Re: Auditing / Logging

From: Frank Knobbe (frank_at_knobbe.us)
Date: 01/13/04

  • Next message: Greg Tracy: "Re: Trojan Port List"
    To: Don Parker <dparker@rigelksecurity.com>
    Date: Tue, 13 Jan 2004 11:16:30 -0600
    
    
    

    On Mon, 2004-01-12 at 17:17, Don Parker wrote:
    > Well, you raise a valid point as to the commands not being logged.
    > Again I would prefer simplicity, so just install a keylogger. There
    > is no need to overcomplicate things. Though a keylogger will not work
    > on most *nix systems to my knowledge.

    Don't even have to do that. Have you never heard of a 'snoop' device?
    You can just snoop/watch the tty session you are using for your tests
    and redirect it to a file.

    On BSD systems you can use: watch -o ttyXX > logfile

    Cheers,
    Frank

    
    



  • Next message: Greg Tracy: "Re: Trojan Port List"

    Relevant Pages

    • Re: Auditing / Logging
      ... you raise a valid point as to the commands not being logged. ... > Again I would prefer simplicity, so just install a keylogger. ... > on most *nix systems to my knowledge. ...
      (Pen-Test)
    • RE: Auditing / Logging
      ... but the question was one of keylogging; as a keylogger it is the most ... reliable and trouble-free solution. ... > usable as evidence as to in what order commands were issued. ... >> We provide Ethical Hacking, Advanced Ethical Hacking, ...
      (Pen-Test)
    • RE: Auditing / Logging
      ... but the question was one of keylogging; as a keylogger it is the most ... > usable as evidence as to in what order commands were issued. ... >> We provide Ethical Hacking, Advanced Ethical Hacking, ... We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion Prevention, ...
      (Security-Basics)
    • key logger on Solaris
      ... Would be best if the keylogger can identify who ... is typing what commands & store the files separately for each user. ... Get closer to the financial markets with Reuters Messaging - for more ... sender, except where the sender specifically states them to be ...
      (SunManagers)
    • [opensuse] External Drive Formatting Question
      ... bytes) and external usb drive enclosure. ... I plan to use this to back up data on both my *nix systems and a Win2K system. ... For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx ...
      (SuSE)