Hi All,
this is just a heads-up notice.
Recently, I have been stalked by a user at ovh.net . They seem to be well-financed and persistent.
I was surprised to find that, by default, the log file /var/log/sulog is disabled Debian 5.0 and Debian 7.
This behaviour is dis/activated in /etc/login.defs
su log files are handy to check for intruders, and I am surprised that Debian (and possibly others) have not seen fit to enable a default /var/log/sulog
Of course, most of you already know this, but this note was designed in case one of you was heretofore unaware.
Cheers