Re: Detailed logging of ssh sessions

From: - (user_at_celeritystorm.com)
Date: 06/21/05

  • Next message: -: "Re: Unable to decipher error "ELF binary type 3 not known""
    Date: Tue, 21 Jun 2005 15:03:29 +0100
    To: freebsd-questions@freebsd.org
    
    

    Try the termlog port, do some minor source changes so it doesn't spam
    the system logs. I use it to monitor shell server users, and works
    wonders. Even have a shell script that creates directories according to
    the current date, checks for "operation not permitted" and "permission
    denied", mails the results to me, and archives the logs in the folder
    (ie 21-06-2005). The only problem with this is a cat /dev/urandom can
    fill a partition up, because all output is logged :)

    I keep these logs in a separate partition.

    Glenn Dawson wrote:

    > At 08:38 AM 6/19/2005, Bill Moran wrote:
    >
    >> I've been researching this, and so far haven't found a way to do what I
    >> want to do.
    >>
    >> I have servers here and there, that should only be accessible by a
    >> limited
    >> number of administrators via ssh (i.e. mail and web servers, firewalls).
    >>
    >> As an added security measure, I'd like to start logging everything that
    >> happens during any ssh login (since all our work on these machines is
    >> via ssh). I understand, and frequently use script(1), but I want this
    >> to be required. I have two goals:
    >> 1) If someone manages to guess a password and break in, I want a log
    >> of what they're doing.
    >> 2) I want 100% guarantee that everything we do is recorded, to make
    >> future debugging of configuration mistakes easier.
    >>
    >> I've been researching sshd, and it doesn't seem as if it has this
    >> capability. Web searches have not yet turned up anything ... I'm
    >> guessing
    >> I'm not searching for the right phrases, since I can't believe I'm the
    >> only one doing this.
    >>
    >> Any advice or pointers are welcome.
    >
    >
    > This looks like it might do the trick for you:
    > http://honeypots.sourceforge.net/modified_script.html
    >
    > -Glenn
    >
    >
    >> --
    >> Bill Moran
    >> Potential Technologies
    >> http://www.potentialtech.com
    >> _______________________________________________
    >> freebsd-questions@freebsd.org mailing list
    >> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    >> To unsubscribe, send any mail to
    >> "freebsd-questions-unsubscribe@freebsd.org"
    >
    >
    > _______________________________________________
    > freebsd-questions@freebsd.org mailing list
    > http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    > To unsubscribe, send any mail to
    > "freebsd-questions-unsubscribe@freebsd.org"
    >

    _______________________________________________
    freebsd-questions@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"


  • Next message: -: "Re: Unable to decipher error "ELF binary type 3 not known""

    Relevant Pages

    • Re: Bad news about Tor
      ... A "privacy service" would be ideal. ... Attack truly anonymous methods like Tor even though it ... keeps logs and lies about it, but got caught using them to track people ... Servers in the US are a lot safer that servers in most other places, ...
      (alt.privacy)
    • Re: system container in SMS 2003
      ... These logs don't show any AD publishing activity. ... "Publish servers in Active Directory" and subsequent log entries for ... >>> Then I went through and found the system management folder and didn't ...
      (microsoft.public.sms.setup)
    • RE: Event log counts...
      ... logs on 47 web servers and all logs on 6 domain controllers and we are ... Subject: Event log counts... ...
      (Security-Basics)
    • Re: OT: Indexing and searching logs
      ... This is more for application logs, app servers, webservers & mail servers etc. ... ...the Sin of Stupidity. ...
      (Fedora)
    • Re: 1058 and 1030 errors revisited
      ... from what I can see when I look at the event logs on all ... minutes on that client. ... I watched the Network Monitor on the server adapters this ... We have four servers to ...
      (microsoft.public.windows.group_policy)