LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-21-2003, 07:32 AM   #1
mibsun
LQ Newbie
 
Registered: Jul 2003
Posts: 4

Rep: Reputation: 0
Security Logging


Hi ,
I have recently inherited a LINUX Network without any documentation anything at all . I would like your advise on :
1) How can I collect and check logs to see If someone was trying to break in .

Any Ideas Appreciated .
Regards
John Jacks
 
Old 07-21-2003, 07:42 AM   #2
jharris
Senior Member
 
Registered: May 2001
Location: Bristol, UK
Distribution: Slackware, Fedora, RHES
Posts: 2,243

Rep: Reputation: 47
It sounds to me like you want to configure syslog on all your boxes to send all its messgaes to a loghost. That way anything sent through syslog will get log to the single box where you can carry out your checks. Have a look at man syslog.conf at it has some pretty good examples. You might also want to look at the various howto's available on http://www.tldp.org

HTH and welcome to LQ!

Jamie...
 
Old 07-22-2003, 04:35 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Jharris' advice will be an excellent way to improve your current logging situation.

a LINUX Network without any documentation

There is a problem you will need to address and that is the current unknown/untrusted state the boxen are in. If you're speaking about break in attempts in the past tense: the attempts itself aren't interesting, but those that succeeded are. If some did, then I would advise caution: chances are you probably won't find much info about them in the logs. Start logging all in/outbound traffic, determine the most crucial boxen, backup, change all passes and start your audit.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Logging Thoughts Matir Linux - Security 12 09-18-2005 08:47 AM
[Security Questions] Last Login, how good is this feature for security breach info? t3gah Linux - Security 2 06-14-2005 01:02 AM
logging failed access to security objects tbeaton Linux - Security 1 06-24-2004 05:05 PM
using red-carpet without logging out and logging as root. packman Linux - Software 1 12-09-2002 02:55 AM
Samba logging & security aimstr8 Linux - General 0 05-30-2001 02:45 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration