1823399 Members
2415 Online
109655 Solutions
New Discussion

Re: User mail

 
SOLVED
Go to solution
TheJuiceman
Super Advisor

User mail

Hi everyone,

I am wondering if anyone has put together a script that will monitor user mail for signs of anomolies such as an attack. Thanks in advance for sharing!!!
1 REPLY 1
F Verschuren
Esteemed Contributor
Solution

Re: User mail

hy,

I monitor on lines in the /var/adm/syslog/syslog.log
Depening on how You normaly monitor your system you need a adisional script, tng, tivoly and hpopenview can be configured to monitor this lines.
the lines are:

rexecd[28617]: read: Connection refused
DBLISTENER[28853]: .CADB_F_999 Pid=28853: Interrupted child process is being terminated
remshd[28952]: Connection from 0.0.0.0 on illegal port
telnetd[29024]: getpid: peer died: Error 0
ftpd[10504]: FTP LOGIN REFUSED (ftp not in /etc/passwd) FROM manual-1.1.1.1, anonymous