Fedora Linux Support Community & Resources Center
  #1  
Old 23rd June 2005, 04:03 PM
sforget Offline
Registered User
 
Join Date: Jun 2005
Posts: 9
Logging SSH connections

I have noticed that the system log only records failed log-in attempts through SSH.

While still providing useful information, I would rather log ALL attempts at logging in through SSH, successful or otherwise. This way I can determin how secure my server is by also paying attention to who does successfully log in.

Any ideas how I might go about doing this?
Reply With Quote
  #2  
Old 23rd June 2005, 04:11 PM
yanik Offline
Registered User
 
Join Date: Nov 2004
Posts: 148
where are you looking?
Reply With Quote
  #3  
Old 23rd June 2005, 04:14 PM
yanik Offline
Registered User
 
Join Date: Nov 2004
Posts: 148
look at /var/log/secure
Reply With Quote
  #4  
Old 23rd June 2005, 04:17 PM
w5set Offline
Registered User
 
Join Date: Feb 2005
Location: ark n saw out in the sticks
Posts: 2,316
edit /etc/ssh/shhd_config and in the "logging" section--
uncomment the #LogLevel INFO line
Reply With Quote
  #5  
Old 23rd June 2005, 11:30 PM
pushback Offline
Registered User
 
Join Date: Jun 2005
Location: Bay Area, California
Posts: 167
Quote:
Originally Posted by sforget
I have noticed that the system log only records failed log-in attempts through SSH.

While still providing useful information, I would rather log ALL attempts at logging in through SSH, successful or otherwise. This way I can determin how secure my server is by also paying attention to who does successfully log in.

Any ideas how I might go about doing this?

You can also use the 'last' command--that will show you all logins--example:

apollo[root]:/root-> last
root pts/4 209.57.192.100 Thu Jun 23 15:28 still logged in
root pts/3 192.168.100.11 Thu Jun 23 12:47 still logged in
root pts/3 192.168.100.11 Wed Jun 22 23:17 - 02:23 (03:05)
root pts/3 192.168.100.11 Wed Jun 22 22:21 - 22:52 (00:30)
root pts/5 209.57.192.100 Wed Jun 22 13:59 - 22:22 (08:23)
root pts/5 209.57.192.100 Wed Jun 22 13:38 - 13:58 (00:19)
root pts/3 192.168.100.11 Wed Jun 22 01:34 - 14:06 (12:31)

Also, the /var/log/messages file shows you all attempts, failed or succesful:

Jun 23 14:03:12 apollo sshd(pam_unix)[5487]: check pass; user unknown
Jun 23 14:03:12 apollo sshd(pam_unix)[5487]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=80.51.253.38
Jun 23 14:03:17 apollo sshd(pam_unix)[5489]: check pass; user unknown
Jun 23 14:03:17 apollo sshd(pam_unix)[5489]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=80.51.253.38
Jun 23 15:28:40 apollo sshd(pam_unix)[6183]: session opened for user root by root(uid=0)

(looks like I already have someone trying to crack my new install of fc4--sheesh)

Finally, if you are running logwatch, which runs by default in fc4, you should have these messages in roots mailbox daily:

U 4 root@localhost.local Sun Jun 19 04:02 176/6410 "LogWatch for apollo"

contents:

sshd:
Authentication Failures:
root (192.168.100.11): 2 Time(s)
Sessions Opened:
root by root: 4 Time(s)
Reply With Quote
  #6  
Old 24th June 2005, 08:49 AM
sforget Offline
Registered User
 
Join Date: Jun 2005
Posts: 9
Quote:
Originally Posted by w5set
edit /etc/ssh/shhd_config and in the "logging" section--
uncomment the #LogLevel INFO line

Thank-you. Thats works exactly as I need
Reply With Quote
Reply

Tags
connections, logging, ssh

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
2 connections, 1 NIC nspmangalore Servers & Networking 2 23rd August 2007 03:03 PM
2 connections, 1 NIC nspmangalore Using Fedora 1 22nd August 2007 10:03 AM
Help with my connections. Allieonfire Using Fedora 1 3rd July 2006 06:35 AM
FC4 stop logging after Webmin installed ( bandwidth logging ) simonxyz EOL (End Of Life) Versions 0 15th November 2005 10:48 AM
VPN Connections. Jeffa Using Fedora 3 17th October 2004 04:31 AM


Current GMT-time: 22:29 (Thursday, 23-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat