Intrusion Detection Systems mailing list archives

Re: snooping on RH?


From: mlists () gizmo kyrnet kg (CyberPsychotic)
Date: Thu, 7 Oct 1999 17:25:38 +0500 (KGT)



~ Does anyone know of any ports of ttywatcher for linux (specifically redhat)?
~ 
~ I've been looking for something good to monitor potential problem-users for
~ a while, Any suggestions?
~ 

 if you have root on machine, where you want to monitor your users, you
could use ttysnoop which is `troyaned' replacement for in.telnetd daemon.
Alternatively there were some linux kernel hacks featured in Phrack's 50th
issue called linspy. I also was writing the similar tool which could let
you watch all telnet-connected terminals in your local network, but I
never managed to make it up so anyone but me could play with it..



Current thread: