Re: Unix privileged access logging
offset <[email protected]>
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <[email protected]> |
On Wed, May 16, 2007 at 10:56:13AM -0400, James B Horwath wrote: > One of the items I am struggling with right now is logging Unix privileged > commands (add/deletes/etc). On some flavors of Unix administrative > actions are available via menus as well as the command line. The command > menus provide no method for syslog integration and the menus provide a > convenient tool fort staff. The native audit subsystem produces such a > large volume of data, parsing said data is not practical. Although sudo > logs all administrative access, it seems many admins lack the discipline > to use sudo on a routine basis other than to sudo su -. > Are there any tool recommendations? > Thanks in advance, > Jim > You are fighting a losing battle unless you can control the root account password. Use a tool such as powerbroker (supports keystroke logging) or equivalent and don't allow the admins to have the root password directly (escrow it away in a lock box or something) and have them user powerbroker (or equivalent) for all admin duties. And no, I do not work for powerbroker, just have used it in the past. The keystroke logging is excellent. Very flexible language for admin functions/rules. -- offset - ubersecurity org