由于telnet,FTP等服务都是由xinetd守候进程来管理的,所以我们可以通过查看/var/log/xinetd.log日志文件来查看登录的记录。
例:
suselinux:/var/log # tail xinetd.log
08/5/16@14:16:57: START: telnet from=104.104.104.101
08/5/16@14:29:08: START: telnet from=104.104.104.101
08/5/16@14:29:09: START: telnet from=104.104.104.101
08/5/16@14:30:10: EXIT: telnet status=1 duration=61(sec)
08/5/16@14:30:12: START: telnet from=104.104.104.101
08/5/16@14:30:13: START: ftp from=104.104.104.101
08/5/16@14:30:16: EXIT: ftp status=0 duration=3(sec)
suselinux:/var/log #
OK。