logging invalid user

This is a discussion on logging invalid user within the Linux Security forums, part of the System Security and Security Related category; Hi, Does anyone know if it is possible to log invalid users access with ssh to syslog ? I want in ...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 09-16-2004
herc
 
Posts: n/a
Default logging invalid user

Hi,

Does anyone know if it is possible to log invalid users access with
ssh to syslog ? I want in my syslog an AUTH.WARNING with the message
[sshd]Invalid user from host = xxxxxx of something like that.

regards,

Chris
Reply With Quote
  #2 (permalink)  
Old 09-16-2004
Dimitri Maziuk
 
Posts: n/a
Default Re: logging invalid user

herc sez:
> Hi,
>
> Does anyone know if it is possible to log invalid users access with
> ssh to syslog ?


Yes.

...I want in my syslog an AUTH.WARNING with the message
> [sshd]Invalid user from host = xxxxxx of something like that.


You mean your ssh doesn't?

Dima
--
I have not been able to think of any way of describing Perl to [person]
"Hello, blind man? This is color." -- DPM
Reply With Quote
  #3 (permalink)  
Old 09-17-2004
herc
 
Posts: n/a
Default Re: logging invalid user

Dimitri Maziuk <dima@127.0.0.1> wrote in message news:<slrnckjea2.8rd.dima@localhost.localdomain>.. .
> herc sez:
> > Hi,
> >
> > Does anyone know if it is possible to log invalid users access with
> > ssh to syslog ?

>
> Yes.
>
> ..I want in my syslog an AUTH.WARNING with the message
> > [sshd]Invalid user from host = xxxxxx of something like that.

>
> You mean your ssh doesn't?
>
> Dima


If I log in to my computer with ssh and I use an invalid passwd I get
the following message to my syslog server

09-17-2004 12:32:30 Auth.Notice 172.16.13.12 PAM_unix[18715]: 1 more
authentication failure; (uid=0) -> root for ssh service
09-17-2004 12:32:30 Auth.Notice 172.16.13.12 PAM_unix[18715]: 1 more
authentication failure; (uid=0) -> root for ssh service
09-17-2004 12:32:25 Auth.Notice 172.16.13.12 PAM_unix[18715]:
authentication failure; (uid=0) -> root for ssh service
09-17-2004 12:32:25 Auth.Notice 172.16.13.12 PAM_unix[18715]:
authentication failure; (uid=0) -> root for ssh service


If I logging with an invalid user, nothings appears on the syslog
server
Reply With Quote
  #4 (permalink)  
Old 09-17-2004
Dimitri Maziuk
 
Posts: n/a
Default Re: logging invalid user

herc sez:
> Dimitri Maziuk <dima@127.0.0.1> wrote in message news:<slrnckjea2.8rd.dima@localhost.localdomain>.. .
>> herc sez:
>> > Hi,
>> >
>> > Does anyone know if it is possible to log invalid users access with
>> > ssh to syslog ?

>>
>> Yes.
>>
>> ..I want in my syslog an AUTH.WARNING with the message
>> > [sshd]Invalid user from host = xxxxxx of something like that.

>>
>> You mean your ssh doesn't?
>>
>> Dima

>
> If I log in to my computer with ssh and I use an invalid passwd I get
> the following message to my syslog server
>
> 09-17-2004 12:32:30 Auth.Notice 172.16.13.12 PAM_unix[18715]: 1 more
> authentication failure; (uid=0) -> root for ssh service
> 09-17-2004 12:32:30 Auth.Notice 172.16.13.12 PAM_unix[18715]: 1 more
> authentication failure; (uid=0) -> root for ssh service
> 09-17-2004 12:32:25 Auth.Notice 172.16.13.12 PAM_unix[18715]:
> authentication failure; (uid=0) -> root for ssh service
> 09-17-2004 12:32:25 Auth.Notice 172.16.13.12 PAM_unix[18715]:
> authentication failure; (uid=0) -> root for ssh service
>
>
> If I logging with an invalid user, nothings appears on the syslog
> server


(syslog-ng format)

Sep 12 09:08:29 x.x.x.x/x.x.x.x sshd[16228]: input_userauth_request:
illegal user yvonne
Sep 12 09:08:29 x.x.x.x/x.x.x.x sshd[16228]: Failed password for
illegal user yvonne from 143.107.45.186 port 55656 ssh2
Sep 12 09:08:29 x.x.x.x/x.x.x.x sshd[16228]: Received disconnect
from 143.107.45.186: 11: Bye Bye

-- from RH

Aug 31 14:20:48 x.x.x.x/x.x.x.x sshd[22309]: [ID 800047
auth.info] input_userauth_request: illegal user test
Aug 31 14:20:48 x.x.x.x/x.x.x.x sshd[22309]: [ID 800047
auth.info] Failed password for NOUSER from 140.130.177.203 port 4422 ssh2
Aug 31 14:20:48 x.x.x.x/x.x.x.x sshd[22309]: [ID 800047
auth.info] Received disconnect: 11: Bye Bye

-- from Solaris 9

Check your sshd_conf for log level & facility, check what your
loghost does with that facility/level messages.

Dima
--
I like the US government, makes the Aussie one look less dumb and THAT is a
pretty big effort. -- Craig Small
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 01:22 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0