Summary: key logger on Solaris

Pit-Ong.Ong.Goh_at_reuters.com
Date: 06/16/04

  • Next message: Raji: "simple script not working on soalris 9"
    Date: Wed, 16 Jun 2004 11:07:52 +0800
    To: sunmanagers@sunmanagers.org
    
    

    Hi,

    Thanks, there's plentiful of replies & I cant list out all of them.
    Thanks vm. Other the sudo ones, below are the replies :

    ***************************************************************************

    A friend of mine took the source for bash and just added a line to
    log to a file. Said it wasn't hard. Haven't tried myself so can't
    say. But then you can just force users to that shell (whatever
    shell you modify) and get everything.

    ---------------------------------------------------------------------------

    Try PowerBroker

    ---------------------------------------------------------------------------

    Why not try solaris config tracker?
    Available free from sun.
    Dosen't log key strokes but tracks changes to files that you specify.

    ---------------------------------------------------------------------------

    I've used a program called PowerBroker...it has its own scripting
    language which is very good and very easy to use. You can set up
    different profiles for each user on different boxes, or have a profile
    for a group of users. It is very customizable and it logs locally and
    to a central server as well. Even does vi sessions so you can playback
    log files if needed.

    Here is the website http://www.symark.com/powerbroker.htm

    ---------------------------------------------------------------------------

    1. Adjust the firewalls and sshd settings to allow ssh login only from
    one server.
    2. Force everyone to login to that server as their own user. Log all
    traffic passing through that box in each separate ssh session.

    That's what one of the banks I am working in does.

    -----------------------------------------------------------------
            Visit our Internet site at http://www.reuters.com

    Get closer to the financial markets with Reuters Messaging - for more
    information and to register, visit http://www.reuters.com/messaging

    Any views expressed in this message are those of the individual
    sender, except where the sender specifically states them to be
    the views of Reuters Ltd.
    _______________________________________________
    sunmanagers mailing list
    sunmanagers@sunmanagers.org
    http://www.sunmanagers.org/mailman/listinfo/sunmanagers


  • Next message: Raji: "simple script not working on soalris 9"

    Relevant Pages

    • Re: Problem with server shutting down completely need help..
      ... Smith" schreef in bericht ... > the replies to my post if I did not connect to the internet soon after ... >>> into some problems with my server shutting down completely while I'm ... >>> event viewer to examine the event log for details. ...
      (microsoft.public.windows.server.sbs)
    • Re: reverse proxy identification
      ... they are Windows Boxes. ... many IP replied with Server param set to "webserver" ... SYN ACK replies from servers. ... How do u interpret all this data, what are possible configurations to get these ...
      (Pen-Test)
    • Re: An error occurred while reconnecting....
      ... * PLEASE post all messages and replies in the newsgroups ... The problem was resolved by upgrading a portion of the network to gigabit, ... the server) on that portion of the network. ... with caution - as it will disconnect ALL network mappings. ...
      (microsoft.public.win2000.networking)
    • Re: Slow throughput problem
      ... thx for the replies, today was another day for the integration test. ... to use telnet and the server can read the message just fine. ... already that the throughput was fine except when they use their client. ... // the part handling packet to be sent ...
      (comp.lang.java.programmer)
    • Re: Can usenet be saved?
      ... I can't afford to d/l hundreds of headers to ... possible find my replies. ... In principle IMO the server should do the ... orphaned response. ...
      (news.software.readers)