in reply to /etc/shadow logging
Many systems using shadow passwords also record the date the password was changed (as a Julian date in one of the later fields), if your systems have this you could easily figure out who had their passwords changed on a particular day.
| We're not surrounded, we're in a target-rich environment! |
|---|
|
|---|