Can VM report if a user has run a switch user (su) command to root on a Unix agent? (NETIQKB50569)

  • 7750569
  • 02-Feb-2007
  • 24-May-2007

Resolution

goal
Can VM report if a user has run a switch user (su) command to root on a Unix agent?

goal
Can I use Vulnerability Manager to see who has run an su command on a Unix agent?

goal
How do I use VM to check if a user has changed their user ID to become root?

fact
NetIQ Vulnerability Manager 5.0

fact
NetIQ Vulnerability Manager 5.5

fact
VigilEnt Security Agent for Unix 5.0+

fix

To view all available information on switch user (su) commands run on the system:

  1. Start the NetIQ Vulnerability Manager console.
  2. Expand Security Knowledge > Security Checks > NetIQ Checks > UNIX > System.
  3. In the list pane, select the Switch User Command Statistics security check.
  4. In the toolbar, click Actions > Run Security Checks.


note
This check returns a dump of all su command information. If you need real-time alerting on su activities, use the Rules Manager component of Unix Manager. Contact NetIQ Support if you need more information.

Additional Information

Formerly known as NETIQKB50569