store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Mon May 20, 2013 12:19 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 
Author Message
 Post subject: File change notifications
Unread postPosted: Fri May 25, 2012 7:31 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1844
I'm aware than ossec notices when certain files are changed, but this mechanism isn't useful as it gets hidden in the "noise" of other alerts.

What I'd like is an email notification triggered when certan "critical" files are changed. For example, Plesk MU#32 reset smtp_psa and smtps_psa to their defaults, killing off spamdyke. If I hadn't been looking for it, I would not have noticed it.

I'd really like a clear alert when something like that happens.

Same probably goes for qmail_send or whatever it is that gets changes that causes qmail-scanner to stop working.

Basically if any imporant config flle that isn't in the self-healing list changes, I'd like to know about it.

Of course I can't think of anything else other than httpd.conf and php.ini (which I've never seen changed by Plesk, thankfully, so maybe not good candidates), but doubtless there are some.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: File change notifications
Unread postPosted: Sat Jun 30, 2012 3:55 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Oct 29, 2007 6:51 pm
Posts: 606
The ftp files would be nice too, maybe the psa.conf file too


Top
 Profile  
 
 Post subject: Re: File change notifications
Unread postPosted: Mon Jul 02, 2012 11:25 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
Have you tried out the "Watch" function in the File Integrity manager? You can set a watch on a file or directory, the level to alert at (say 13 in your example) and a custom email address if youd like. My original idea for this was to let you use it for domain level owners to get HIDS alerts when their domains change. You could certainly use it for this too:

In ASL Web select:
-> ASL
-> File Integrity
-> Options
-> Directories
-> Add new rule:
-> Select: notify
Path: /path/to/file/or/directory
Level: XX (13 for example)
Email to: <your@email.address>
-> Click update


Top
 Profile  
 
 Post subject: Re: File change notifications
Unread postPosted: Tue Jul 03, 2012 11:05 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1844
Cool! I wasn't aware of this feature.

ASL is probably to application I least like to experiment with, so if I don't absolutely need to do something I don't touch it :-)

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: File change notifications
Unread postPosted: Tue Jul 03, 2012 12:40 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
Also if you select the "Report Changes" option it will send you the diffs of the changes made to an ASCII file


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group