|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
RE: Detecting Brute-Force and Dictionary attacks
From: John Forristel (SunGard-Chico) (John.Forristel
sungardbi-tech.com)
Date: Thu Oct 19 2006 - 09:43:48 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Using System Watcher (Swatch) is very easy. Set the swatchrc file to watch the /var/log/messages file and trigger on a keyword (incorrect, unauthorized, failed, etc), and email you when it happens. Or set it to log to a file that emails you every hour/5 hours/day.
You can even set Swatch to execute an NMAP command then write to a file, so you have the login they were trying to use and where it came from.
John Forristel | SunGard Bi-Tech LLC | Network Security Analyst | UNIX and Linux Administration | (w) 530-879-2897 | 6:00am to 3:00pm
-----Original Message-----
From: listbounce
securityfocus.com [mailto:listbounce
securityfocus.com] On Behalf Of Shashi Kanth Boddula
Sent: Wednesday, October 18, 2006 3:02 AM
To: focus-linux
securityfocus.com
Cc: shashi.boddula
oracle.com
Subject: Detecting Brute-Force and Dictionary attacks
Hi All,
I am looking for a good tool to detect brute-force and dictionary attacks on user accounts on a Linux system . The tool should also have the intelligence to differntiate between user mistakes and actual brute-force/dictionary attacks and reduce the false positives. SuSE/RedHat included security tools are not helping in this case .
Please , anyone knows any third party security tool or any opensource security tool which solves my problem ?
Thanks & Regards,
Shashi Kanth,CISSP
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]