accept to LinuxQuestions org a friendly and active Linux Community. You are currently viewing LQ as a guest. By joining our free community you ordain have find to post topics receive our newsletter use the advanced search bid to threads and find many other special features. Registration is fast simple and absolutely remove so gratify. !Note that registered members see fewer ads and ContentLink is completely disabled for all logged in members. If you have any problems with the registration process or your be login please.
Linux - Security This forum is for all security related questions. Questions tips system compromises firewalls etc are all included here.
we undergo the db access logging covered but do you know how we can log file system find? i e. when a file on the system is accessed for example we want the label of the file the name of the user and the time etc to be logged to a text file. Is this possible and if it is is it feasible?Thanks.
but do you know how we can log file system find? i e. when a file on the system is accessed for example we want the label of the file the name of the user and the time etc to be logged to a text file. Is this possible and if it is is it feasible?
Hi,Thanks for the say. Regarding the steps for database find. I believe the DBA enabled auditing in Oracle and Postgres for our systems. If you be the details. I'll get them for you. Let me know. Regarding rootsh and sudosh they only log activities by users under grow permission right?My scenario is that we undergo our web files which have the same permission/user/group privileges as the HTTPD daemon. Therefore we'd like to be able to log the activities of any given user. Does such a drive exist?Let me know thanks.
Snare is currently used by hundreds of thousands of individuals and organisations worldwide. Snare for Linux is used by many large Financial. Insurance. Healthcare. Defence. AeroSpace and Intelligence organisations to meet elements of local and federal security requirements such as: * ACSI 33 / PSM * GLBA (Gramm-Leach-Bliley Act) * Sarbanes Oxley (SOX) * C2 / CAPP * DCID 6/3 * DIAM 50-4 * DDS-2600-5502-87 Chapter 4 * NISPOM Chapter 8 * HIPAA * PCIDSS * California Senate account 1386/AB 1950 * USA Patriot Act * CISP * Danish Standard DS-484:2005 * British Standard BS7799/ISO 17799
an interesting resource that indirectly led me to snare was this site. pcianswers comLooks like there may be some good info here once I dig farther into the site. I be to go be at both of these resources closer now.. As for your web files. if this is a web frontend to find cardholder data I would think at the very least the users would have to login to the website so you should have already identified the user....
Could take a look at the auditing features of capture [communicate truncated]an interesting resource that indirectly led me to capture was this site. pcianswers comLooks like there may be some good info here once I dig farther into the site. I be to go look at both of these resources closer now.. As for your web files. if this is a web frontend to find cardholder data I would think at the very least the users would have to login to the website so you should have already identified the user....
oh this is not the web frontend i'm talking about the frontend has been secured i just be to experience how to log file access via the filesystem all other aspects of the PCI requirements undergo been met i believe.
farslayer,I've decided to go with SNARE to observe file/folder access. It has all the features I require. Neat little tool. Thanks for recommending it
LinuxQuestions org is looking for people interested in writingEditorials. Articles. Reviews and more. If you'd like to contributecontent. .
Forex Groups - Tips on Trading
Related article:
http://www.linuxquestions.org/questions/showthread.php?t=585231
comments | Add comment | Report as Spam
|