LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-29-2009, 01:40 AM   #1
FireRaven
Member
 
Registered: Apr 2006
Location: Australia
Distribution: Debian Squeeze
Posts: 135

Rep: Reputation: 18
Is Logwatch still being used?


Hi,

I'm looking for a program to email me daily info about my server, mostly about bruteforce attacks, and hacker logins, and anything else that could interest an admin.

Logwatch hasn't been updated since 2007, is this what people use for that, or is there anything better?
 
Old 07-29-2009, 02:06 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by FireRaven View Post
Logwatch hasn't been updated since 2007
Where did you get that idea from?

Code:
scripts/logfiles/emerge/applydate               6:#   Revision  1.5   2008/03/24  23:31:26  kirk
scripts/services/denyhosts                      5:#   Revision  1.2   2008/03/24  23:31:26  kirk
scripts/services/kernel                         6:#   Revision  1.35  2008/03/24  23:31:26  kirk
scripts/services/modprobe                       6:#   Revision  1.15  2008/03/24  23:31:26  kirk
scripts/services/pam_unix                       6:#   Revision  1.35  2008/03/24  23:31:26  kirk
scripts/services/php                            5:#   Revision  1.2   2008/03/24  23:31:26  kirk
scripts/services/sendmail                       6:#   Revision  1.97  2008/03/24  23:31:26  kirk
scripts/services/sudo                           5:#   Revision  1.14  2008/03/24  23:31:27  kirk
scripts/services/zz-runtime                     5:#   Revision  1.3   2008/03/24  23:31:27  kirk
scripts/services/samba                          5:#   Revision  1.31  2008/05/06  22:29:58  mike
install_logwatch.sh                             32:#  Revision  1.20  2008/05/12  22:53:28  mike
scripts/services/courier                        6:#   Revision  1.18  2008/06/30  20:47:20  kirk
scripts/services/http                           5:#   Revision  1.40  2008/06/30  20:47:20  kirk
scripts/services/spamassassin                   6:#   Revision  1.2   2008/06/30  20:47:20  kirk
scripts/services/bfd                            5:#   Revision  1.3   2008/06/30  23:07:51  kirk
scripts/services/cisco                          6:#   Revision  1.13  2008/06/30  23:07:51  kirk
scripts/services/evtapplication                 5:#   Revision  1.3   2008/06/30  23:07:51  kirk
scripts/services/evtsecurity                    5:#   Revision  1.3   2008/06/30  23:07:51  kirk
scripts/services/evtsystem                      5:#   Revision  1.3   2008/06/30  23:07:51  kirk
scripts/services/oidentd                        6:#   Revision  1.7   2008/06/30  23:07:51  kirk
scripts/services/pix                            5:#   Revision  1.4   2008/06/30  23:07:51  kirk
scripts/services/proftpd-messages               5:#   Revision  1.27  2008/06/30  23:07:51  kirk
scripts/services/pureftpd                       5:#   Revision  1.12  2008/06/30  23:07:51  kirk
scripts/services/qmail-pop3d                    5:#   Revision  1.3   2008/06/30  23:07:51  kirk
scripts/services/qmail-pop3ds                   5:#   Revision  1.3   2008/06/30  23:07:51  kirk
scripts/services/qmail-send                     5:#   Revision  1.3   2008/06/30  23:07:51  kirk
scripts/services/qmail-smtpd                    5:#   Revision  1.10  2008/06/30  23:07:51  kirk
scripts/services/rt314                          5:#   Revision  1.10  2008/06/30  23:07:51  kirk
scripts/services/saslauthd                      5:#   Revision  1.4   2008/06/30  23:07:51  kirk
scripts/services/scsi                           5:#   Revision  1.5   2008/06/30  23:07:51  kirk
scripts/services/shaperd                        6:#   Revision  1.6   2008/06/30  23:07:51  kirk
scripts/services/slon                           5:#   Revision  1.6   2008/06/30  23:07:51  kirk
scripts/services/sonicwall                      5:#   Revision  1.4   2008/06/30  23:07:51  kirk
scripts/services/windows                        5:#   Revision  1.4   2008/06/30  23:07:51  kirk
scripts/services/xntpd                          6:#   Revision  1.22  2008/06/30  23:07:51  kirk
scripts/services/zz-network                     5:#   Revision  1.6   2008/06/30  23:07:51  kirk
scripts/services/zz-sys                         6:#   Revision  1.3   2008/06/30  23:07:51  kirk
scripts/shared/applyeurodate                    5:#   Revision  1.4   2008/06/30  23:07:51  kirk
scripts/shared/applytaidate                     5:#   Revision  1.3   2008/06/30  23:07:51  kirk
scripts/shared/eventlogonlyservice              5:#   Revision  1.3   2008/06/30  23:07:51  kirk
scripts/shared/eventlogremoveservice            5:#   Revision  1.3   2008/06/30  23:07:51  kirk
scripts/services/postfix                        22:#  Revision  1.41  2008/08/11  15:33:53  mike
scripts/services/fail2ban                       5:#   Revision  1.5   2008/08/18  16:07:46  mike
scripts/services/dpkg                           6:#   Revision  1.6   2008/12/08  15:21:28  mike
scripts/services/clam-update                    5:#   Revision  1.21  2009/02/20  17:15:19  mike
scripts/services/sshd                           5:#   Revision  1.77  2009/02/20  17:49:03  mike
scripts/services/audit                          6:#   Revision  1.15  2009/02/20  17:59:47  mike
scripts/services/amavis                         6:#   Revision  1.56  2009/02/20  18:01:49  mike
scripts/services/cron                           5:#   Revision  1.37  2009/06/02  14:41:09  mike
scripts/services/dovecot                        5:#   Revision  1.17  2009/06/02  14:48:06  mike
scripts/services/exim                           5:#   Revision  1.24  2009/06/02  14:50:37  mike
scripts/services/named                          5:#   Revision  1.58  2009/06/02  14:55:45  mike
scripts/services/secure                         5:#   Revision  1.85  2009/06/02  14:59:58  mike
scripts/services/smartd                         6:#   Revision  1.26  2009/06/02  15:01:34  mike
scripts/services/pluto                          5:#   Revision  1.18  2009/06/05  13:50:26  mike
scripts/services/iptables                       5:#   Revision  1.9   2009/06/05  14:06:07  mike
conf/logfiles/syslog.conf                       5:#   Revision  1.3   2009/06/12  14:16:06  mike

Quote:
Originally Posted by FireRaven View Post
is this what people use for that, or is there anything better?
Define "better"?
 
Old 07-29-2009, 02:17 AM   #3
FireRaven
Member
 
Registered: Apr 2006
Location: Australia
Distribution: Debian Squeeze
Posts: 135

Original Poster
Rep: Reputation: 18
Quote:
Originally Posted by unSpawn View Post
Where did you get that idea from?
Just from their site: http://www.logwatch.org/tabs/download/

Code:
Latest Stable Release (changes)

Download the latest stable release of Logwatch (7.3.6) here: Binary RPM (noarch, 7.3.6, May 19, 2007)   Source RPM (7.3.6, May 19, 2007)

Download the latest stable release of Logwatch (7.3.6) here (source only, not packaged): tar.gz (7.3.6, May 19, 2007)
May 19 2007?
 
Old 07-29-2009, 04:08 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Code:
 rpm -q logwatch --changelog| head -10
* Thu Jan 03 2008 Ivana Varekova <varekova@redhat.com> 7.3-6
- Resolves: #307281
  logwatch HTML output
- Resolves: #249792
  option --usage deleted from the man page
- Resolves: #296001
  Logwatch is unable to handle e.g. postfix 2.3 mail logs
- Resolves: #230974
  add no-oldfiles-log option
So?
 
Old 07-29-2009, 08:09 AM   #5
FireRaven
Member
 
Registered: Apr 2006
Location: Australia
Distribution: Debian Squeeze
Posts: 135

Original Poster
Rep: Reputation: 18
So is that a closed source version?
 
Old 07-29-2009, 08:32 AM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
No the license Logwatch is distributed under is GPL, AFAIK. If you're concerned about "bruteforce attacks, and hacker logins, and anything else" like you say, could you please tell us what distro+release you run, if the machine is hardened and what services you're providing?
 
Old 07-29-2009, 08:36 AM   #7
OlRoy
Member
 
Registered: Dec 2002
Posts: 306

Rep: Reputation: 86
You could use a HIDS, such as OSSEC.
 
Old 07-29-2009, 09:23 AM   #8
FireRaven
Member
 
Registered: Apr 2006
Location: Australia
Distribution: Debian Squeeze
Posts: 135

Original Poster
Rep: Reputation: 18
Quote:
Originally Posted by unSpawn View Post
No the license Logwatch is distributed under is GPL, AFAIK. If you're concerned about "bruteforce attacks, and hacker logins, and anything else" like you say, could you please tell us what distro+release you run, if the machine is hardened and what services you're providing?
Running Ubuntu 9 with SSH, BIND9, VNC, VirtualBox with guest WindowsXP connecting with RDP, Postfix mail server (port 25). No firewall.
Logwatch reports around 150 failed SSH logins per day, can't imagine how many VNC failed attempts I'm getting.
 
Old 07-29-2009, 11:44 AM   #9
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Low-hanging fruit first: Basic sshd hardening

You're going to want to take steps to lock down postfix, bind, and vnc (perhaps at the IP level...). Are you intending for all of these services to be available from anywhere on the 'net?

As for the original question, I regularly review logwatch reports for all my production RHEL servers.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Does logwatch run automatically? How can I reset logwatch? abefroman Linux - Software 4 06-17-2009 02:17 AM
logwatch clpl1980 Fedora 5 12-05-2006 07:31 AM
Logwatch winchester169 Linux - Security 1 10-21-2004 09:18 AM
LogWatch exyst Linux - Software 0 03-13-2004 06:04 PM
logwatch GraemeK Linux - Software 2 12-18-2003 08:32 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:45 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration