QuicksearchCodenews SearchDisclaimerThe individual owning this blog works at Sun Microsystems GmbH in Germany, a subsidiary of Oracle. The opinions expressed here are his own, are not necessarily reviewed in advance by anyone but the individual author, and neither Oracle nor any other party necessarily agrees with them.
NavigationCategories
|
Less known Solaris features: AuditingSaturday, February 2. 2008Comments
Display comments as
(Linear | Threaded)
When I think someone owend my box, the first thing I should do is a1:1 copy of my harddrive... running this auditing process first could damage important data (important like 'how did the attacker get on my system').
Beside that it's great article. But somehow I get the feeling that Schaeuble will use Solaris soon.
Obviously you should activate auditing before an attacker hacks your system and move them to a different place on a regular schedule. So you can search for the attack vector and for the things done by the attacker.
Good thing would be to use the audit_syslog plugin. (http://docs.sun.com/app/docs/doc/816-5175/6mbba7eup?a=view) This will duplicate the events into syslog.
Syslog messages can then be forwarded to another system.
Yes ... definitly. A central loghost for this messages is a good idea.
Check out this BigAdmin page for a HOWTO on setting up a remote auditlog server using SSH.
http://www.sun.com/bigadmin/content/submitted/bsm_audit.jsp See method #4 for the remote option (SSH + RBAC). -Mike.
If I use the audit the return values for e.g. rm without sufficient privileges were logged as success. May an error on my configuration or on the audit module.
greetings up |
Links in this articleThe LKSF bookThe book with the consolidated Less known Solaris Tutorials is available for download here
Twitterfeedstwitter.com/c0t0d0s0
Uploaded to Flickr: DSC_0093 http://bit.ly/9QPykw twitter.com/codenews 6932434 AAC adapter GUI hang when creating or deleting RAID http://bit.ly/cZVKE0 twitter.com/SunPatches 128365-04 - Sun Crypto Accelerator 6000 1.1: Driver Patch. Available for SPARC since Mar/19/10. http://bit.ly/agl9Nw twitter.com/SolPatchesX86 118192-04 - SunOS 5.9_x86: gtar patch. Available since Mar/19/10. http://bit.ly/cbnoJ7 twitter.com/SolPatchesSPARC 118191-04 - SunOS 5.9: gtar patch. Available since Mar/19/10. http://bit.ly/cb2Drj Web 2.0Contact
Networking open.bc My photos SyndicationTagged articlesAMD Apple avs Bahn Blogging Blogosphere braindump Business Travel CeBIT cec cec2006 CMT del.icio.us deutsch dtrace fliegen Fundsache General Hamburg IBM i hate sundays Intel iscsi jumpstart Links Linux lksf Mindfuck Movies Music Musik Niagara Opensolaris Opteron Photographie policy of ... Politik Security Solaris storage Sun suncec2007 sunw t1 The IT Business Ultrasparc ultrasparc t1 Wirtschaft Work ZFS
Comments about Reengining
Sat, 20.03.2010 21:36
I didn't have special interest
in airplanes, but your articl
es about airplanes are very go
od. They have made to ta [...]
Sat, 20.03.2010 08:55
Yes. And I just don't like the
way they're killing all of Su
n brands.
They could just buy
, help, let live, contro [...]
Sat, 20.03.2010 08:49
Well, I don't think many peopl
e were using Solaris at home b
efore Oracle acquisition too,
I see home servers more [...]
about Who are you?
Sat, 20.03.2010 02:15
Ich bin im Rahmen der Diskussi
on um das Zugangserschwerungsg
esetz auf dein Blog gestoßen.
Als Linux-Begeisterter d [...]
Sat, 20.03.2010 00:32
The article doesn't explain wh
y the adquisition of Sun is go
ing to be a sucessfull. It onl
y says that we all know: [...]
Buttons![]() This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 Germany License
![]() ![]() ![]() Blog Administration |
Ben Rockwood of Cuddletech wrote a good tutorial about the auditing in Solaris. This is a nice addition to the reading my LKSF tutorial about auditing
Tracked: Oct 20, 13:09