LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 09-01-2008, 08:10 AM   #1
NBA2009
LQ Newbie
 
Registered: Aug 2008
Posts: 4

Rep: Reputation: 0
using snort to detect shutdown, thanks!


I have installed a snort system under linux.

Now i need to write a rule to detect a "shutdown" command which came from remote telnet, also alert and log it.

what i wrote is like this:

alert tcp any any -> 192.168.115.130/24 (content: "shutdown"; msg: "someone shut down!!"


but when i used another computer to telnet my system and send a "shutdown" command, the snort system cannot detect any "shutdown" command using this rule. However, if i change the keyword in content from "shutdown" to "root" and try a "root" command from remote telnet, then the "root" command can be detected. I don't know why.

I really need help about how to write this rule to alert some information if there are attempts to shut down my system using telnet remotely.

Thanks in advance!!
 
Old 09-01-2008, 08:23 AM   #2
Wakil
LQ Newbie
 
Registered: Apr 2008
Distribution: Fedora core 8
Posts: 18

Rep: Reputation: 0
erm, haven't used snort before so i'm blank there except if i won't trouble you could i ask why would you want to log a report of shutting down your system? i mean unles if it is a server and if so you could give that rule to a sys admn only or maybe you've got some memebers who would want to shutdown your system?.
thnx
 
Old 09-01-2008, 08:42 AM   #3
NBA2009
LQ Newbie
 
Registered: Aug 2008
Posts: 4

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by Wakil View Post
erm, haven't used snort before so i'm blank there except if i won't trouble you could i ask why would you want to log a report of shutting down your system? i mean unles if it is a server and if so you could give that rule to a sys admn only or maybe you've got some memebers who would want to shutdown your system?.
thnx
thanks
if someone is not system member and he may connect to the system and send a shutdown command? anyway, i have to write the rule as my group memeber asked me to do this task...
 
Old 09-01-2008, 09:37 AM   #4
arizonagroovejet
Senior Member
 
Registered: Jun 2005
Location: England
Distribution: openSUSE, Fedora, CentOS
Posts: 1,094

Rep: Reputation: 198Reputation: 198
Quote:
Originally Posted by NBA2009 View Post
thanks
if someone is not system member and he may connect to the system and send a shutdown command?
Well I don't know what you mean by 'system member' but by default only root can issue the shutdown command from the command line (i.e. from a telnet session (which they probabyl shouldn't be using anyway for security reasons - use ssh instead)). Since the root password should be closely guarded and only known to systems administrators who actually need it, then you should have no need to worry about logging if someone shutdown the system. If your system is set up so that anyone can issue the shutdown command then that seems rather unwise and you should change the configuration.
 
Old 09-01-2008, 11:27 AM   #5
NBA2009
LQ Newbie
 
Registered: Aug 2008
Posts: 4

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by arizonagroovejet View Post
Well I don't know what you mean by 'system member' but by default only root can issue the shutdown command from the command line (i.e. from a telnet session (which they probabyl shouldn't be using anyway for security reasons - use ssh instead)). Since the root password should be closely guarded and only known to systems administrators who actually need it, then you should have no need to worry about logging if someone shutdown the system. If your system is set up so that anyone can issue the shutdown command then that seems rather unwise and you should change the configuration.


hi, man, that is not important.. my group member asked me to do so then i must do that, no matter it is reasonable or very useful. Thanks
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How can I detect boot and shutdown times from logs? RichardBronosky Linux - General 2 02-26-2007 10:53 PM
Slack 11 : Doesn't detect USB devices & can't shutdown ?? mnemonix Slackware 7 12-17-2006 06:04 AM
How to detect nmap SYN scan w snort jmARC Linux - Security 1 06-09-2005 11:09 AM
using snort to detect possible spammer(s) shengchieh Linux - Security 5 05-17-2005 11:35 PM
howto detect shutdown in progress? gw1500se Mandriva 0 04-25-2004 01:00 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 10:25 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration