The sys admin’s daily grind: login mail

SPYGLASS

Article from Issue 117/2010
Author(s):

Charly often gets suggestions and ideas for his column at community get-togethers. Last week, he picked up a tip for an early warning system that quickly secures login attempts.

Some servers I don’t log in to for weeks on end. On machines like this, the danger of intruders being able to log in without my noticing is fairly high. And if attackers do manage to crack open a victim’s computer, they will do everything they can to cover their tracks. This includes removing all traces of the login from the logs, which makes it more or less impossible to ascertain the exact time of the attack and – what’s more important – the attacker’s IP.

Buy this article as PDF

Express-Checkout as PDF
Price $2.95
(incl. VAT)

Buy Linux Magazine

SINGLE ISSUES
 
SUBSCRIPTIONS
 
TABLET & SMARTPHONE APPS
Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content

  • LUG Camp 2010

    From the Lower Rhine to Central Franconia, on his journey, Charly found beaten gold, relaxed Linux users, abandoned beer cellars, and a Python one-liner for presentable photos of the tour. A once-in-a-year experience.

  • Charly's Column

    Users log on to services such as SSH, ftp, SASL, POP3, IMAP, Apache htaccess, and many more using their names and passwords. These popular access mechanisms are a potential target for brute-force attacks. An attentive bouncer will keep dictionary attacks at bay.

  • The sys admin's daily grind: Users and groups

    This time Charly investigates the three most frequently asked questions about user groups.

  • Charly's Column: LUG Camp Tschierv

    He nearly missed this year’s LUG Camp, but what was columnist Charly supposed to do instead – celebrate Father’s Day?

  • Charly's Column: Swaks

    Searching for errors on an SMTP server via Telnet and test mails can seem like a never-ending obstacle course. The utility called Swaks helps bring the finish line within reach.

comments powered by Disqus