia
    Posts
    32

    Thumbs up AdminGeekz

    I went with AdminGeekz. Best decision i ever made.

    The company in question was Server Wizards. Absolutely terrible.

    Try running a search on WHT, you'll see what I mean.

Similar Threads & Tags
Similar threads

  1. How do you check developers activity?
    By Mister9 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 07-11-2011, 06:44 PM
  2. How to log SSH activity
    By maever in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-28-2009, 09:23 AM
  3. How To : MySql Activity monitor
    By Manuel_accu in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 10-07-2006, 04:18 AM
  4. suspecious activity on the server
    By simonlee in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 11-25-2003, 07:48 AM
  5. Log for Frontpage activity?
    By WebmastTroy in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 06-13-2003, 10:46 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube