LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-18-2001, 12:22 PM   #1
JustinHoMi
Member
 
Registered: Apr 2001
Location: Raleigh, NC
Distribution: CentOS
Posts: 154

Rep: Reputation: 30
good program to scan logs?


Howdy. Is there a good program, or set of programs intended for scanning the logs on my computer to detect possible malicious activity? I'm curious now, b/c I just went through my httpd logs and found a huge number of:

123.456.789.123 - - [22/Sep/2001:07:12:14 -0400] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 310 "-" "-"


I know I'm not vulnerable to this, but I do want to block the ips of anyone with bad intent.

Now I realize there's lots of logs on the machine that I rarely look at. It would be nice to have something to go through them for me.

Any suggestions?

Thanks,
justin
 
Old 10-18-2001, 08:59 PM   #2
paavaka
Member
 
Registered: Jun 2001
Location: Virginia
Distribution: Slackware,Debian,SuSE
Posts: 43

Rep: Reputation: 15
A decent log scanner is LogSentry, by Psionic. It scans my logs every couple of hours and tells me the hostnames/IP addresses of anyone who scanned me, how many attempts there were, etc... it also sends me information about failed login attempts, various processes starting and stopping, stuff like that. I don't know if that is the sort of depth you are looking for... this is on my home system, so it is fine with me. It is just a collection of shell scripts they wrote so you don't have to. Also, their firewall program, PortSentry, works great. It can be used by itself, but works better when you use it as an interface to ipchains or iptables. It makes my life simpler.
 
Old 10-18-2001, 11:36 PM   #3
JustinHoMi
Member
 
Registered: Apr 2001
Location: Raleigh, NC
Distribution: CentOS
Posts: 154

Original Poster
Rep: Reputation: 30
ahh, yes i use port sentry on my server. I'll have to check that out. Thanks a lot.

J
 
Old 10-19-2001, 08:32 AM   #4
Aussie
Senior Member
 
Registered: Sep 2001
Location: Brisvegas, Antipodes
Distribution: Slackware
Posts: 4,590

Rep: Reputation: 58
Chalk up one more vote for PortSentry+iptables and LogCheck.
 
Old 10-21-2001, 01:00 AM   #5
JustinHoMi
Member
 
Registered: Apr 2001
Location: Raleigh, NC
Distribution: CentOS
Posts: 154

Original Poster
Rep: Reputation: 30
What about all the stuff at snort.org? Any experience with that vs. portsentry? They have a lot of programs for scanning and evaluating the logs. Also looks like there's good support on their site, and frequent updates.

Justin
 
Old 10-28-2001, 11:04 AM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Snort gooood, Portsentry baaahhhhd.... :-]

Portsentry only looks for connects on a port, where Snort actually scans for a signature.
This means that if Portsentry is used for adding blocking rules, you could D0S the box by spoofing souce addresses. Snort will actually scan if a signature matches any known malicious traffic. Even then it won't take action itself (it can't), you would need any of the contributed apps like Guardian to add blocking rules.

Earlier this year I found that reason enough to trade in Portsentry for Snort. Another reason is mr Roland doesn't seem to expand/develop Portsentry anymore.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Good Linux Virus Scan !!! chuck77 Linux - General 4 09-02-2008 02:54 AM
How do I send daily clamav scan logs to my work e-mail account rwtreke SUSE / openSUSE 3 05-20-2005 12:05 PM
I need a program to scan windows clients for cracked programs ddaas General 6 04-12-2005 11:35 AM
what program do you use to analyze your logs ? ddaas Linux - General 3 03-06-2005 09:21 AM
Program runs when a user logs in mindstormsguy Linux - Software 2 03-31-2004 05:01 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:00 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration