Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 61 guests and 3 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Toolsarrow Log cleaning
EH-Net
May 25, 2012, 09:13:55 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Log cleaning  (Read 4387 times)
0 Members and 1 Guest are viewing this topic.
former33t
Full Member
***
Offline Offline

Posts: 228


View Profile
« on: June 29, 2009, 08:34:29 PM »

I was curious if anyone knows of any good log cleaning tools out there that take care of extended process accounting on Solaris.  I'm not trying to do something illegal.  Quite the contrary actually.  A pentest I was involved with recently had extended accounting on some Solaris servers, so even with credentials, we basically were on and off without a good tool to clean the logs.  Same thing with BSM.  As soon as you see its there, you have to get off or the test is over (if your admin is worth the money they are paying him).  I got to thinking it can't be too hard to write some cleaning tools. A google search turned up nothing, but often doesn't.  Anyone know of anything out there before I get to coding?

Thanks.
Logged

Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
timmedin
Sr. Member
****
Offline Offline

Posts: 470



View Profile WWW
« Reply #1 on: July 11, 2009, 03:58:24 PM »

I dont' know of any.

If that same admin is worth his money the logs should be shipped off the box anyhow so you would have to work on the SIEM.
Logged

twitter.com/timmedin | http://blog.securitywhole.com
former33t
Full Member
***
Offline Offline

Posts: 228


View Profile
« Reply #2 on: July 11, 2009, 09:40:56 PM »

Yeah, that thought hadn't escaped me, but you wouldn't believe the number of INTERNET ACCESSIBLE boxes I find in pen tests that are only logging locally.  Often times the admin has been lulled into a false sense of security because they run a cron job or some such to fire off relevant log and audit entries to a logging server on a regular basis.  In this case, it is just a matter of beating the cron (or simply pausing it) so you can clean your garbage out of the logs first.
Logged

Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
timmedin
Sr. Member
****
Offline Offline

Posts: 470



View Profile WWW
« Reply #3 on: July 14, 2009, 07:18:18 PM »

Yeah, that thought hadn't escaped me, but you wouldn't believe the number of INTERNET ACCESSIBLE boxes I find in pen tests that are only logging locally.

<Sigh> ... Sad, but very true.

I did figure out if you send the send the correct kill signal you can pause lots of logging, clear out the stuff you want removed, and then restart it. Obviously it depends on the logging app. I can never remember the correct signal name, and I am away from home right now so I can't look it up.
Logged

twitter.com/timmedin | http://blog.securitywhole.com
aweSEC
Hero Member
*****
Offline Offline

Posts: 1100


View Profile
« Reply #4 on: July 15, 2009, 12:39:22 AM »

I haven't had touched Solaris once yet, but I am assuming that programs written in Python or similar languages should work on it. With Python it is for example very easy to automate various tasks.

Gathering information on forensic tools such as Microsoft's Coffee, EnCase Portable, etc. it should not be too hard to reverse the process and clean all logs which are gathered from them.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.185 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.