LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-16-2010, 02:36 AM   #1
pranks
LQ Newbie
 
Registered: Jun 2010
Posts: 7

Rep: Reputation: 0
Question how to find USB logs in linux


HI
how to find USB enteries/ logs in linux
 
Old 06-16-2010, 02:49 AM   #2
druuna
LQ Veteran
 
Registered: Sep 2003
Posts: 10,532
Blog Entries: 7

Rep: Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405
Hi,

Take a look in /var/log/messages or execute dmesg.

Both should contain usb related messages.

Hope this helps.
 
Old 06-16-2010, 03:48 AM   #3
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Also, could you explain the context of the information you are seeking? Presumably this is security-related, as you've posted in LQSEC, right? The more verbose you are, the greater the chances of having a productive discussion.
 
Old 06-17-2010, 01:41 AM   #4
pranks
LQ Newbie
 
Registered: Jun 2010
Posts: 7

Original Poster
Rep: Reputation: 0
Thnx a lot for quick response drrunna
@winsux : someone has used my pc in my absence and i doubt data theft. probably i may find some usb entries which does not belong to mine
 
Old 06-17-2010, 03:04 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by pranks View Post
someone has used my pc in my absence
Was it off? Was it on but locked? Or was no login required? How is your default access set up? Shell only or Xorg access?


Quote:
Originally Posted by pranks View Post
and i doubt data theft.
What kind of data are we talking about? Was it passworded, encrypted or plain text? Large or small files? Easy to find?


Quote:
Originally Posted by pranks View Post
probably i may find some usb entries which does not belong to mine
Can you narrow down the suspected period of time? If it was for example an USB stick then 'grep usb-storage /var/log/messages' will show the times when an USB mass storage device was attached. If a login is required then you can correlate times with those from running 'last'. If a login was not required then you should not have put that data there in the first place as an out-of-the-box GNU/Linux installation does not come with extensive auditing enabled by default so UUIDs, device names and partition labels may or may not have been logged.
 
Old 06-19-2010, 11:52 AM   #6
pranks
LQ Newbie
 
Registered: Jun 2010
Posts: 7

Original Poster
Rep: Reputation: 0
re

System was on
some emails and .dot documents.small files only n it was not pwd protected.
times was somewhere betwwen 9 to 2pm (+5.30 GMT)
I am not sure whether usb was attached or not, probably someone transferred the files using his hotmail, yahoo etc.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] usb-storage + usb card-reader = klogd spamming logs GrapefruiTgirl Linux - Kernel 9 08-10-2009 09:34 AM
To find out the logs count gsiva Programming 1 07-02-2009 06:40 AM
Finding LDAP Server Logs / Application Logs in Linux arbignay Linux - Newbie 2 03-24-2008 09:54 AM
qmail can't find my logs :) OTIM Linux - Server 2 12-05-2007 02:27 PM
Where can i find the logs for Ftp? ZAMO Linux - Server 2 07-09-2007 05:12 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration