LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-02-2014, 04:04 PM   #1
bugatti
LQ Newbie
 
Registered: Apr 2014
Posts: 4

Rep: Reputation: Disabled
How to log the activities of scripts from Windows to Linux server?


I found my CentOS server has been accessed by a Windows desktop daily and caused files have been locked frequently.
Is there any way to log the port(s) that the scrips or programs use to access my server for me to analyze?
 
Old 04-02-2014, 05:25 PM   #2
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Code:
grep -i <keyword> /var/log/* -R | less
IF they access it daily, it's written daily in /var/log somwhere.
 
Old 04-02-2014, 05:59 PM   #3
bugatti
LQ Newbie
 
Registered: Apr 2014
Posts: 4

Original Poster
Rep: Reputation: Disabled
Dear Habitual.

Than you. I got the suspicious log below, how do i block/drop it when it accesses the server?

/var/log/audit/audit.log:type=USER_ROLE_CHANGE msg=audit(1396394239.662:18770): user pid=20125 uid=0 auid=538 subj=system_u:sys
em_r:remote_login_t:s0-s0:c0.c1023 msg='pam: default-context=user_u:system_r:unconfined_t:s0 selected-context=user_u:system_r:u
confined_t:s0: exe="/bin/login" (hostname=?, addr=?, terminal=pts/2 res=success)'

/var/log/audit/audit.log:type=USER_START msg=audit(1396394239.663:18771): user pid=20125 uid=0 auid=538 subj=system_u:system_r:
emote_login_t:s0-s0:c0.c1023 msg='PAM: session open acct="xuser" : exe="/bin/login" (hostname=192.168.1.140, addr=192.168.1.140, te
minal=pts/2 res=success)'
/var/log/audit/audit.log:type=CCA msg=audit(1396394239.663:18772): user pid=20125 uid=0 auid=538 subj=system_u:system_r:re
ote_login_t:s0-s0:c0.c1023 msg='PAM: setcred acct="xuser" : exe="/bin/login" (hostname=192.168.1.140, addr=192.168.1.140, terminal=
ts/2 res=success)'
/var/log/audit/audit.log:type=CCD msg=audit(1396394704.169:18796): user pid=20125 uid=0 auid=538 subj=system_u:system_r:r
 
Old 04-03-2014, 07:20 AM   #4
Skatman88
Member
 
Registered: Mar 2014
Posts: 65

Rep: Reputation: Disabled
Quote:
Originally Posted by bugatti View Post
I found my CentOS server has been accessed by a Windows desktop daily and caused files have been locked frequently.
Is there any way to log the port(s) that the scrips or programs use to access my server for me to analyze?
You could download yourself and AESA application. ArcSight do a free version, although if it's compatible with Linux I have no idea. Couldn't see any reason why not though. You just have to configure it yourself and it'll tell you anything from any event log. When someone logged on, if they accessed files they're not supposed to if they entered a password in the username box (password in cleartext across the network). Really good bits of kit.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: How to record terminal activities and outputs to a log file LXer Syndicated Linux News 0 06-26-2012 12:11 AM
Samba Log all user activities simplyA Linux - Server 6 02-04-2011 04:02 AM
Can,t log into samba on linux; windows 2k, xp, vista can not log in to smb; admir330 Linux - General 1 12-23-2008 08:31 PM
Squid - Track Users Activities - 1 Month Log grant-skywalker Linux - Server 1 11-30-2006 11:51 AM
how to watch linux client machine desktop(activities) from windows machine deepak rawat Linux - Networking 7 07-03-2006 04:59 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:59 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration