Solaris 9, with Solaris Auditing enabled and certain patches for sshd installed, can generate audit records with an audit-ID of 0 even when the user logging into ssh is not root, which makes it easier for attackers to avoid detection and can make it more difficult to conduct forensics activities.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Solaris | Sun | 9 (including) | 9 (including) |