Re: tripwire log checking



Dolf,

Is almost impossible to assure the integrity of a log file. Any good
cracker can easily play with any log file unnoticeably. The best way
to avoid tampering, is using a secure remote syslog or remote storage
system to send the logs to. Any local security measure (even tripwire)
will not be reliable in all conditions.

2009/1/29 Dolf Andringa <dolf.andringa@xxxxxxxxx>:
Hey all,

From a security point of view it is wise I think to know that nobody has
messed with the logs on a linux machine, because hackers often try to remove
any evidence of their presence. So tripwire, which I use to keep an eye on
file modifications, watches my /var/log folder for changes (which it does by
default on Ubuntu Hardy Heron server edition). But due to logrotation and
additions to my logs, tripwire keeps complaining that files have been added
and modified. Of course tripwire says that since after every logrotation,
files are moved around (/var/log/syslog->/var/log/syslog.0,
syslog.0->syslog.1.gz, etc).
So, my question is, do other people check their logs for integrity, and if
so, how?
Cheers,

Dolf.




--
Saludos,
Gustavo Castro Puig.
E-Mail: gcastrop@xxxxxxxxx

LPI Level-1 Certified (https://www.lpi.org/es/verify.html
LPID:LPI000042304 Verification Code: hp6re8w5qg )
-----BEGIN GEEK CODE BLOCK-----
Version: 3.12
GCS/CM/IT/ED dx s-:- a? C(+++)$ UL++++*$ P+ L++++(++)$ E--- W+++$ N+ o?
K- w O M V-- PS PE++(-) Y-(+) PGP+ t(++) 5+ X++ R tv+ b++(++++) DI+++
D++ G++ e++ h--- r y+++
------END GEEK CODE BLOCK------
Registered Linux User #69342



Relevant Pages

  • Re: Outlook Express sends mail, but it doesnt ....
    ... Maintenance page to do a Clean Up Now - I've never noticed the log file ... I've got a nasty OE problem with sending emails and the logs may well give ...
    (uk.comp.misc)
  • Re: App Verifier - Does not work on service correctly
    ... about AV in the log file. ... What user context are you running your services under? ... are not finding the logs when you go to View->Logs. ... Verifier found because when AppVerifier is turned off I do NOT recieve ...
    (microsoft.public.win32.programmer.tools)
  • Re: Hard Disk filling up after SMS 2003 Upgrade
    ... I just emailed you every log file contained in D:\SMS\Logs. ... I have plenty of disk space still ... > BTW, when zipping your FULL sms logs, can you also send me your MP logs too? ... > From: Joseph Calabig ...
    (microsoft.public.sms.misc)
  • Re: Exch 2007 - Message Tracking
    ... Max file size for single tracking log file is 10 Mb. ... In Exch 2003, I enabled message tracking and it would create daily logs in the location I specified. ...
    (microsoft.public.exchange.setup)
  • Re: Vsftpd rotate logs with newsyslog...
    ... restart cause i dont think the apache will be getting too many connections ... apache finishes and probably will xip logs that are still being access by ... you can compress the logs at a later time once the files ... B indicates that the log file is a binary file, ...
    (freebsd-questions)

Loading