- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: security script
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-27-2000 03:26 AM
10-27-2000 03:26 AM
I am looking at writing a script that will on being run FTP copies of system log files to another server. So that in the event of a security problem I can concentrate on fixing and bring the attacked sever back on line and then later do an offline investigation.
Well guys/gals what are your thoughts on this?
Is it feasible to set up a list of all the files that may show an intruders footsteps?
And if so which file do you include - some are very obvious (wtmp,btmp,syslog etc)but what are the less obvious?
Awaiting your ideas-
Paula
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-27-2000 04:06 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-27-2000 04:40 AM
10-27-2000 04:40 AM
Re: security script
Your problem will be as follows:
If someone gets into the system, he/she will always try to wipe their prints. So depending on what level of access they get to you system will basically determine how well they can wipe their prints. Most damaging obviously being root.
Besides they few obvious ones like wtmp,btmp,etc you should consider copieng some of these files as well:
passwd
shell history commands
acct files
crontab - yes nice way to reinstate access
syslog
maillog
nettlogs
This list might vary a lot depending on the setup of your system
Like: is accounting enabled?
are you running a secure system ?
etc
Hope you find some info to be usefull.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-27-2000 07:01 AM
10-27-2000 07:01 AM
Re: security script
- points will be awarded.
The list so far is:-
1. wtmp
2. btmp
3. utmp
4. utmpx
5. syslog.log
6. passwd
7. groups
8. shell history
9. mail.log
10. netlogs
11. sulog
12. inetd.sec
13. crontab
Now the list is mainly log files, how about.
ll ?R |grep ?ATTACK_DATE? >attacked
and this file included in the routine?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-27-2000 07:18 AM
10-27-2000 07:18 AM
Re: security script
Can be obtained from the COAST security site.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2000 12:54 AM
10-31-2000 12:54 AM
Re: security script
Points have been awarded.
Best wishes
Paula
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2000 09:51 AM
10-31-2000 09:51 AM
Re: security script
do you know what is internet address this sw ( SW Tripwire ) ?
thank?s
Paulo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2000 09:51 AM
10-31-2000 09:51 AM
Re: security script
do you know what is internet address this sw ( SW Tripwire ) ?
thank?s
Paulo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2000 09:52 AM
10-31-2000 09:52 AM
Re: security script
do you know what is internet address this sw ( SW Tripwire ) ?
thank?s
Paulo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2000 09:55 AM
10-31-2000 09:55 AM
Re: security script
Address for tripwire is
http://www.tripwiresecurity.com/products/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2000 10:07 AM
10-31-2000 10:07 AM