EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesHard

A blue team analyst is investigating a suspected breach and discovers that an attacker has modified the system's `utmp`, `wtmp`, and `btmp` files on a Linux server. What is the primary purpose of modifying these specific files?

  1. ATo install a rootkit.
  2. BTo change system time settings.
  3. CTo delete user accounts.
  4. DTo hide login and logout records.
Show answer & explanation

Correct answer: D. To hide login and logout records.

The `utmp`, `wtmp`, and `btmp` files on Linux systems store records of user logins, logouts, and failed login attempts. Modifying or clearing these files is a common technique used by attackers during the 'clearing tracks' phase to remove evidence of their presence and activities on the compromised system.

Why the other options are wrong

  • A. Rootkits hide processes and files, but modifying these specific files is about hiding *login records*.
  • B. System time settings are typically controlled by `timedatectl` or `ntp` configurations, not these files.
  • C. Deleting user accounts is a separate action, not directly related to these files.

Clearing Logs (Linux)

The process of removing or altering log entries on a Linux system to erase forensic evidence of an attacker's activities, making it harder to detect and trace the intrusion.

  • Targets system logs (e.g., `auth.log`, `syslog`).
  • Targets login records (`utmp`, `wtmp`, `btmp`).
  • Can involve using tools like `logrotate` or direct file manipulation.

Memory trick: To 'erase' your 'footprints', clean up the 'login records'.

More System Hacking Phases and Attack Techniques questions