LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 10-22-2015, 05:22 PM   #1
jaydul
Member
 
Registered: Sep 2012
Posts: 69

Rep: Reputation: Disabled
Question A keylogger for CentOS 7/6.6


Hello
I need A keylogger for for centOS server.Because it my server sometime system administrator work on my server.but they change password/delete command.I wanna monitor my server and my system admin.what he doing on my server its possible with any keylogger?


Thank you
 
Old 10-22-2015, 05:25 PM   #2
ericson007
Member
 
Registered: Sep 2004
Location: Japan
Distribution: CentOS 7.1
Posts: 735

Rep: Reputation: 154Reputation: 154
I never trie using keyloggers but I think it will create more work to monitor all the output that what it will take to take away administrator rights.

Try configuring sudo on the server and that way they will not be able to make system wide changes.
 
Old 10-22-2015, 07:22 PM   #3
berndbausch
LQ Addict
 
Registered: Nov 2013
Location: Tokyo
Distribution: Mostly Ubuntu and Centos
Posts: 6,316

Rep: Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002
The real question is, how can you give admin access to somebody you don't trust.
 
1 members found this post helpful.
Old 10-22-2015, 07:31 PM   #4
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,362

Rep: Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751
Theoretically there's a tech soln.

Give him a sudo acct and ensure sudoers logging is on, BUT also ensure the logs are immediately fwd'd via rsyslog to a system he does NOT have access to.
Even then I'd worry - he could fool with that setting although you'd have some evidence.
Frankly you need someone you can trust... get a new admin.
 
Old 10-24-2015, 05:04 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by jaydul View Post
I need A keylogger for for centOS server. Because it my server sometime system administrator work on my server.but they change password/delete command. I wanna monitor my server and my system admin. what he doing on my server its possible with any keylogger?
As stated before: if you can not trust an admin to perform requested tasks and nothing else then they should be corrected or not get access in the first place. That said what you're looking for is not a key logger but extending your auditing capabilities. First of all since the user gains root privileges you have to set up a few things before you can start logging:
- ensure you have all-encompassing, current backups (and test restoring those!),
- exfiltrate audit logging using a remote syslog server,
- implement a HIDS (like Samhain due to remote database, logging, use of inotify and continuous monitoring mode),
- a service monitor,
- install rootsh (make it log to syslog obviously), and
- ensure you have a good set of auditd rules.

With that in place, and having hired the services of a reputable sysadm, you have:
- no problem telling the admin he/she's being audited (psyops does work wonders for most),
- an almost-complete remote audit trail, and
- the means to revert any unwarranted changes (provided you possess Out of Band access ;-p).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
keylogger? |2ainman Linux - Security 4 08-21-2013 03:48 AM
lkl Keylogger kirtan Linux - Software 2 12-18-2010 04:51 AM
Keylogger For Linux ????????????????? kirtan Linux - Security 2 12-17-2010 04:31 PM
about keylogger abrenar Linux - Security 3 02-24-2009 03:26 AM
Possible keylogger? StefaX Linux - Security 3 01-27-2009 05:23 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 04:53 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration