Re: Logcheck Keyword Files

2004-06-08 Thread Ronny Adsetts
Mark Bucciarelli said at 08/06/04 17:24: I'm thinking about using the logcheck [1] program for intrusion detection, and was wondering if anyone here uses it. If so, have you modified the keyword filter files? I'd advise creating a 'local' definition in /etc/logcheck/ignore.d/ and friends rather

Re: Logcheck Keyword Files

2004-06-08 Thread Mark Bucciarelli
On Tuesday 08 June 2004 12:31, Steve Kemp wrote: > On Tue, Jun 08, 2004 at 12:24:26PM -0400, Mark Bucciarelli wrote: > > I like logcheck because it is simple. But it's not packaged for > > Debian, so maybe no-one here uses it. If not, what tool do you > > recommend for intrusion detection? > >

Re: Logcheck Keyword Files

2004-06-08 Thread Steve Kemp
On Tue, Jun 08, 2004 at 12:24:26PM -0400, Mark Bucciarelli wrote: > I like logcheck because it is simple. But it's not packaged for Debian, so > maybe no-one here uses it. If not, what tool do you recommend for > intrusion detection? Logcheck is a good tool, and can be modified easily. I

Re: Logcheck Keyword Files

2004-06-08 Thread Ronny Adsetts
Mark Bucciarelli said at 08/06/04 17:24: I'm thinking about using the logcheck [1] program for intrusion detection, and was wondering if anyone here uses it. If so, have you modified the keyword filter files? I'd advise creating a 'local' definition in /etc/logcheck/ignore.d/ and friends rather

Re: Logcheck Keyword Files

2004-06-08 Thread Mark Bucciarelli
On Tuesday 08 June 2004 12:31, Steve Kemp wrote: > On Tue, Jun 08, 2004 at 12:24:26PM -0400, Mark Bucciarelli wrote: > > I like logcheck because it is simple. But it's not packaged for > > Debian, so maybe no-one here uses it. If not, what tool do you > > recommend for intrusion detection? > >

Re: Logcheck Keyword Files

2004-06-08 Thread Steve Kemp
On Tue, Jun 08, 2004 at 12:24:26PM -0400, Mark Bucciarelli wrote: > I like logcheck because it is simple. But it's not packaged for Debian, so > maybe no-one here uses it. If not, what tool do you recommend for > intrusion detection? Logcheck is a good tool, and can be modified easily. I

Re: Logcheck Question

2002-06-24 Thread axacheng
Hello Nate : Thank You Very Very Very Very Very Much. ;-) -- Trust & Unique ... Axacheng's PGP Public Key http://www.navigation.idv.tw/pgpkey -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Logcheck Question

2002-06-24 Thread axacheng
Hello Nate : Thank You Very Very Very Very Very Much. ;-) -- Trust & Unique ... Axacheng's PGP Public Key http://www.navigation.idv.tw/pgpkey -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: logcheck

2000-09-22 Thread Martin WHEELER
On Thu, 21 Sep 2000 [EMAIL PROTECTED] wrote: > Also, would something be running from cron that does this every morning at > 6:23 AM? Apache? > Anyone know how I can investigate furthur? see: /etc/cron.daily/ (to see what's being run) /etc/crontab (to see when it's being run

Re: logcheck

2000-09-22 Thread Martin WHEELER
On Thu, 21 Sep 2000 [EMAIL PROTECTED] wrote: > Also, would something be running from cron that does this every morning at > 6:23 AM? Apache? > Anyone know how I can investigate furthur? see: /etc/cron.daily/ (to see what's being run) /etc/crontab (to see when it's being ru

Re: logcheck

2000-09-21 Thread brian moore
On Thu, Sep 21, 2000 at 06:09:48PM -0500, [EMAIL PROTECTED] wrote: > Hey Russel and Group, > Thanks for the continuing discussion. > > > Nobody suing to root is not non-threatening! Ideally you would have a > > group > > wheel or root required for su to root to prevent this. Currently I haven'

Re: logcheck

2000-09-21 Thread Gerard MacNeil
On Thu, 21 Sep 2000, [EMAIL PROTECTED] wrote: > Hey Russel and Group, > Thanks for the continuing discussion. > > > Nobody suing to root is not non-threatening! Ideally you would have a > > group wheel or root required for su to root to prevent this. Currently I > > haven't as I haven't got the P

Re: logcheck

2000-09-21 Thread debian-isp
Hey Russel and Group, Thanks for the continuing discussion. > Nobody suing to root is not non-threatening! Ideally you would have a group > wheel or root required for su to root to prevent this. Currently I haven't > as > I haven't got the PAM setup for it going yet. PAM is acronym for 'pass

Re: logcheck

2000-09-21 Thread brian moore
On Thu, Sep 21, 2000 at 06:09:48PM -0500, [EMAIL PROTECTED] wrote: > Hey Russel and Group, > Thanks for the continuing discussion. > > > Nobody suing to root is not non-threatening! Ideally you would have a group > > wheel or root required for su to root to prevent this. Currently I haven't as

Re: logcheck

2000-09-21 Thread Gerard MacNeil
On Thu, 21 Sep 2000, [EMAIL PROTECTED] wrote: > Hey Russel and Group, > Thanks for the continuing discussion. > > > Nobody suing to root is not non-threatening! Ideally you would have a > > group wheel or root required for su to root to prevent this. Currently I > > haven't as I haven't got the

Re: logcheck

2000-09-21 Thread debian-isp
Hey Russel and Group, Thanks for the continuing discussion. > Nobody suing to root is not non-threatening! Ideally you would have a group > wheel or root required for su to root to prevent this. Currently I haven't as > I haven't got the PAM setup for it going yet. PAM is acronym for 'passwo

Re: logcheck

2000-09-20 Thread Russell Coker
On Wed, 20 Sep 2000, Art Sackett wrote: >On Tue, Sep 19, 2000 at 06:03:48PM -0500, [EMAIL PROTECTED] wrote: >> Hey Guys, >> Do any of you know what may have caused this message in my syslogs? >> >> Unusual System Events >> =-=-=-=-=-=-=-=-=-=-= >> Sep 19 06:25:02 ghost su[322]: + ??? root-nobody >>

Re: logcheck

2000-09-20 Thread Russell Coker
On Wed, 20 Sep 2000, Art Sackett wrote: >On Tue, Sep 19, 2000 at 06:03:48PM -0500, [EMAIL PROTECTED] wrote: >> Hey Guys, >> Do any of you know what may have caused this message in my syslogs? >> >> Unusual System Events >> =-=-=-=-=-=-=-=-=-=-= >> Sep 19 06:25:02 ghost su[322]: + ??? root-nobody >

Re: logcheck

2000-09-19 Thread Art Sackett
On Tue, Sep 19, 2000 at 06:03:48PM -0500, [EMAIL PROTECTED] wrote: > Hey Guys, > Do any of you know what may have caused this message in my syslogs? > > Unusual System Events > =-=-=-=-=-=-=-=-=-=-= > Sep 19 06:25:02 ghost su[322]: + ??? root-nobody > Sep 19 06:25:02 ghost PAM_unix[322]: (su) ses

Re: logcheck

2000-09-19 Thread Art Sackett
On Tue, Sep 19, 2000 at 06:03:48PM -0500, [EMAIL PROTECTED] wrote: > Hey Guys, > Do any of you know what may have caused this message in my syslogs? > > Unusual System Events > =-=-=-=-=-=-=-=-=-=-= > Sep 19 06:25:02 ghost su[322]: + ??? root-nobody > Sep 19 06:25:02 ghost PAM_unix[322]: (su) se