LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-28-2009, 10:57 AM   #1
humbletech99
Member
 
Registered: Jun 2005
Posts: 374

Rep: Reputation: 30
Full Command Logging?


I am looking for a really good command logging tool to improve the auditing of my servers. I have previously used snoopy but this is currently a bit flaky and causing serious problems for me, it doesn't look like it's been maintained since 2004, it didn't even want to compile until I added -fPIC but it's causing segmentation faults and just ruins my test systems, eventually causing all or nearly all commands to segfault.

I've tried the process account tools but they log only the command basename, no args and no shell built-ins either (although even snoopy doesn't get that last one, but I could live without it if I had to). Shell history files are not security, they are just convenience, so they don't fit either (unless we find a way of capturing all shell history straight into syslog...)

So I'm looking for something else that I can deploy among my servers to fully audit any commands entered and log them via syslog.

Does anyone have any recommendations for a good thorough command logger, capturing args as well?
 
Old 01-29-2009, 03:07 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by humbletech99 View Post
Shell history files are not security, they are just convenience, so they don't fit either (unless we find a way of capturing all shell history straight into syslog...)
Check out 'rootsh' I'd say. It transparently wraps around shells and can dump to syslog NP. Depending on you requirements for cross-referencing it I'd combine it with either in-kernel logging facilities like GRSecurity or TOMOYO offer (or Auditd) plus make syslog dump to a separate syslog server.

Last edited by unSpawn; 01-29-2009 at 03:08 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ssh command logging jcookeman Linux - Security 3 08-26-2008 02:50 AM
full system logging (and I mean everyting!) gacott Linux - General 3 05-10-2007 04:00 AM
command logging esdeedee Linux - Security 2 05-24-2006 12:29 PM
Do you enable full sendmail logging? hbt Linux - Software 1 12-19-2004 03:06 PM
get full path of a command (in C) Hady Linux - Software 1 11-19-2003 05:46 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration