(Ozymandias) RE: Emergency Sentry Robot

by Ozymandias (Hermit)
on Sep 11, 2000 at 03:52 UTC

in reply to Emergency Sentry Robot

This might have its uses, but it's risky to alert the person that you know they're there. They have a nasty habit of panicking and removing all logs via the "brute force method" - rm -rf *.

For quick security solutions, I find Psionic's freeware products to be excellent utilities for security; they're not perfect, but if you need something fast and accurate, they'll do the job. Even if they are written in Python...

I think especially highly of PortSentry and HostSentry, although HostSentry takes a little longer to set up than PortSentry.

RE: (Ozymandias) RE: Emergency Sentry Robot
by Aighearach on Sep 11, 2000 at 05:28 UTC

    Well, in this case I already had log backups of the activity. And, installing a package represented an unknown time period to research the available options, and install that option. It's a testament to the power of Perl that in these situations it can take less time to write a program from scratch than it would likely take to locate and install a free package. Also, and this is just from a quick glance at the links, those products don't offer the functionality that my script does; they detect intruders, but not unauthorized access of private files by somebody with root access. In this case it was the owner of the machine who had tarred and transfered files he didn't have legal access to.

    Anyway, the logs are already multiplexed. ;)

    Paris Sinclair
      Hey, it's your machine. All I can say is *I* wouldn't do that. Sure, the rm -rf * from / won't destroy the logs if you copy them off. So their immediate purpose is not well served. Umm... so? They've still completely trashed your box.

      Final word on the topic - alerting intruders that you are aware of their presense is a very bad idea. Do so at your own risk, and PLEASE don't try to tell people that it's not.

        Trashed my box? No, it's their box. And my files. I didn't say it is anything it's not, and I wasn't giving anybody advice. Why are you peeing on my node? Next time read it first.
        Paris Sinclair
