LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise
User Name
Password
Linux - Enterprise This forum is for all items relating to using Linux in the Enterprise.

Notices


Reply
  Search this Thread
Old 03-10-2007, 04:47 AM   #1
sachin1361
Member
 
Registered: Feb 2007
Posts: 126

Rep: Reputation: 15
monitoring


Can anybody create a script or something like that to help me which unathorized users are connected from the outside world. The command such as who ,netstat provides information of all users but i want to generate a list of those usres which are not authorized to connect any of the services but still get connected anyhow ??? when running above commande I have to check each variable which are my known or unknown and base upon that information we came to any conclusion and that takes significiant time. If there would be any command or script running which could genarate a list of that users to simply my monitoring task.


i 'd monitord someone on internet host 156.12.14.111 had connected with my computer. but now no connection from that IP address?: I want to know which files are modified from that IP or which configurations has been altered from that host ?How can I check that ?

Last edited by sachin1361; 03-10-2007 at 05:05 AM.
 
Old 03-10-2007, 08:57 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
unathorized users are connected from the outside world. The command such as who ,netstat provides information of all users but i want to generate a list of those usres which are not authorized to connect any of the services
Which "services" are you talking about, what does "the outside world" mean in relation to your box (anything not LAN? just some TLD's? or literally the whole world except a few IP ranges?) and what measures did you take to control access (so you can differentiate "authorised" from "unauthorised" "users")?
 
Old 03-11-2007, 03:53 AM   #3
sachin1361
Member
 
Registered: Feb 2007
Posts: 126

Original Poster
Rep: Reputation: 15
monitoring

We have one mail server, apache server and ssh/telnet enabled services which are accessed by internal users as well as by VPN clients from the remote locations. But I want to take some precautionary measures so that if in case others (not authenticated)users connect to any of these services , a customized report/file will be generated so that i could refer to the log files to trace individual line
 
Old 03-11-2007, 01:40 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
If the server(s) are located behind a firewall/router and
- (is/are located in a DMZ)? and
- (traffic is being scrubbed by an IDS)? and
- the edge firewall is configured so only LAN and VPN clients have access to it and is logging attempts and
- the server (host-based) is configured so only LAN and VPN clients have access to it and is logging attempts and
- the services on server(s) are properly configured so only LAN and VPN clients have access to it and are logging attempts
then you have more than enough data to generate reporting. You can chose for per-host reporting or you could deploy a central syslog server and for instance use Logwatch, Swatch, Logsurfer (old?) or Logsentry (old?) to generate reports. Determine if you need (near-)realtime alerting, multiple log checking tools and review the features of the products to see if they fit your requirements. See the LQ FAQ: Security references, post #1 under "Log analysis tools, resources" for application-specific tools or Freshmeat or Sourceforge.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Monitoring magasem AIX 2 11-05-2006 04:08 AM
what do you think of this monitoring service? ziggie216 Linux - Software 2 12-23-2003 08:18 AM
Process Monitoring arb Linux - Newbie 1 09-15-2003 08:35 AM
monitoring IP changes aru_titi Linux - Software 4 08-23-2003 08:31 AM
Monitoring jISV Linux - General 6 06-05-2003 11:12 AM

LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise

All times are GMT -5. The time now is 01:32 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration