Re: New rules for su root attempts
Yoann Vandoorselaere <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <1216811173.6943.17.camel@arwen> |
Hello Alexander, Le vendredi 18 juillet 2008 à 18:05 +0300, Alexander Afonyashin a écrit : > I've found that performing 'su - root' task generates no events from > prelude-lml sensor on FreeBSD systems. So I added two rules for > successfull and non-successfull attempts. I'm not sure what *.rules > should be updated (pam.rules or other), so I placed them into su.rules > file. Before including the rules in Prelude-LML, I'd suggest making the following modification: - Use the same classification as PAM (ie: User Authentication). - Match on any user (not only root). Thanks for this contribution! -- Yoann Vandoorselaere | Responsable R&D / CTO | PreludeIDS Technologies Tel: +33 (0)8 70 70 21 58 Fax: +33(0)4 78 42 21 58 http://www.prelude-ids.com _______________________________________________ Prelude-devel site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-devel