Re: [Prelude Hybrid IDS] #304: New rules for su attempts on FreeBSD systems

"Prelude Hybrid IDS" <[email protected]> Tue, 19 Aug 2008 15:29:13 -0000
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
#304: New rules for su attempts on FreeBSD systems
-------------------------+--------------------------------------------------
 Reporter:  Shurcik      |        Owner:  yoann             
     Type:  enhancement  |       Status:  assigned          
 Priority:  normal       |    Milestone:  Prelude-LML 0.9.13
Component:  prelude-lml  |      Version:  0.9               
 Severity:  normal       |   Resolution:                    
 Keywords:  su freebsd   |  
-------------------------+--------------------------------------------------
Changes (by yoann):

  * owner:  => yoann
  * status:  new => assigned


Old description:

> Hi all.
>
> I'm still not sure do we need separate su.rules file for them or we may
> put them to pam.rules file and update pcre.rules to:
>
> regex=([Pp][Aa][Mm]_|[Ss][Uu]);     include = pam.rules;
>
> Attached file has the updated rules for FreeBSD-style su attempts (check
> if analyzer.name should be "PAM" instead of used "su"):
>
> Best regards,
> Alexander Afonyashin

New description:

 Hi all.

 I'm still not sure do we need separate su.rules file for them or we may
 put them to pam.rules file and update pcre.rules to:

 {{{
 regex=([Pp][Aa][Mm]_|[Ss][Uu]);     include = pam.rules;
 }}}

 Attached file has the updated rules for FreeBSD-style su attempts (check
 if analyzer.name should be "PAM" instead of used "su"):

 Best regards,
 Alexander Afonyashin

--

-- 
Ticket URL: <https://trac.prelude-ids.org/ticket/304#comment:2>
Prelude Hybrid IDS <http://www.prelude-ids.org>
The Prelude Hybrid Intrusion Detection System suite
_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel