Re: Finding IP address of Failed Login Attempt
Ed Fishel <edfishel-r/[email protected]> Wed, 2 May 2007 08:33:19 -0500
| Newsgroups | gmane.comp.systems.as400.security |
|---|---|
| Message-ID | <OF5A46E426.0E9F1D26-ON862572CF.00495DC1-862572CF.004A60C6@us.ibm.com> |
ALopez wrote on 05/02/2007 07:44:58 AM: > We run a nightly report using DSPAUDJRNE ENTTYP(PW). This report has > ballooned to hundreds of pages because of one user id. > > VIOLATION USER USER DEVICE REMOTE LOCAL NETWORK JOB > JOB > TYPE PROFILE NAME NAME NAME NAME ID > NAME USER > PW Q QTCP MATTHEW QTVDEVICE QTCP > PW Q QTCP MATTHEW QTVDEVICE QTCP > > I've spoken with the user and he is unaware of these attempts. The times > show that they occur at 2 minute intervals. I suspect that the user was > signed in on a 5250 emulation session with reconnect enabled, changed his > password on another session/terminal, and now the original device keeps > retrying with an old password. > > Is there a way to track down the IP address of these attempts, or even the > workstation id that it is using? I've looked at the job log for > QTVDEVICE. It doesn't seem to give any info that would help me track down > the origin. The sign on server doesn't show any entries in the job log > and I can't seem to hit a decent search pattern on either Midrange.com or > Google. The information you are looking for it in the security audit journal. The reason you are not seeing it is that DSPAUDJRNE does not show it to you. DSPAUDJRNE is old and no longer being enhanced. Perhaps I was wrong to argue against deleting this command a few years ago. People still use it and as a result miss some auditing information. If your system is at V5R4 you should use the new CPYAUDJRNE command instead of DSPAUDJRNE. Once the file has been created use your favorite query to select and print the fields you are interested in. The IP address from where the request originated should be in the header section of each *TYPE5 audit record. If you are on an earlier release you should first use CRTDUPOBJ OBJ(QASYPWJ5) FROMLIB(QSYS) OBJTYPE(*FILE) TOLIB(QTEMP) to create a physical file in QTEMP and then use DSPJRN with OUTFILFMT(*TYPE5) to copy the PW audit records to that file. The remaining steps to display the data will be the same as for V5R4. Ed Fishel, edfishel-r/[email protected] _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400.