Summary: key logger on Solaris

From: Pit-Ong.Ong.Goh@reuters.com
Date: Tue Jun 15 2004 - 23:07:52 EDT


Hi,

Thanks, there's plentiful of replies & I cant list out all of them.
Thanks vm. Other the sudo ones, below are the replies :

***************************************************************************

A friend of mine took the source for bash and just added a line to
log to a file. Said it wasn't hard. Haven't tried myself so can't
say. But then you can just force users to that shell (whatever
shell you modify) and get everything.

---------------------------------------------------------------------------

Try PowerBroker

---------------------------------------------------------------------------

Why not try solaris config tracker?
Available free from sun.
Dosen't log key strokes but tracks changes to files that you specify.

---------------------------------------------------------------------------

I've used a program called PowerBroker...it has its own scripting
language which is very good and very easy to use. You can set up
different profiles for each user on different boxes, or have a profile
for a group of users. It is very customizable and it logs locally and
to a central server as well. Even does vi sessions so you can playback
log files if needed.

Here is the website http://www.symark.com/powerbroker.htm

---------------------------------------------------------------------------

1. Adjust the firewalls and sshd settings to allow ssh login only from
one server.
2. Force everyone to login to that server as their own user. Log all
traffic passing through that box in each separate ssh session.

That's what one of the banks I am working in does.

-----------------------------------------------------------------
        Visit our Internet site at http://www.reuters.com

Get closer to the financial markets with Reuters Messaging - for more
information and to register, visit http://www.reuters.com/messaging

Any views expressed in this message are those of the individual
sender, except where the sender specifically states them to be
the views of Reuters Ltd.
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 23:28:52 EDT