Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: syslog idea
From: jmb () kryten Atinc COM (Jonathan M. Bresler)
Date: Fri, 7 Oct 1994 09:33:07 -0400 (EDT)


On Thu, 6 Oct 1994, *Hobbit* wrote:

If you don't have a secure logging host, there's also a possibility of
someone breaking in and then trashing the logfile to hide their tracks.

This brought to mind the idea of a "syslog monitor", or a process that would
just hang out someplace and stat the various log files periodically,
using some mechanism to warn of excessive size, mysterious shrinkage, and
maybe some other warning signs.
        
        take a look at tripwire from gene spafford and gene kim at purdue.
version 1.2 was released just last month.  it will monitor any files you 
want for changes in any of the fields returned by the lstat() syscall.  
this includes size, modification time, owner etc.   it  will also 
checksum those files using the checksum you specify, from simple 32bit 
crc to cryptographically strong signature algorithms.   you can run it 
out of cron as often as desired.

jmb

Jonathan M. Bresler  jmb () kryten atinc com    | Analysis & Technology, Inc.  
                                                | 2341 Jeff Davis Hwy
play go.                                        | Arlington, VA 22202
ride bike. hack FreeBSD.--ah the good life      | 703-418-2800 x346



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]