Re: SOCKS over OpenSSH Logging?



On 2007-06-13, jnovack@xxxxxxxxx <jnovack@xxxxxxxxx> wrote:
Is there any way (from the server standpoint) to log the usage of the
SOCKS via OpenSSH? I've noticed that my server's bandwidth has gone
up considerably and a few of my users are idle (or running a minimal
task to avoid the timeout) and assume they are proxying, but I cannot
prove it.

Whether its in source/destination format, bandwidth used, time spent
or even IF someone is using it, I'd like to log it in some fashion.

If you set LogLevel DEBUG1 or higher in sshd_config (and restart sshd)
then you will get a server_request_direct_tcpip log entry with
destination address and port for each port forward request (I don't
think it logs the traffic volume, though).

Note that if your users have shell access, this isn't the only way of
relaying and this will not catch those. See if your platform supports
a way of accounting for all users' traffic to catch those.

--
Darren Tucker (dtucker at zip.com.au)
GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69
Good judgement comes with experience. Unfortunately, the experience
usually comes from bad judgement.
.



Relevant Pages

  • Re: Need help with bandwidth management . . .
    ... The bandwidth managements is much better in v24 than in v23: ... QoS lan port settings, and I cannot get anything consistent. ... it common practice on their home connections. ... first one in my opinion is bandwidth management. ...
    (alt.internet.wireless)
  • Re: block_ssh_guessers
    ... port knocking daemon by sheer volume - say, ... might be in the packet (which after all is only going to be a SYN in most ... due to, for example, the logs using up all available disk space. ... _usually_ a waste of time, CPU cycles, disk-space and bandwidth. ...
    (comp.os.linux.security)
  • Re: Port Attack Question
    ... Mark - The problem is one of the processing on the firewall and available ... The port whether it is POP/SMTPor HTTPis irrelevant aside from the ... connections and may slow the firewall down if enough connections are ... If the attackerhad enough bandwidth or networks to bounce the ...
    (comp.security.firewalls)
  • Re: MRTG monitoring specific ports
    ... Spades wrote: ... | Is there anyway for us to trace the server bandwidth based on ... | specific ports on a MRTG graph? ... port 110 ...
    (freebsd-questions)
  • Re: randyfromm.com Technical Department Reopened
    ... and plan on paying the subscription for your ... port 80 and I had to serve on the alternate ... the bandwidth consumption raised a red flag and my ISP ... In order to continue to serve, I had to subscribe to my ISP's "Business ...
    (rec.games.video.arcade.collecting)