Re: User account auditing

From: H Carvey (keydet89_at_yahoo.com)
Date: 04/19/05

  • Next message: Steve Bostedor: "VNC Security"
    Date: 19 Apr 2005 10:17:49 -0000
    To: security-basics@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is) In-Reply-To: <20050418192823.11627.qmail@web13824.mail.yahoo.com>

    >With multiple platforms like Windows, Linux, As400,
    >Unix etc. How do you manage and verify accounts on
    >these systems ?

    On Windows, I understand "manage", but what do you mean by "verify"?

    >Do you have all admins send a monthly report on the
    >accounts present, last time account was utilized etc.
    >?

    When I was in an FTE position, I had a script that would access the domain controller and get all of the last login times. I'd then break it down by 30, 60, and 90 days...with certain steps forwarded to the sysadmins based on the increment.

    >This would also have to be done for database like
    >Oracle, SQL, SYBASE...

    Sure. I don't really see where that's a problem. I think the biggest issue is going to be the requirements development...what is it that you're trying to do?

    H. Carvey
    "Windows Forensics and Incident Recovery"
    http://www.windows-ir.com
    http://windowsir.blogspot.com


  • Next message: Steve Bostedor: "VNC Security"

    Relevant Pages

    • Postfix, Courier-imap with mysql and squirrelmail
      ... The accounts allready there works just fine, ... virtual unix - n n - - virtual ... maildrop unix - n n - - pipe ... hosts = 127.0.0.1 ...
      (Debian-User)
    • Re: Is VMS losing the Financial Sector, also?
      ... I can see where your thinking makes sense if you are on a single monolithic system, which may be the case in the VMS world. ... Not sure what the equivalent is on UNIX or Windows, but I am sure they must have an equivalent means to do this. ... system accounts can be well monitored. ...
      (comp.os.vms)
    • Re: Integrating Unix logons into Windows AD
      ... Microsoft MVP - Directory Services ... I'm wondering if its possible to configure Unix based systems ... > have their logon authenticated against a Windows system and Active ... > systems are easier to maintain (currently, accounts need to be manually ...
      (microsoft.public.windows.server.active_directory)
    • Re: no permission for root???
      ... Here's a really good simple site on what Unix permissions are and I ... Windows, except they are mutually exclusive in Linux, meaning I can ... and many other accounts are specialized to ...
      (freebsd-questions)
    • Re: Integrating Unix logons into Windows AD
      ... >> accounts on our Unix systems and another group of accounts on Windows, ... >> the OpenLDAP implementation scheme on Unix is similar to Active ...
      (microsoft.public.windows.server.active_directory)