Skip to main content

Hacking threat - and my idea for solution:

Comments

3 comments

  • ModServ
    You mean that when some account owner login into FTP, he/she can remove backtrace logs from /var/log/messages?
    0
  • quizknows
    OP is probably referring to the logs in /home/user/access-logs and/or /home/user/logs that are owned by the account itself. Technically users could manipulate these, however, like you mentioned /var/log/messages exists and an unprivileged user (i.e. not root) cannot modify that file.
    0
  • cPanelMichael
    Hello :) Yes, as mentioned, the /var/log/messages log file records FTP activity. You can check this log file as "root" if you want to verify if any activity differs from the FTP access logs stored within the account. Thank you.
    0

Please sign in to leave a comment.