LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-02-2012, 08:30 PM   #1
milljunky
LQ Newbie
 
Registered: May 2012
Posts: 5

Rep: Reputation: Disabled
Send mail on failed attempt to login


Hi everyone!

My question is pretty straight-forward.
I have a mail server running on a desktop, and I want to be notified for each failed login attempt on the machine. Someone types a wrong password => e-mail to root.

By default I am already notified by failed sudo's.

I've searched a lot but I couldn't find the way.
I imagine it's done through PAM, right?


Thank you in advance.
 
Old 06-03-2012, 04:34 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by milljunky View Post
I want to be notified for each failed login attempt on the machine. Someone types a wrong password => e-mail to root.
I always wonder how one would prioritize it when faced with a gazillion alerts happening in a short period of time, what happens when the recipient isn't at his or her desk or doesn't get instant mail notifications, what happens if the MTA or route is down, what kind of security people think this provides or whatever else they want with instant notification?..


Quote:
Originally Posted by milljunky View Post
I imagine it's done through PAM, right?
Anyway. If PAM is used then failures are logged to /var/log/secure or whatever else you configured (r)syslog(-ng) with and if not then the service may provide its own log file. Any log file can be watched with Logcheck, Swatch or a cronjob that greps the log file for strings and alerts you.
 
Old 06-03-2012, 12:09 PM   #3
milljunky
LQ Newbie
 
Registered: May 2012
Posts: 5

Original Poster
Rep: Reputation: Disabled
Hi!

Of course I'm not relying all my security in it. It's just a test in a small workstation.
Thanks for your help.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] SquirrelMail v1.4.21 failed to send mail from specific PC moyorakkhi Linux - Newbie 1 12-01-2011 11:58 PM
Make computer shutdown on failed login attempt? Canadian1296 Linux - Security 2 11-21-2011 12:03 AM
Block IP after failed login attempt using iptables? FireRaven Linux - Security 6 08-11-2009 12:33 PM
Failed to send mail : Write failed : Permission denied shawnbishop Linux - Software 1 03-27-2006 01:50 PM
sendmail.. how do i login externally so I can send mail ? BaerRS Linux - Networking 3 05-17-2002 07:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:34 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration