Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 41 guests online
 
Advertisement

You are here: Home arrow Resourcesarrow Toolsarrow Log cleaning
EH-Net
May 18, 2013, 08:44:35 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Log cleaning  (Read 4935 times)
0 Members and 1 Guest are viewing this topic.
former33t
Full Member
***
Offline Offline

Posts: 226


View Profile
« on: June 29, 2009, 08:34:29 PM »

I was curious if anyone knows of any good log cleaning tools out there that take care of extended process accounting on Solaris.  I'm not trying to do something illegal.  Quite the contrary actually.  A pentest I was involved with recently had extended accounting on some Solaris servers, so even with credentials, we basically were on and off without a good tool to clean the logs.  Same thing with BSM.  As soon as you see its there, you have to get off or the test is over (if your admin is worth the money they are paying him).  I got to thinking it can't be too hard to write some cleaning tools. A google search turned up nothing, but often doesn't.  Anyone know of anything out there before I get to coding?

Thanks.
Logged

Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
timmedin
Sr. Member
****
Offline Offline

Posts: 469



View Profile WWW
« Reply #1 on: July 11, 2009, 03:58:24 PM »

I dont' know of any.

If that same admin is worth his money the logs should be shipped off the box anyhow so you would have to work on the SIEM.
Logged

twitter.com/timmedin | http://blog.securitywhole.com
former33t
Full Member
***
Offline Offline

Posts: 226


View Profile
« Reply #2 on: July 11, 2009, 09:40:56 PM »

Yeah, that thought hadn't escaped me, but you wouldn't believe the number of INTERNET ACCESSIBLE boxes I find in pen tests that are only logging locally.  Often times the admin has been lulled into a false sense of security because they run a cron job or some such to fire off relevant log and audit entries to a logging server on a regular basis.  In this case, it is just a matter of beating the cron (or simply pausing it) so you can clean your garbage out of the logs first.
Logged

Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
timmedin
Sr. Member
****
Offline Offline

Posts: 469



View Profile WWW
« Reply #3 on: July 14, 2009, 07:18:18 PM »

Yeah, that thought hadn't escaped me, but you wouldn't believe the number of INTERNET ACCESSIBLE boxes I find in pen tests that are only logging locally.

<Sigh> ... Sad, but very true.

I did figure out if you send the send the correct kill signal you can pause lots of logging, clear out the stuff you want removed, and then restart it. Obviously it depends on the logging app. I can never remember the correct signal name, and I am away from home right now so I can't look it up.
Logged

twitter.com/timmedin | http://blog.securitywhole.com
UNIX
Hero Member
*****
Offline Offline

Posts: 1234


View Profile
« Reply #4 on: July 15, 2009, 12:39:22 AM »

I haven't had touched Solaris once yet, but I am assuming that programs written in Python or similar languages should work on it. With Python it is for example very easy to automate various tasks.

Gathering information on forensic tools such as Microsoft's Coffee, EnCase Portable, etc. it should not be too hard to reverse the process and clean all logs which are gathered from them.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.097 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.