Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [ISSForum] AIX Server Sensor Not Working |
|---|---|
| Date: | Wed, 16 Mar 2005 20:11:53 -0800 (PST) |
Hi Zoran, The syslog is running but not into a file. When I make necessary changes to the syslog.conf, syslog messages can show its events in the SP(like SU_login). But this is not what I want, the events like login_with_Administrative_privileges events didn't show up(like someone doing telnet & accessing as root). The only way I can do it is by using C2 audit. Doing the C2 audit is really a big hassle as there's another file to keep track on its size. I already patched the system according to the article. Best regards, Kwan --- Zoran Hrvoic <zoran4afc@hdinfo.hr> wrote:
Hello, AFAIK, you can't run any UNIX ServerSensor without syslog. From the Server Sensor Installation Guide (RS_SvrSensor_IG_7.0.pdf): "... for UNIX sensors, you must enable syslog logging before any syslog based signatures can work (many non-network based signatures rely on the syslog)". You should also check the KB article #2902. Zoran ----- Original Message ----- From: "Kwan Chee Kin" <kck3180@yahoo.com> To: "Zoran Hrvoic" <zoran4afc@hdinfo.hr>; <ISSForum@iss.net> Sent: Wednesday, March 16, 2005 3:20 PM Subject: Re: [ISSForum] AIX Server Sensor Not Working Hi, I'm not using any Syslog. Kwan --- Zoran Hrvoic <zoran4afc@hdinfo.hr> wrote:I had a similar issue few years ago with AIX OS Sensor. Then the problem was trivial: the syslog daemonhadbeen writing to the "/var/log/syslog.log" file, and the sensorexpectedlog in "/var/log/syslog". Check what is your syslog output file, and is itthesame file the sensor is expecting. Zoran ----- Original Message ----- From: "Kwan Chee Kin" <kck3180@yahoo.com> To: "Andres Riancho" <andresit@fibertel.com.ar>; <issforum@iss.net> Sent: Saturday, March 12, 2005 10:24 AM Subject: Re: [ISSForum] AIX Server Sensor Not Working Hi, Yes, I did try with another policy. It still won't work. I did not install the network monitoring component so I don't think that will work, willit?I'm trying to get the auditting part work. Thanks. Best regards, Kwan Chee Kin --- Andres Riancho <andresit@fibertel.com.ar>wrote:Have you tried with another policy ? Maybe youcouldtry to enable the event HTTP_GET for testing. Cheers , Andres Riancho ----- Original Message ----- From: "Kwan Chee Kin" <kck3180@yahoo.com> To: <issforum@iss.net> Sent: Thursday, March 10, 2005 7:32 AM Subject: [ISSForum] AIX Server Sensor NotWorkingHi, I installed RS Server Sensor 7 on both AIX and Windows. I got the Sensors on both platforms communicating to the Site Protector 5. Iappliedthedefault Attack_And_Audit_Policy into theSensors.ThenI tried to test on the audit part of thispolicybytrying a brute force login to the Sensors. The Windows platform sensors shows me theeventslikeI expected but the AIX did not even showanything.There is not even an event showing 'root'accesstothe system. I verified the Sensors is Active. Then Iverifiedthatthe enforce audit policy is turned on in eachAIXsensors and the Auditing in OS for the policyischecked. What could be the problem? Anyone bump intosuchproblem before? Will AIX sensors show me anything in theeventsliketelnet login? Anyone knows any diagnostic tool I can checkwhetherthe AIX sensor is working or not? Appreciate any comment. Thank you. Best regards, Kwan CK__________________________________________________Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spamprotection aroundhttp://mail.yahoo.com_______________________________________________ISSForum mailing list ISSForum@iss.net TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, gotohttps://atla-mm1.iss.net/mailman/listinfo/issforumTo contact the ISSForum Moderator, send emailtomod-issforum@iss.netThe ISSForum mailing list is hosted andmanagedbyInternet Security Systems, 6303 Barfield Road, Atlanta, Georgia,USA30328.__________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com _______________________________________________ ISSForum mailing list ISSForum@iss.net TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum To contact the ISSForum Moderator, send email to mod-issforum@iss.net The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.__________________________________ Do you Yahoo!? Yahoo! Small Business - Try our new resources site! http://smallbusiness.yahoo.com/resources/
=== message truncated ===
__________________________________
Do you Yahoo!?
Yahoo! Small Business - Try our new resources site!
http://smallbusiness.yahoo.com/resources/
_______________________________________________
ISSForum mailing list
ISSForum@iss.net
TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to
https://atla-mm1.iss.net/mailman/listinfo/issforum
To contact the ISSForum Moderator, send email to mod-issforum@iss.net
The ISSForum mailing list is hosted and managed by Internet Security Systems,
6303 Barfield Road, Atlanta, Georgia, USA 30328.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [ISSForum] AIX Server Sensor Not Working, Kwan Chee Kin |
|---|---|
| Next by Date: | Re: [ISSForum] AIX Server Sensor Not Working, Zoran Hrvoic |
| Previous by Thread: | Re: [ISSForum] AIX Server Sensor Not Working, Zoran Hrvoic |
| Next by Thread: | [ISSForum] RSDP and Safenet, MATT PIERCE |
| Indexes: | [Date] [Thread] [Top] [All Lists] |