I got a warning from ISPConfig just before that the /etc/group file has changed. I compared the new version to a backup and found that the root user has been added to client0:x:5005,www-data. I would like to see how this occured but don't know which log file to look in. Any advice on what I should do? Cheers, Nap
Thats strange. I dont think that the linux commandline user tools write a log for the changes. But you can take a look into the sys_datalog table of the dbispconfig database too see if there is any corresponding activity to this in there.
I had a look at the table but nothing there to do with this. The timing of the warning coincides with settings I made in ISPConfig whereby I put in custom php.ini setting and apache directives. But that was not for client0.