Thread: adding to logwatch?
i way tell me when program opens network connection. started (cron, bash shell, other program) there way can this?
there existing log or way turn on logging. besides each individual programs logs might not exist if malicious program.
have unexplained network events router says blocked. far know have clean machine. pretty fresh install minimal programs installed , have shored think need it.
apache web server expect traffic outside port 80. handles email sendmail expect traffic our filter on port 25 sends email form php pages expect outgoing mail on 25. handles dns via bind expect incoming , outgoing on 53. ssh , run shelter scripts block bad ssh attempts.
logwatch emails everyday , looks normal. shows when login via ssh , sudo root maintenance. shows normal web traffic , like. show when apt-get connects , updates. show when emails sent , programs. show when else opens port ever reason. can remove offending programs or users.
===update=========
remember can logging iptables although im not sure can tell program trying make connection. remember being able log go search that.
Forum The Ubuntu Forum Community Ubuntu Official Flavours Support Networking & Wireless [other] adding to logwatch?
Ubuntu
Comments
Post a Comment