The UNIX and Linux Forums  
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.

Go Back   The UNIX and Linux Forums > Special Forums > Security
.
google unix.com



Security Discuss UNIX and Linux computer and network security, cybersecurity, cyberattacks, IT security, CISSP, OWASP and more.

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
shell command logging minkie SUN Solaris 2 12-04-2008 02:37 PM
Command Logging in SCO brian_g UNIX for Dummies Questions & Answers 2 04-13-2006 05:46 PM
Logging command invocations - cmdlog Driver UNIX for Dummies Questions & Answers 1 05-15-2004 07:30 PM
What is command for logging? dtamminx UNIX for Dummies Questions & Answers 3 02-11-2003 06:58 PM
SSH and command logging penguin-friend UNIX for Advanced & Expert Users 2 02-25-2002 06:11 AM

Closed Thread
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Bulgarian Greek Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
  #1 (permalink)  
Old 01-28-2009
humbletech99 humbletech99 is offline
Registered User
  
 

Join Date: Sep 2008
Posts: 18
Full Command Logging?

I am looking for a really good command logging tool to improve the auditing of my servers. I have previously used snoopy but this is currently a bit flaky and causing serious problems for me, it doesn't look like it's been maintained since 2004, it didn't even want to compile until I added -fPIC but it's causing segmentation faults and just ruins my test systems, eventually causing all or nearly all commands to segfault. I've tried the process account tools but they log only the command basename, no args and no shell built-ins either (although even snoopy doesn't get that last one, but I could live without it if I had to). Shell history files are not security, they are just convenience, so they don't fit either (unless we find a way of capturing all shell history straight into syslog...) So I'm looking for something else that I can deploy among my servers to fully audit any commands entered and log them via syslog. Does anyone have any recommendations for a good thorough command logger, capturing args as well?
  #2 (permalink)  
Old 01-29-2009
otheus's Avatar
otheus otheus is offline Forum Staff  
Moderator ala Mode
  
 

Join Date: Feb 2007
Location: Innsbruck, Austria
Posts: 1,884
I made some updates to snoopy, including command argument handling, fixing its bugs, and a more flexible configuration (filtering out uninteresting commands, such as crond children, etc), but the authors haven't responded. It relies on any system that allows the LD_PRELOAD and supports sysv seamphores. If you are interested, I will send you my version, and you can help me remove any other bugs. Send me a PM with your email address.
Closed Thread

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 05:48 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0