Results 1 to 4 of 4

Thread: SSH Logs?

  1. #1
    Member
    Join Date
    Aug 2001
    Location
    Williams,OR,USA
    Posts
    121

    SSH Logs?

    Anyone here know where the SSH Secure File transfer Program keeps it's logs (if it creates any?) A recently fired employee had this program installed on his machine and had access to almost all the company's manufacturing processes. The Big shots are worried about what he might have sent and to whom. So is there anyway to tell.

    Thanks
    Will

  2. #2
    Ultimate Member
    Join Date
    Oct 2003
    Location
    Apex, North Carolina
    Posts
    1,981
    It probably does keep a log, but I do not know where. Perhaps the software maker can tell you.
    You could probably also write a script to do a search on which files were accessed by a specific
    program. At least then you would know what he accessed with that program. You would still need
    to find out where he sent the files. The Router Logs may tell you IF you know or can find out what
    port the program used.

  3. #3
    Member delRhode's Avatar
    Join Date
    Dec 2003
    Location
    Spokane, WA
    Posts
    82
    I don't believe the client keeps any logs... you would want to check the logs on any server running sshd (default log location is /var/log/secure on RedHat/Fedora machines) for accesses by the individual, which might help you eliminate some machines from contention (unless he had root privileges, in which case all bets are off). However, even the server just logs connections by default, not files accessed, from what I've seen.

  4. #4
    Member
    Join Date
    Aug 2001
    Location
    Williams,OR,USA
    Posts
    121
    I figured it was a long shot anyway. Thanks for the replies. I'll run some file recovery software and see if any deleted files might be of interest.

    Thanks again
    Will

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •