Re: boot -s - can i detect intruder

From: Socketd (db_at_traceroute.dk)
Date: 09/16/03

  • Next message: G Hasse: "Re: boot -s - can i detect intruder"
    Date: Tue, 16 Sep 2003 10:14:14 +0200
    To: freebsd-security@freebsd.org
    
    

    On Tue, 16 Sep 2003 11:02:05 +0100
    "Nikolay Kanchev" <niki@amk-drives.bg> wrote:

    > Several people have physical access to my FreeBSD box and I have the
    > feeling that somebody try to get access with boot -s options . Can I
    > log activity after boot -s option (change user password, install
    > software and etc.). I use boot -s and change user password, but after
    > reboot i can't find this atcivity in log files.
    > The BSD box is shutdown and run again many time at day.

    Why not set console in /etc/ttys to insecure? Then you can't login
    without a password.

    br
    socketd
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: G Hasse: "Re: boot -s - can i detect intruder"

    Relevant Pages

    • SUMMARY: system shut down cleanly?
      ... some good ideas from the usual suspects - Alan Rollow, Ryan Frantz, David ... Also if you have decevent installed, it will also log a shutdown ... We looked at all the log files. ... > CONFIDENTIALITY NOTICE ...
      (Tru64-UNIX-Managers)
    • Re: EWF-RAM protected partition on Compact Flash becomes unbootabl
      ... If a shutdown was happening during a write operation are all the directories ... My log files have their own ... card I noticed a dramatic increase in the number of FBA's the card would ... If data is being writen to the second partition when the system shutdown, ...
      (microsoft.public.windowsxp.embedded)
    • Re: Apache probe
      ... > I'm seeing this phenomenon occur since updated to 1.3.22-6. ... This machine was upgraded to apache-1.3.22-6 before either shutdown. ... was that in reviewing my log files, ... I'm also suspicious that this machine needs a BIOS upgrade. ...
      (comp.os.linux.security)
    • Re: [Full-Disclosure] SSH Exploit Request
      ... 'shutdown now' is BSD. ... IIRC, SunOS used the BSD version, but starting with ... SunOS 5.5 they switched to System V shutdown. ...
      (Full-Disclosure)
    • Re: stuck in shutdown
      ... > Xiaoyi Wu wrote: ... >>Does anyone else experence the similar thing? ... shutdown is "gpm shutdown failed". ... If it stuck on "unmounting file systems", chances are, the log files are ...
      (comp.os.linux.setup)