1. RSH does NOT log remote activity

2. TCP wrappers would be the way to go. I am not good with tcp wrappers
so I may research it. I was more looking for a "Switch" that could be
toggle to log rsh activity.

3. One suggested that the who and last would give that information, I have
found out that is not so.

Below are the responses;

After rsh'ing to a remote machine, the command
"who" (run on the remote machine) will show your
id as well. In this case "last" will also show
the time your rsh'd (again run "last" on the
remote machine).

BTW, this info. is stored in /var/adm/utmp(x)
files. Check if these files are emptied on the
remote machine. If they are empty, then last
does not give any output.



Only interactive logins are entered in utmp/utmpx

Command logging through 'acct' or using auditing are your next options.


Not by Default. If you put the Servers behind TCP Wrappers, however,
you can have Logs detailing the Connections made, logged with ori-
ginating Host and possibly the Result of an identd Request thereto;
No Way that I'm aware of to log the Username actually used on the
local Side, though.


You would probably have to install TCP wrappers to log rsh activity.

I don't know about rsh, but ssh (secure shell) logs all this stuff any
time a connection is made from another host. Not in wtmpx, but via
syslog. rsh might be able to do the same thing, haven't checked.


     Get tcp wrappers and wrap rsh. or run inetd with a -ts flag.


