Determining (failed) client connections
Posted in 2000
Topics: Server Administration, Security, Permissions & Auditing, Platform-Specific Issues, Versions, Editions & End-of-Life
Is there a way of finding out which user is failing his login attempts,
and flooding my message log with that unhelpful "listener-thread: err =
-952: oserr = 0: errstr = : User's password is not correct for thedatabase server" message? Informix's tech support actually taught me
something new here -- onmode -i/onmode -I <msgnr> to "clear the catch"
and trace the user who's generating the message (set TrapError) in the
message log (did you just learn something new here? I didn't find this
documented anywhere. Informix, is there a reason you don't tell us
about the full range of your products' diagnostic and analytical
capabilities? Are you even listening? And when you get around to it,
I'd also like to learn from you the meanings of all the columns of
output from all the variations of the onstat command.). Unfortunately,
since the connection was coming in remotely over the network, I could
only see a "-1" for the session_id.
Can anyone tell me how to further debug this so I can capture the
username and IP address from which the failed connection originated?
I'm using IDS 7.31 on Solaris 2.7/x86 (don't ask).
In article <390987B3.DB114EA6@yahoo.com>,
Red Valsen <red_valsen@yahoo.com> wrote:
> Is there a way of finding out which user is failing his login
attempts,
> and flooding my message log with that unhelpful "listener-thread: err
=
> -952: oserr = 0: errstr = : User's password is not correct for the
> database server" message? ...
> since the connection was coming in remotely over the network, I could
> only see a "-1" for the session_id.
>
> Can anyone tell me how to further debug this so I can capture the
> username and IP address from which the failed connection originated?
>
> I'm using IDS 7.31 on Solaris 2.7/x86 (don't ask).
# man tcpdump
TCPDUMP(8) TCPDUMP(8)
NAME
tcpdump - dump traffic on a network
SYNOPSIS
tcpdump [ -adeflnNOpqStvx ] [ -c count ] [ -F file ]
[ -i interface ] [ -r file ] [ -s snaplen ]
[ -T type ] [ -w file ] [ expression ]
DESCRIPTION
Tcpdump prints out the headers of packets on a network
interface that match the boolean expression.
>
>
Sent via Deja.com http://www.deja.com/
Before you buy.
As far as I've been able to find, tcpdump 1) is not a standard Solaris
utility, and so requires one to download and compile source or find the
binary; 2) requires additional non-trivial manipulation of output, or even
another application, for humanly intelligible interpretation; 3) can only
be run as root. In short, it can't tell me whose login keeps failing and
from what address -- something that Informix should be able to consistently
capture, anyway.
merlindoggie@my-deja.com wrote:
> In article <390987B3.DB114EA6@yahoo.com>,
> Red Valsen <red_valsen@yahoo.com> wrote:
> > Is there a way of finding out which user is failing his login
> attempts,
> > and flooding my message log with that unhelpful "listener-thread: err
> =
> > -952: oserr = 0: errstr = : User's password is not correct for the
> > database server" message? ...>
> > since the connection was coming in remotely over the network, I could
> > only see a "-1" for the session_id.
> >
> > Can anyone tell me how to further debug this so I can capture the
> > username and IP address from which the failed connection originated?
> >
> > I'm using IDS 7.31 on Solaris 2.7/x86 (don't ask).
>
> # man tcpdump
>
> TCPDUMP(8) TCPDUMP(8)
>
> NAME
> tcpdump - dump traffic on a network
>
> SYNOPSIS
> tcpdump [ -adeflnNOpqStvx ] [ -c count ] [ -F file ]
> [ -i interface ] [ -r file ] [ -s snaplen ]
> [ -T type ] [ -w file ] [ expression ]
>
> DESCRIPTION
> Tcpdump prints out the headers of packets on a network
> interface that match the boolean expression.
>
> >
> >
>
> Sent via Deja.com http://www.deja.com/
> Before you buy.
In article <3909FB0A.1B2C4750@yahoo.com>, Red Valsen <red_valsen@yahoo.com> wrote: > As far as I've been able to find, tcpdump 1) is not a standard Solaris > utility, and so requires one to download and compile source or find the > binary; http://ee.lbl.gov/ take the tcpdump link Many other sites also have the sources. >2) requires additional non-trivial manipulation of output, or >even another application, for humanly intelligible interpretation; a few lines of shell script or perl.... >3) can only be run as root. sudo will handle this > In short, it can't tell me whose login keeps failing > and from what address I beg to differ. But it's up to you how you wish to solve this. Sent via Deja.com http://www.deja.com/ Before you buy.
Your "solutions" solve nothing because they all require root access. Tell me something that user informix can do and I'll admit you were helpful. merlindoggie@my-deja.com wrote: > In article <3909FB0A.1B2C4750@yahoo.com>, > Red Valsen <red_valsen@yahoo.com> wrote: > > As far as I've been able to find, tcpdump 1) is not a standard Solaris > > utility, and so requires one to download and compile source or find > the > > binary; > > http://ee.lbl.gov/ take the tcpdump link > Many other sites also have the sources. > > >2) requires additional non-trivial manipulation of output, or > >even another application, for humanly intelligible interpretation; > > a few lines of shell script or perl.... > > >3) can only be run as root. > > sudo will handle this > > > In short, it can't tell me whose login keeps failing > > and from what address > > I beg to differ. But it's up to you how you wish to solve this. > > Sent via Deja.com http://www.deja.com/ > Before you buy.