Re: portsentry

From: RainbowHat (nHiATlE@blSackholeP.mAit.edMu.invalid)
Date: 03/18/02


From: RainbowHat <nHiATlE@blSackholeP.mAit.edMu.invalid>
Date: Mon, 18 Mar 2002 20:40:45 +0000 (UTC)


< Julio
>One more thing, where does it keep the logs of attackers and how can I
>make it mail the log to root?

http://www.psionic.com/download/
http://www.psionic.com/tools/logcheck-?.?.?.tar.gz

-- 
Best Regards, RainbowHat. I support FULL DISCLOSURE.
----+----1----+----2----+----3----+----4----+----5----+----6----+----7



Relevant Pages

  • Re: Help: partitions - running out of free space
    ... Some logs indicate that I'm running out of disk space. ... It appears as if you're root filesystem has filled up, ... as init is switching to the single user maintenance runlevel. ... cannot give you any advice on how to download and install any missing ...
    (comp.os.linux.misc)
  • Re: some attack to fedora machine .
    ... I monitor my system for intrusion attacks ... Its very true as most informed people don't run as root, however you gotta be root to delete,modify, or even look at the logs. ... A sys admin will have to make trade offs to ensure people can get their work done but a saavy user can often get around things because its a trade off, ...
    (Fedora)
  • Re: some attack to fedora machine .
    ... I monitor my system for intrusion attacks ... the interesting information isn't owned by root at all but by the users. ... gotta be root to delete,modify, or even look at the logs. ... that it really depends on your perspective, user vs. sys admin. ...
    (Fedora)
  • Re: my log files-is there any problem
    ... >I am little concerned with these 2 means are these the normal entries ... >root 313 times isn't it too much. ... For the sendmail logs, nothing much to worry as a relaying attempt was ...
    (Fedora)
  • Re: Sarge system now refusing all login attempts
    ... > sudo attempt just hung forever. ... > sign on as either root or a user, at any prompt including VT's (which ... :-) try ls -lrt to see which logs were changed last (right after you do ... lilo prompt, type the lilo label followed by init=...), you get a root ...
    (Debian-User)