Linux排查异常登录及异常操作

1、查 message

cat /var/log/message
cat /var/log/message.1
cat /var/log/message.2
cat /var/log/message.3
cat /var/log/message.4

2、查 secure

cat /var/log/secure
cat /var/log/secure.1
cat /var/log/secure.2
cat /var/log/secure.3
cat /var/log/secure.4

3、查history命令历史

history

4、查lastlog

lastlog

5、查看失败用户登录记录

lastb

8、查询显示当前用户的IP信息

who -m

注:如有不对的地方,请私信我及时更正,谢谢!

猜你喜欢

转载自blog.csdn.net/qq_34362409/article/details/110081199