Re: New rules for su root attempts

Yoann Vandoorselaere <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <1216811173.6943.17.camel@arwen>
Hello Alexander,

Le vendredi 18 juillet 2008 à 18:05 +0300, Alexander Afonyashin a
écrit :

> I've found that performing 'su - root' task generates no events from
> prelude-lml sensor on FreeBSD systems. So I added two rules for
> successfull and non-successfull attempts. I'm not sure what *.rules
> should be updated (pam.rules or other), so I placed them into su.rules
> file.

Before including the rules in Prelude-LML, I'd suggest making the
following modification:

- Use the same classification as PAM (ie: User Authentication).
- Match on any user (not only root).

Thanks for this contribution! 

-- 
Yoann Vandoorselaere | Responsable R&D / CTO | PreludeIDS Technologies
Tel: +33 (0)8 70 70 21 58                  Fax: +33(0)4 78 42 21 58
http://www.prelude-ids.com

_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.