Re: New rules for su root attempts

Yoann Vandoorselaere <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <1216824370.6943.60.camel@arwen>
Le mercredi 23 juillet 2008 à 08:06 -0400, Steve Grubb a écrit : 
> On Wednesday 23 July 2008 07:06:13 Yoann Vandoorselaere wrote:
> > > I've found that performing 'su - root' task generates no events from
> > > prelude-lml sensor on FreeBSD systems. So I added two rules for
> > > successfull and non-successfull attempts. I'm not sure what *.rules
> > > should be updated (pam.rules or other), so I placed them into su.rules
> > > file.
> >
> > Before including the rules in Prelude-LML, I'd suggest making the
> > following modification:
> >
> > - Use the same classification as PAM (ie: User Authentication).
> 
> Well, su actually has 2 operations, user authentication and change of 
> credentials that may include new rights via ancilliary groups and of course 
> capabilities if root. It is possible to have the correct password, but yet be 
> denied by pam.
> 
> So it would seem to me that you would want any failure in the password to be 
> logged as an auth failure, but you would want anything else to be recorded as 
> a change in credentials.

Currently, a lot of alert generated use word to indicate
successful/failed completion within classification.text. 

We are in the process of normalizing all classification in order to make
it easier for the Correlation agent to work with a set of alert.

This is the reason classification.text should not, when possible
indicate completion value:  impact.completion is preferred for this
purpose.

I agree through that the current classification is discussable, and
might not fit in specific PAM case. We ideally should open a wiki page
to create a set of generic classification.text that can be used by any
products (hint: contribution in this area are more than welcome): do you
have any idea that would better fit for this event? 

> > - Match on any user (not only root).
> 
> root is the one called out for in many security targets because its a granting 
> of capabilities.

One might target a random user with higher credentials in order to have
more access on the machine, this is why we try to match for any user
change.

-- 
Yoann Vandoorselaere | Responsable R&D / CTO | PreludeIDS Technologies
Tel: +33 (0)8 70 70 21 58                  Fax: +33(0)4 78 42 21 58
http://www.prelude-ids.com

_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.