<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Hide Syslog file in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643354#M756274</link>
    <description>Hi Laurie,&lt;BR /&gt;&lt;BR /&gt;You can edit the syslog configuration file /etc/syslog.conf. The file name is specified over there. If you want to change the location of this file, stop the syslog daemon and edit the conf file and then restart the syslog daemon. Do a "man syslog.conf" for more info.&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&lt;BR /&gt;&lt;BR /&gt;Regds&lt;BR /&gt;</description>
    <pubDate>Fri, 11 Jan 2002 20:11:16 GMT</pubDate>
    <dc:creator>Sanjay_6</dc:creator>
    <dc:date>2002-01-11T20:11:16Z</dc:date>
    <item>
      <title>How to Hide Syslog file</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643351#M756271</link>
      <description>Hi All,&lt;BR /&gt;&lt;BR /&gt;We have Trusted HP-UX Servers (11.0 and 11.11)&lt;BR /&gt;and I want to hide the syslog files.  Basically&lt;BR /&gt;if someone gets in they might try to cover&lt;BR /&gt;their tracks by editing the syslog.log file.&lt;BR /&gt;&lt;BR /&gt;Now how could I setup to syslog.log into another directory instead of /var/adm/syslog&lt;BR /&gt;and called the file another name, like&lt;BR /&gt;stuff.save.  &lt;BR /&gt;&lt;BR /&gt;But then I would have to change the /etc/syslog.conf file or else a hacker&lt;BR /&gt;could find where I am hiding tne new syslog.&lt;BR /&gt;&lt;BR /&gt;Any thoughts?  &lt;BR /&gt;&lt;BR /&gt;Also (part 2 here) I want to know how to have&lt;BR /&gt;an audit trail of everyone who ftp's and&lt;BR /&gt;telnet's in.&lt;BR /&gt;&lt;BR /&gt;Thank You,&lt;BR /&gt;Laurie &lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 11 Jan 2002 20:03:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643351#M756271</guid>
      <dc:creator>Laurie A. Krumrey</dc:creator>
      <dc:date>2002-01-11T20:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to Hide Syslog file</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643352#M756272</link>
      <description>Don't know of a way to hide syslog.log unless you recompile to not use a syslog.conf file and put all the directives in the C code.&lt;BR /&gt;&lt;BR /&gt;Second part, auth.info is standard syslog entry for putting login info into syslog.log. Test the auth facility with some different serverity levels to see which one shows what you are looking for.&lt;BR /&gt;&lt;BR /&gt;GL,&lt;BR /&gt;C</description>
      <pubDate>Fri, 11 Jan 2002 20:08:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643352#M756272</guid>
      <dc:creator>Craig Rants</dc:creator>
      <dc:date>2002-01-11T20:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to Hide Syslog file</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643353#M756273</link>
      <description>Hi Laurie,&lt;BR /&gt;&lt;BR /&gt;The best method is to send the syslogs to a remote syslog server and restrict access to only people who are authorized. This way you dont have to worry about it.&lt;BR /&gt;&lt;BR /&gt;Modifying the syslog.conf file like&lt;BR /&gt;&lt;BR /&gt;*.info     @someotherserver&lt;BR /&gt;&lt;BR /&gt;will send the message to someotherserver&lt;BR /&gt;&lt;BR /&gt;Do not create any accounts on someotherserver except for few admins and periodically check the server.&lt;BR /&gt;&lt;BR /&gt;Make note still the hacker will know where the messages go but he/she can't get to it with usual methods.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;-Sri&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 11 Jan 2002 20:08:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643353#M756273</guid>
      <dc:creator>Sridhar Bhaskarla</dc:creator>
      <dc:date>2002-01-11T20:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to Hide Syslog file</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643354#M756274</link>
      <description>Hi Laurie,&lt;BR /&gt;&lt;BR /&gt;You can edit the syslog configuration file /etc/syslog.conf. The file name is specified over there. If you want to change the location of this file, stop the syslog daemon and edit the conf file and then restart the syslog daemon. Do a "man syslog.conf" for more info.&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&lt;BR /&gt;&lt;BR /&gt;Regds&lt;BR /&gt;</description>
      <pubDate>Fri, 11 Jan 2002 20:11:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643354#M756274</guid>
      <dc:creator>Sanjay_6</dc:creator>
      <dc:date>2002-01-11T20:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to Hide Syslog file</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643355#M756275</link>
      <description>Redirect sysloging to a seperate system that is either serially connected to your main system, or is on a private network between the two. Do not put it on the main network.  This severly limits the access to the sysloging system, and thus protects the log from hacker access. &lt;BR /&gt;&lt;BR /&gt;You have to add the system name to the /etc/hosts file, but be sure to not allow remote shell commmands (i.e. don't put the sysloging system in any .rhost files) and be sure to have unique login ID's and passwords for the syslogging system.&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;mark</description>
      <pubDate>Fri, 11 Jan 2002 20:13:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643355#M756275</guid>
      <dc:creator>Mark Greene_1</dc:creator>
      <dc:date>2002-01-11T20:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to Hide Syslog file</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643356#M756276</link>
      <description>In order to track ftp, edit /etc/inetd.conf file and add -l to the ftp command&lt;BR /&gt;&lt;BR /&gt;ftp  stream ... ... ../lbin/ftpd ftp -l&lt;BR /&gt;&lt;BR /&gt;you can also ftp -l -o -i to log every file transfered in or out  (that goes to /var/adm/syslog/xferlog)&lt;BR /&gt;&lt;BR /&gt;the telnet automaticaaly gets recorded in the /var/adm/wtmp file, you access this by doing the who, or last command</description>
      <pubDate>Fri, 11 Jan 2002 20:14:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643356#M756276</guid>
      <dc:creator>Jeff Machols</dc:creator>
      <dc:date>2002-01-11T20:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to Hide Syslog file</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643357#M756277</link>
      <description>Hi Laurie:&lt;BR /&gt;&lt;BR /&gt;First, the normal permissions of '/var/adm/syslog/syslog.log' are 644 with owhership by root.  This should prohibit the non-root user from writing to the file.&lt;BR /&gt;&lt;BR /&gt;To enhance the logging done by the 'ftpd' daemon, add the '-l' and '-L', '-i' and/or '-o' options to the daemon initiation arguments in '/etc/inetd.conf' and restart the inetd daemon:&lt;BR /&gt;&lt;BR /&gt;# /usr/sbin/inetd -c&lt;BR /&gt;&lt;BR /&gt;See the man pages for 'ftpd' for 11.x for more information.  On 10.x the '-l' and '-v' options apply.&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
      <pubDate>Fri, 11 Jan 2002 20:16:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643357#M756277</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2002-01-11T20:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to Hide Syslog file</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643358#M756278</link>
      <description>if you don't have another system to use a syslog server, you can create a daemon doeas something like &lt;BR /&gt;&lt;BR /&gt;tail -f syslog.log &amp;gt; /root/log.  &lt;BR /&gt;&lt;BR /&gt;If somebody gets in as root they can still see the syslog.conf file, so if you go to a different server, make sure thr root password is different and there are no .rhosts or they can get over there and wipe it out</description>
      <pubDate>Fri, 11 Jan 2002 20:17:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643358#M756278</guid>
      <dc:creator>Jeff Machols</dc:creator>
      <dc:date>2002-01-11T20:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to Hide Syslog file</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643359#M756279</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Check this out:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://us-support.external.hp.com/cki/bin/doc.pl/sid=ade5f0e20142f3d856/screen=ckiDisplayDocument?docId=200000056855569" target="_blank"&gt;http://us-support.external.hp.com/cki/bin/doc.pl/sid=ade5f0e20142f3d856/screen=ckiDisplayDocument?docId=200000056855569&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;HTH,&lt;BR /&gt;Shiju&lt;BR /&gt;</description>
      <pubDate>Fri, 11 Jan 2002 20:17:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643359#M756279</guid>
      <dc:creator>Helen French</dc:creator>
      <dc:date>2002-01-11T20:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to Hide Syslog file</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643360#M756280</link>
      <description>Hi (again) Laurie:&lt;BR /&gt;&lt;BR /&gt;I should also have noted for you that the permissions on the directory in which /var/adm/syslog/syslog.log resides (namely /var/adm/syslog) are normally 555 (r-x) which disallow the *removal* of the syslog.log by a non-root user.  Hence if users can't write to the file and they can't remove the file, I don't see the worry.&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
      <pubDate>Fri, 11 Jan 2002 20:29:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643360#M756280</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2002-01-11T20:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to Hide Syslog file</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643361#M756281</link>
      <description>HI&lt;BR /&gt;&lt;BR /&gt;For second part of your question, the ftpd daemon can be started with differnet options (-l, -L) from /etc/inetd.conf file.&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;BR /&gt;Prashant.</description>
      <pubDate>Fri, 11 Jan 2002 20:45:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-hide-syslog-file/m-p/2643361#M756281</guid>
      <dc:creator>Deshpande Prashant</dc:creator>
      <dc:date>2002-01-11T20:45:23Z</dc:date>
    </item>
  </channel>
</rss>

