Templates and Alerts

 

 

 

 

 

Login/Logout Template

Table A-21

Successful su Detected Alert Properties (Continued)

 

 

 

 

 

 

 

 

Response

Alert

Alert

 

 

 

Program

Field

Alert Value/Format

Description

 

Field

 

Argument

Type

 

 

 

 

 

 

 

 

 

 

 

 

 

argv[5]

<Empty>

n/a

n/a

This field is

 

 

 

 

 

empty

 

 

 

 

 

 

 

argv[6]

<Empty>

n/a

n/a

This field is

 

 

 

 

 

empty

 

 

 

 

 

 

 

argv[7]

Summary

String

"Successful su session"

Alert summary

 

 

 

 

 

 

 

argv[8]

Details

String

“User <username_from> switched to user

Detailed alert

 

 

 

 

<username_to> on tty <tty>”

description

 

 

 

 

 

 

 

argv[9]

Local

Integer

<secs>

Local time in

 

 

Time

 

 

number of

 

 

 

 

 

seconds since

 

 

 

 

 

epoch when a

 

 

 

 

 

successful su

 

 

 

 

 

event occurs.

 

 

 

 

 

 

 

argv[10]

Flag

Integer

2

Indicates an su

 

 

 

 

 

alert versus a

 

 

 

 

 

login/logout

 

 

 

 

 

alert.

 

 

 

 

 

 

 

argv[11]

Device

String

<tty>

The tty from

 

 

 

 

 

which a

 

 

 

 

 

successful su

 

 

 

 

 

attempt was

 

 

 

 

 

made.

 

 

 

 

 

 

 

argv[12]

From

String

<username>

The name of the

 

 

 

 

 

user attempting

 

 

 

 

 

to su.

 

 

 

 

 

 

 

argv[13]

To

String

<username>

The target user

 

 

 

 

 

of the su

 

 

 

 

 

command.

 

 

 

 

 

 

Limitations

• The template only detects logins and logouts that are logged to wtmp[s].

The template does not detect successful secure ftp (sftp) logins and logouts because the ssh daemon logs successful sftp logins and logouts using syslog(3C) instead of logging them to wtmp on 11i version 1.0 and wtmps on 11i version 2.0.

The template does not detect secure shell (ssh) logins and logouts by ssh daemons that do not log successful ssh logins and logouts to wtmp on 11i version 1.0 and wtmps on 11i version 2.0. SSH daemons should be configured with the "UsePAM" configuration value set to "no" in order to log successful ssh logins and logouts to wtmp(s).

Appendix A

171

Page 183
Image 183
HP Host Intrusion Detection System (HIDS) manual Appendix a 171