LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-10-2011, 02:23 AM   #1
sneakyimp
Senior Member
 
Registered: Dec 2004
Posts: 1,056

Rep: Reputation: 78
need help with samhain -- unexpected logkey alert


A couple of months back I was involved in a lengthy process to move my site from a compromised server to a new server. Part of this process was setting up samhain. Samhain has been behaving predictably and made me feel much reassured about the security of my server. However, it sent me an ALRT email just a few minutes ago with msg=LOGKEY.

I'm not entirely sure what all the samhain messages mean but seem to recall that ALRT messages are the most serious type and that logkeys are only generated when a log is started. I want to know what this means and whether I should be concerned about my system. Can anyone tell me more about this?
 
Old 10-10-2011, 09:18 AM   #2
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
Logkeys are used in Samhain to allow you to verify the integrity of the logs. From what I remember, when the logging is restarted, a log key is generated. In this case, it sounds like you received some form of alert message and the logkey was provided to allow you to verify the authenticity of the alert. It would be prudent to investigate the alert and determine the source. More than likely, it is indicating that something uncommon happened, which could be a form of scan attempt or any number of things and I wouldn't take this to mean that you have been compromised. See this link for some more information on the log key feature.

As an example of what I mean, this morning, I was reviewing the output of logwatch and noticed an entry for connect from in.comsat on 127.0.0.1 in the secure log. As I keep the SSH port closed off to all but my a few known IP addresses on the public interface, this really caught my attention. Doing some digging, showed that the time was at the same point that the ClamAV update process ran. Further digging showed that this is a daemon process involving mail and that it was an email being sent to the root@localhost user. It was a benign alert, but it caught my attention because it was out of the ordinary.
 
Old 10-10-2011, 12:27 PM   #3
sneakyimp
Senior Member
 
Registered: Dec 2004
Posts: 1,056

Original Poster
Rep: Reputation: 78
Thanks again, Noway2.

Yes this alert was quite uncommon. I usually only get alerts when I change something. I went digging around and it would appear that logrotate finally decided to rotate the samhain log. The timing of the new logkey appears to coincide more or less precisely with the dates on the log files. If I'm not mistaken, it would appear that logrotate signalled the samhain process and rotated the logs. I'm just not sure if this is how samhain behaves or not.

I used the new log key to verify the current log file and it gives a PASS for every line:
Code:
samhain -L /var/log/samhain/samhain.log
I guess I'm just wondering if that's how samhain would behave when a log gets rotated.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
OPENNMS -how can i get disk space alert & memory alert BY MAIL saravanakumar Linux - Server 11 05-30-2014 08:45 AM
opennms --memory alert & disk alert issue saravanakumar Linux - Server 4 07-19-2011 10:54 AM
Samhain questions kaplan71 Linux - Security 1 06-16-2010 05:16 PM
ALERT!!! ALERT!!! I messed up the UNIX!!! Firew Linux - Software 1 11-05-2001 11:48 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:04 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration