LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-14-2001, 10:13 PM   #1
buttnutt
Member
 
Registered: Dec 2001
Location: Dallas, TX
Distribution: Slackware
Posts: 46

Rep: Reputation: 15
Logs


I have set up my Linux box as a router and firewall. I would like to know what logs to look at to see if I am being attacked. Does anyone have any good monitoring tips, logs to check, things to be aware of, etc.

Thanks.
 
Old 12-15-2001, 05:26 AM   #2
bluecadet
Member
 
Registered: Oct 2001
Distribution: MD81 RH71
Posts: 555

Rep: Reputation: 30
it's always fun checking the /var/log/httpd/error_log if yuo've got apache running, all those IIS Code Red / Blue attacks pile up faster than you can count them!

if you've a mail server, look at all the failed spam in /var/log/maillog

just make sure that whatever services you have are as local as possible, samba on internal ip's only etc... i was got a number of times when people got into my smb shares cos i didin't know what i was doing
 
Old 12-15-2001, 12:55 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Logging firewall messages depends on how you set up syslogd (/etc/syslog.conf) it uses the KERN facility, but you can direct the messages by level to a different log.

Not because I'm lazy, but I'd like you to read the threads in this forum concerning firewalling, breakins and setups. By now I think we've got some good leads in almost every thread on how to extend your detection and logging capabilities.
If after reading you've don't see the pattern, or got more specific questions, just ask, ok :-]

Start here:
http://www.linuxquestions.org/questi...?threadid=8417
http://www.linuxquestions.org/questi...threadid=10131
http://www.linuxquestions.org/questi...?threadid=9928
http://www.linuxquestions.org/questi...?threadid=9760
http://www.linuxquestions.org/questi...?threadid=8694
http://www.linuxquestions.org/questi...?threadid=7812
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Ubuntu logs on, then logs back off generallee5686 Ubuntu 0 10-20-2005 01:11 PM
Firewall logs in logs and terminal... robbow52 Debian 7 11-20-2004 07:13 PM
Firefox logs user out? Where are error logs? case1984 Linux - General 0 10-09-2004 02:22 PM
Separate firewall logs and general logs dominant Linux - General 3 04-20-2004 01:26 AM
Apache logs - ???Linux logs??? mylo2003 Linux - General 3 08-07-2003 04:49 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:53 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration