[Prelude Hybrid IDS] #304: New rules for su attempts on FreeBSD systems
"Prelude Hybrid IDS" <[email protected]> Tue, 12 Aug 2008 14:02:19 -0000
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
#304: New rules for su attempts on FreeBSD systems --------------------------------+------------------------------------------- Reporter: Shurcik | Type: enhancement Status: new | Priority: normal Milestone: Prelude-LML 0.9.13 | Component: prelude-lml Version: 0.9 | Severity: normal Keywords: su freebsd | --------------------------------+------------------------------------------- Hi all. I'm still not sure do we need separate su.rules file for them or we may put them to pam.rules file and update pcre.rules to: regex=([Pp][Aa][Mm]_|[Ss][Uu]); include = pam.rules; Attached file has the updated rules for FreeBSD-style su attempts (check if analyzer.name should be "PAM" instead of used "su"): Best regards, Alexander Afonyashin -- Ticket URL: <https://trac.prelude-ids.org/ticket/304> Prelude Hybrid IDS <http://www.prelude-ids.org> The Prelude Hybrid Intrusion Detection System suite _______________________________________________ Prelude-devel site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-devel