Focus on Linux
root shell auditing Jul 28 2008 01:34PM
Mars Gobetti (erresei6 libero it) (6 replies)
Re: root shell auditing Jul 30 2008 04:34PM
JW (jw mailsw com)
RE: root shell auditing Jul 30 2008 11:15AM
THORNTON Simon (Simon THORNTON swift com)
Re: root shell auditing Jul 29 2008 02:11PM
Diego Lacerda (diegolacerda gmail com) (1 replies)
Re: root shell auditing Jul 31 2008 09:24AM
Hari Sekhon (hpsekhon googlemail com) (2 replies)
Re: root shell auditing Aug 04 2008 01:09PM
Marian Rudzynski (mr impaled org) (1 replies)
Re: root shell auditing Aug 04 2008 01:30PM
Hari Sekhon (hpsekhon googlemail com) (1 replies)
Re: root shell auditing Aug 05 2008 05:18PM
Glynn Clements (glynn gclements plus com) (1 replies)
Re: root shell auditing Aug 06 2008 08:10AM
Hari Sekhon (hpsekhon googlemail com)
Glynn Clements wrote:
> Hari Sekhon wrote:
>
>
>> Perhaps you could force everybody to use sudo for every command that
>> requires root privs and have automated alerting if anyone does a direct
>> root login or a sudo su or an sudo (/usr)?/bin/shell_of_your_choice type
>> thing...
>>
>> sudo does log properly and if all commands go through it, then you win.
>> This way all root commands would either be logged or you'd be alerted to
>> someone intentionally circumventing the logging by getting a full root
>> shell.
>>
>
> Looking for specific commands won't work. There are just too many
> "indirect" ways to execute a command.
>
> Even if you log everything which the user types and review those logs
> thoroughly, there are still ways to slip things past the reviewer,
> especially if the user is allowed to use interactive programs (vi,
> less, etc), or whose behaviour can be influenced by the contents of
> files (which may have changed or been removed by the time that you
> review the logs).
>
> The only mechanism which won't miss anything is logging at the syscall
> level, i.e. auditctl/auditd. Even that won't tell you everything
> that's happening (logging read() and write() would overwhelm the
> logs), but it should be enough to detect suspicious activity, and it
> cannot be bypassed in the way that logging user input or commands can.
>
True true.

So back to the other solution I mentioned which is auditing every
keystroke, input and output of every session.

But alas this is a proprietary solution.

I want an open source version of this so much...

-h

--
Hari Sekhon

[ reply ]
Re: root shell auditing Aug 04 2008 10:46AM
Philip Turner (p turner newman ac uk) (1 replies)
Re: root shell auditing Aug 05 2008 02:01PM
Hari Sekhon (hpsekhon googlemail com)
Re: root shell auditing Jul 29 2008 10:01AM
TJ Easter (tjeaster gmail com) (2 replies)
Re: root shell auditing Jul 31 2008 08:54AM
Hari Sekhon (hpsekhon googlemail com)
RE: root shell auditing Jul 30 2008 07:28AM
Dan Hanman (dan hanman regencyitc co uk)
Re: root shell auditing Jul 29 2008 09:07AM
Huzeyfe ONAL(Gmail) (huzeyfe onal gmail com)
Re: root shell auditing Jul 29 2008 09:07AM
Tim Brown (tmb 65535 com)


 

Privacy Statement
Copyright 2010, SecurityFocus