Re: Logcheck Keyword Files

2004-06-08 Thread Ronny Adsetts
Mark Bucciarelli said at 08/06/04 17:24: I'm thinking about using the logcheck [1] program for intrusion detection, and was wondering if anyone here uses it. If so, have you modified the keyword filter files? I'd advise creating a 'local' definition in /etc/logcheck/ig

Re: Logcheck Keyword Files

2004-06-08 Thread Mark Bucciarelli
On Tuesday 08 June 2004 12:31, Steve Kemp wrote: > On Tue, Jun 08, 2004 at 12:24:26PM -0400, Mark Bucciarelli wrote: > > I like logcheck because it is simple. But it's not packaged for > > Debian, so maybe no-one here uses it. If not, what tool do you > > recomme

Re: Logcheck Keyword Files

2004-06-08 Thread Steve Kemp
On Tue, Jun 08, 2004 at 12:24:26PM -0400, Mark Bucciarelli wrote: > I like logcheck because it is simple. But it's not packaged for Debian, so > maybe no-one here uses it. If not, what tool do you recommend for > intrusion detection? Logcheck is a good tool, and can be m

Logcheck Keyword Files

2004-06-08 Thread Mark Bucciarelli
I'm thinking about using the logcheck [1] program for intrusion detection, and was wondering if anyone here uses it. If so, have you modified the keyword filter files? I like logcheck because it is simple. But it's not packaged for Debian, so maybe no-one here uses it. If not, wh

Re: Logcheck Keyword Files

2004-06-08 Thread Ronny Adsetts
Mark Bucciarelli said at 08/06/04 17:24: I'm thinking about using the logcheck [1] program for intrusion detection, and was wondering if anyone here uses it. If so, have you modified the keyword filter files? I'd advise creating a 'local' definition in /etc/logcheck/ig

Re: Logcheck Keyword Files

2004-06-08 Thread Mark Bucciarelli
On Tuesday 08 June 2004 12:31, Steve Kemp wrote: > On Tue, Jun 08, 2004 at 12:24:26PM -0400, Mark Bucciarelli wrote: > > I like logcheck because it is simple. But it's not packaged for > > Debian, so maybe no-one here uses it. If not, what tool do you > > recomme

Re: Logcheck Keyword Files

2004-06-08 Thread Steve Kemp
On Tue, Jun 08, 2004 at 12:24:26PM -0400, Mark Bucciarelli wrote: > I like logcheck because it is simple. But it's not packaged for Debian, so > maybe no-one here uses it. If not, what tool do you recommend for > intrusion detection? Logcheck is a good tool, and can be m

Logcheck Keyword Files

2004-06-08 Thread Mark Bucciarelli
I'm thinking about using the logcheck [1] program for intrusion detection, and was wondering if anyone here uses it. If so, have you modified the keyword filter files? I like logcheck because it is simple. But it's not packaged for Debian, so maybe no-one here uses it. If not, wh

LogCheck style log analysis for NT/2000

2003-02-28 Thread Gene Grimm
We have one Win2000 box and one WinNT 4 box left with the remainder of our servers running Debian. Does anyone know if there is any sort of log analysis routine similar to LogCheck for WinNT and 2000 so I can keep apprised of problems and attempted hacks on the Windoze boxes?

LogCheck style log analysis for NT/2000

2003-02-28 Thread Gene Grimm
We have one Win2000 box and one WinNT 4 box left with the remainder of our servers running Debian. Does anyone know if there is any sort of log analysis routine similar to LogCheck for WinNT and 2000 so I can keep apprised of problems and attempted hacks on the Windoze boxes? -- To UNSUBSCRIBE

Re: Logcheck Question

2002-06-24 Thread axacheng
Hello Nate : Thank You Very Very Very Very Very Much. ;-) -- Trust & Unique ... Axacheng's PGP Public Key http://www.navigation.idv.tw/pgpkey -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Logcheck Question

2002-06-24 Thread axacheng
Hello Nate : Thank You Very Very Very Very Very Much. ;-) -- Trust & Unique ... Axacheng's PGP Public Key http://www.navigation.idv.tw/pgpkey -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Logcheck Question

2002-06-23 Thread axacheng
Hello List : I got some log report by logcheck, when i was installed MRTG into my site. Jun 24 10:30:01 axanet ucd-snmp[378]: Connection from 61.221.73.226 Jun 24 10:35:02 axanet ucd-snmp[378]: Connection from 61.221.73.226 Jun 24 10:35:02 axanet ucd-snmp[378]: Connection from

Logcheck Question

2002-06-23 Thread axacheng
Hello List : I got some log report by logcheck, when i was installed MRTG into my site. Jun 24 10:30:01 axanet ucd-snmp[378]: Connection from 61.221.73.226 Jun 24 10:35:02 axanet ucd-snmp[378]: Connection from 61.221.73.226 Jun 24 10:35:02 axanet ucd-snmp[378]: Connection from

Re: logcheck

2000-09-22 Thread Martin WHEELER
On Thu, 21 Sep 2000 [EMAIL PROTECTED] wrote: > Also, would something be running from cron that does this every morning at > 6:23 AM? Apache? > Anyone know how I can investigate furthur? see: /etc/cron.daily/ (to see what's being run) /etc/crontab (to see when it's being run

Re: logcheck

2000-09-22 Thread Martin WHEELER
On Thu, 21 Sep 2000 [EMAIL PROTECTED] wrote: > Also, would something be running from cron that does this every morning at > 6:23 AM? Apache? > Anyone know how I can investigate furthur? see: /etc/cron.daily/ (to see what's being run) /etc/crontab (to see when it's being ru

Re: logcheck

2000-09-21 Thread brian moore
On Thu, Sep 21, 2000 at 06:09:48PM -0500, [EMAIL PROTECTED] wrote: > Hey Russel and Group, > Thanks for the continuing discussion. > > > Nobody suing to root is not non-threatening! Ideally you would have a > > group > > wheel or root required for su to root to prevent this. Currently I haven'

Re: logcheck

2000-09-21 Thread Gerard MacNeil
On Thu, 21 Sep 2000, [EMAIL PROTECTED] wrote: > Hey Russel and Group, > Thanks for the continuing discussion. > > > Nobody suing to root is not non-threatening! Ideally you would have a > > group wheel or root required for su to root to prevent this. Currently I > > haven't as I haven't got the P

Re: logcheck

2000-09-21 Thread debian-isp
Hey Russel and Group, Thanks for the continuing discussion. > Nobody suing to root is not non-threatening! Ideally you would have a group > wheel or root required for su to root to prevent this. Currently I haven't > as > I haven't got the PAM setup for it going yet. PAM is acronym for 'pass

Re: logcheck

2000-09-21 Thread brian moore
On Thu, Sep 21, 2000 at 06:09:48PM -0500, [EMAIL PROTECTED] wrote: > Hey Russel and Group, > Thanks for the continuing discussion. > > > Nobody suing to root is not non-threatening! Ideally you would have a group > > wheel or root required for su to root to prevent this. Currently I haven't as

Re: logcheck

2000-09-21 Thread Gerard MacNeil
On Thu, 21 Sep 2000, [EMAIL PROTECTED] wrote: > Hey Russel and Group, > Thanks for the continuing discussion. > > > Nobody suing to root is not non-threatening! Ideally you would have a > > group wheel or root required for su to root to prevent this. Currently I > > haven't as I haven't got the

Re: logcheck

2000-09-21 Thread debian-isp
Hey Russel and Group, Thanks for the continuing discussion. > Nobody suing to root is not non-threatening! Ideally you would have a group > wheel or root required for su to root to prevent this. Currently I haven't as > I haven't got the PAM setup for it going yet. PAM is acronym for 'passwo

Re: logcheck

2000-09-20 Thread Russell Coker
On Wed, 20 Sep 2000, Art Sackett wrote: >On Tue, Sep 19, 2000 at 06:03:48PM -0500, [EMAIL PROTECTED] wrote: >> Hey Guys, >> Do any of you know what may have caused this message in my syslogs? >> >> Unusual System Events >> =-=-=-=-=-=-=-=-=-=-= >> Sep 19 06:25:02 ghost su[322]: + ??? root-nobody >>

Re: logcheck

2000-09-20 Thread Russell Coker
On Wed, 20 Sep 2000, Art Sackett wrote: >On Tue, Sep 19, 2000 at 06:03:48PM -0500, [EMAIL PROTECTED] wrote: >> Hey Guys, >> Do any of you know what may have caused this message in my syslogs? >> >> Unusual System Events >> =-=-=-=-=-=-=-=-=-=-= >> Sep 19 06:25:02 ghost su[322]: + ??? root-nobody >

Re: logcheck

2000-09-19 Thread Art Sackett
On Tue, Sep 19, 2000 at 06:03:48PM -0500, [EMAIL PROTECTED] wrote: > Hey Guys, > Do any of you know what may have caused this message in my syslogs? > > Unusual System Events > =-=-=-=-=-=-=-=-=-=-= > Sep 19 06:25:02 ghost su[322]: + ??? root-nobody > Sep 19 06:25:02 ghost PAM_unix[322]: (su) ses

logcheck

2000-09-19 Thread debian-isp
Hey Guys, Do any of you know what may have caused this message in my syslogs? Unusual System Events =-=-=-=-=-=-=-=-=-=-= Sep 19 06:25:02 ghost su[322]: + ??? root-nobody Sep 19 06:25:02 ghost PAM_unix[322]: (su) session opened for user nobody by (uid=0) I am unsure of what the ??? represents a

Re: logcheck

2000-09-19 Thread Art Sackett
On Tue, Sep 19, 2000 at 06:03:48PM -0500, [EMAIL PROTECTED] wrote: > Hey Guys, > Do any of you know what may have caused this message in my syslogs? > > Unusual System Events > =-=-=-=-=-=-=-=-=-=-= > Sep 19 06:25:02 ghost su[322]: + ??? root-nobody > Sep 19 06:25:02 ghost PAM_unix[322]: (su) se

logcheck

2000-09-19 Thread debian-isp
Hey Guys, Do any of you know what may have caused this message in my syslogs? Unusual System Events =-=-=-=-=-=-=-=-=-=-= Sep 19 06:25:02 ghost su[322]: + ??? root-nobody Sep 19 06:25:02 ghost PAM_unix[322]: (su) session opened for user nobody by (uid=0) I am unsure of what the ??? represents