QuicksearchCodenews SearchDisclaimerThe individual owning this blog works at Sun Microsystems GmbH in Germany, a subsidiary of Oracle. The opinions expressed here are his own, are not necessarily reviewed in advance by anyone but the individual author, and neither Oracle nor any other party necessarily agrees with them.
NavigationCategories
|
Less known Solaris features: AuditingSaturday, February 2. 2008Comments
Display comments as
(Linear | Threaded)
When I think someone owend my box, the first thing I should do is a1:1 copy of my harddrive... running this auditing process first could damage important data (important like 'how did the attacker get on my system').
Beside that it's great article. But somehow I get the feeling that Schaeuble will use Solaris soon.
Obviously you should activate auditing before an attacker hacks your system and move them to a different place on a regular schedule. So you can search for the attack vector and for the things done by the attacker.
Good thing would be to use the audit_syslog plugin. (http://docs.sun.com/app/docs/doc/816-5175/6mbba7eup?a=view) This will duplicate the events into syslog.
Syslog messages can then be forwarded to another system.
Yes ... definitly. A central loghost for this messages is a good idea.
Check out this BigAdmin page for a HOWTO on setting up a remote auditlog server using SSH.
http://www.sun.com/bigadmin/content/submitted/bsm_audit.jsp See method #4 for the remote option (SSH + RBAC). -Mike.
If I use the audit the return values for e.g. rm without sufficient privileges were logged as success. May an error on my configuration or on the audit module.
greetings up |
Links in this articleThe LKSF bookThe book with the consolidated Less known Solaris Tutorials is available for download here
Twitterfeedstwitter.com/c0t0d0s0
@mperedim no ... research for a new blog article ;) twitter.com/codenews 6914386 X freeze (and reboot) a build 130 system http://bit.ly/abvIH5 twitter.com/SunPatches Security patch: 113723-21 - SE3510 423A: StorEdge 3510 array controller firmware upgrade. Available since Feb/08/10. http://bit.ly/btnK9U twitter.com/SolPatchesX86 109810-12 - SunOS 5.8_x86: timezone data patch. Available since Feb/08/10. http://bit.ly/bW5k68 twitter.com/SolPatchesSPARC 109809-12 - SunOS 5.8: timezone data patch. Available since Feb/08/10. http://bit.ly/cNUNg8 Web 2.0Contact
Networking open.bc My photos SyndicationTagged articlesAMD Apple avs Bahn Blogging Blogosphere braindump Business Travel CeBIT cec cec2006 CMT del.icio.us deutsch dtrace fliegen Fundsache General Hamburg IBM i hate sundays Intel iscsi jumpstart Links Linux lksf Mindfuck Movies Music Musik Niagara Opensolaris Opteron Photographie policy of ... Politik Security Solaris storage Sun suncec2007 sunw t1 The IT Business Ultrasparc ultrasparc t1 Wirtschaft Work ZFS
CommentsTue, 09.02.2010 11:44
Is there anything this comment
should tell me ?
Tue, 09.02.2010 11:40
Dedup your brain!
Tue, 09.02.2010 11:25
Interesting read and it inspir
ed me to check upon the dedupe
features in TSM6.1. Seems tha
t it uses SHA-1, non-com [...]
Tue, 09.02.2010 09:32
ZFS computes the checksums any
way. The difference with hash-
only dedup is just the lookup
to a table, with hash-an [...]
Tue, 09.02.2010 09:04
Interesting Document, especial
ly Page three and four.
I c
an't agree that Support over I
nternet Portalsl/Metalin [...]
Buttons![]() This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 Germany License
![]() ![]() ![]() Blog Administration |
Ben Rockwood of Cuddletech wrote a good tutorial about the auditing in Solaris. This is a nice addition to the reading my LKSF tutorial about auditing
Tracked: Oct 20, 13:09