Gentoo Archives: gentoo-user

From: Stroller <stroller@××××××××××××××××××.uk>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Advice for System monitor + Intrusion Detection tools?
Date: Fri, 19 Nov 2010 22:07:12
Message-Id: C2EACFCA-2032-4550-999E-03099097A1C2@stellar.eclipse.co.uk
In Reply to: [gentoo-user] Advice for System monitor + Intrusion Detection tools? by "Fatih Tümen"
1 On 19/11/2010, at 8:45pm, Fatih Tümen wrote:
2 > I just want to beware of anything unusual instantly, preferably by
3 > email. This is a single or two user laptop.
4
5 I've been meaning for some time to look for something like this myself. I'm personally only interested in messages from the RAID controller, and I'm not sure that I'm a high-risk for intrusion, but I do want to know about it *immediately* if a drive fails, so that ideally I can pop into the store on the way home and pick up a new disk to replace the one that failed.
6
7 > ...
8 > I also checked logsurfer which comes with a init script, however, no
9 > working configuration file and sort of confusing examples.
10
11 I don't really have a problem with the examples on these pages:
12 http://www.crypt.gen.nz/papers/logsurfer.html
13 http://www.crypt.gen.nz/logsurfer/man_logsurfer_conf.html
14
15 Or with these explanations [PDF]:
16 http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.5.8610&rep=rep1&type=pdf
17 http://www.laptopmobilesecurity.com/papers/Logsurfer.pdf
18
19 The examples contain a lot of brackets and stuff, but those seem merely to be regular expressions, and if you don't know regex then learning them will pay dividends in other future projects. logsurfer's syntax and the use of "contexts" is not completely clear to me with only the quick glance I've made in the 10 minutes its taken me to write this message, but I'm extremely confident I could have it up and running to meet my needs within an hour. The documentation seems no more complex than any other man page. I'm pretty sure you would understand what's going on if you were only to follow the examples and have a play with them.
20
21 Be sure to use the `start-mail` script you find in the doc/contrib directory, not any others you find floating around the net:
22 http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060389.html
23
24 The doc/contrib script seems to address the issue of escape sequences (although I'm about to do some more homework on this subject).
25
26 Stroller.

Replies

Subject Author
Re: [gentoo-user] Advice for System monitor + Intrusion Detection tools? "Fatih Tümen" <fthtmn+gentoo@×××××.com>
[gentoo-user] Re: Advice for System monitor + Intrusion Detection tools? Lubos Kolouch <lubos.kolouch@×××××.com>