举个例子,看了就明白了。
[root@rhel5 ~]# whoami
root
[root@rhel5 ~]# w
16:53:34 up 8 min, 2 users, load average: 0.00, 0.00, 0.00
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
kxn pts/0 console 16:50 3:07 0.02s 0.02s -bash
kxn pts/1 console 16:50 0.00s 0.07s 0.02s sshd: kxn [priv
[root@rhel5 ~]#
root登陆后,发现有普通用户kxn登陆到本机。 tty为pts/0
查看kxn用户的登陆位置和进程
[root@rhel5 ~]# ps -ef | grep -v grep |grep pts/0
kxn 2236 2234 0 16:50 ? 00:00:00 sshd: kxn@pts/0
kxn 2237 2236 0 16:50 pts/0 00:00:00 -bash
kxn 2343 2237 0 16:57 pts/0 00:00:00 sleep 300
[root@rhel5 ~]#
杀掉他的ssh登陆进程
[root@rhel5 ~]# kill -9 2236
[root@rhel5 ~]# w
17:01:16 up 16 min, 1 user, load average: 0.00, 0.00, 0.00
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
kxn pts/1 console 16:50 0.00s 0.09s 0.02s sshd: kxn [priv
[root@rhel5 ~]#
用户被强制退出系统。
转载于:https://blog.51cto.com/centos5/851220