Credentials Change classification
Russell Fulton <[email protected]> Thu, 5 Aug 2010 17:21:23 +1200
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <[email protected]> |
I am puzzled by the classification of this rule (pam rule set) which gets triggered by a login failure to ssh. This isn't a credential change it is remote login failure as signified by the rhost. # LOG:Dec 21 21:18:46 share2 sshd(pam_unix)[15525]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=a.b.c.d user=root # regex=authentication failure\; logname=([^ ]*)[ ]*uid=([^ ]*)[ ]*euid=.* tty=([^ ]*)[ ]*ruser=([^ ]*)[ ]*rhost=([^ ]*)[ ]*user=([^ ]*); \ classification.text=Credentials Change; optgoto=4; \ _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-technologies.com/mailman/listinfo/prelude-user