Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Page 1 of 4 1234 LastLast
Results 1 to 15 of 49

This is a discussion on System log tweaking in the VPS & Dedicated forum
Hi All: I am now a proud member of the hacked club... lucky for me it was one of my business accounts and not a ...

  1. #1
    Loyal Client
    Join Date
    Sep 2006
    Posts
    143

    Question System log tweaking

    Hi All:

    I am now a proud member of the hacked club... lucky for me it was one of my business accounts and not a customer's account or the whole VPS

    So, been working on tweaks and such to get things right.

    I currently monitor the basic services from 2 different remote PCs on 2 different networks to make sure they are always up. But these 2 IP addresses are filling a bunch of un-needed info the log files. Is there any way to have all of the system logs (whether configured universally or one-by-one) to parse out/skip logging from specific IP addresses?

    Any thoughts or ideas are appreciated.

    Thanks

  2. #2
    Loyal Client thisisit3's Avatar
    Join Date
    Mar 2007
    Posts
    642
    How did you get hacked? did you find a vulnerable script?

    Check the "syslog" man pages, since the syslog is doing all the work on log files.

  3. #3
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by thisisit3 View Post
    How did you get hacked? did you find a vulnerable script?
    Little known fact...

    I've been hacked twice, since 2003, and both times it was by Iranians! They don't seem to like General George Patton quotes!

    What do you think?!?!?!?
    Last edited by thisisit3; 10-11-2007 at 02:11 AM.
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  4. #4
    Loyal Client thisisit3's Avatar
    Join Date
    Mar 2007
    Posts
    642
    I believe they should find something better to do than to deface sites.

    Why not ask them to submit the remote exploits to the authors of the vulnerable script?

  5. #5
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by thisisit3 View Post
    I believe they should find something better to do than to deface sites.

    Why not ask them to submit the remote exploits to the authors of the vulnerable script?
    The U.S. government will set probably set off a thermonuclear device in Phoenix, Seattle or Portland in the next month, and blame it on Iran -- in which case, we WILL turn Iran into 'glass' - or at least 850 (or so) places in Iran.

    In the scheme of things, what difference does defacing of web sites make?

    They should have left Patton alone...
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  6. #6
    all about nothing! Frank Broughton's Avatar
    Join Date
    Jan 2006
    Posts
    2,158
    Quote Originally Posted by Vin DSL View Post
    They should have left Patton alone...
    Better yet, Ike should have left him alone and we would have half the world as ours and all the oil!

  7. #7
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by Frank Broughton View Post
    Better yet, Ike should have left him alone and we would have half the world as ours and all the oil!
    Yeah, I guess, but the root cause of this situation is the Brits...

    They're the ones that busted up the Persian Empire - and the Persians are busy putting Humpty Dumpty back together again!

    I don't know if you realize it, but Turkey is bombing the crap out of Northern Iraq, as we 'speak', softening them up for the invasion - at which point, the Kurds are gonna be stomped out of existence via ground troops, already amassed at the border.

    Yep! This is going to be interesting...

    I assume you read about the leak last month, when the Black OPs were ferrying the thermonuclear tipped cruise missles into position around the USA - the Air Force plane that accidently got caught.

    It's back on schedule for October...
    Last edited by Vin DSL; 10-11-2007 at 12:46 PM.
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  8. #8
    all about nothing! Frank Broughton's Avatar
    Join Date
    Jan 2006
    Posts
    2,158
    Have not heard - I am safe though, my best friend is the next ruler of the world!

  9. #9
    Loyal Client
    Join Date
    Sep 2006
    Posts
    143
    It was a hole in a script that I run, that they claim was fixed in 2004, but I was never notified about ("it aint broke dont fix" just went out the door).

    The script has been taken off line until I can get the hole plugged.

    Any thoughts on the logging and having the logs ignore specific IP addresses?

  10. #10
    Ron
    Ron is offline
    Loyal Client
    Join Date
    Aug 2002
    Posts
    7,312
    Do you mean blocking certain IPs from using your site?
    Good luck

  11. #11
    Loyal Client
    Join Date
    Sep 2006
    Posts
    143
    Blocking IP addresses is what I am working on now (good timing)... any suggestions you have there are appreciated. The WHM IP blocker does not work for squatt.

    What I am trying to accomplish is causing the system logging to ignore documenting actions from specific IP addresses (my machines basically)

  12. #12
    Ron
    Ron is offline
    Loyal Client
    Join Date
    Aug 2002
    Posts
    7,312
    in .htaccess you can deny by IP and IP range.
    An example is
    Code:
    order allow,deny
    deny from 123.45.6.7
    deny from 012.34.5.
    allow from all
    I've never looked into trying to get the system not to log activity..
    Good luck

  13. #13
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by Vin DSL View Post
    [10-11-2007, 11:42 AM] I don't know if you realize it, but Turkey is bombing the crap out of Northern Iraq, as we 'speak', softening them up for the invasion - at which point, the Kurds are gonna be stomped out of existence via ground troops, already amassed at the border.

    Yep! This is going to be interesting...
    No comment[s]?

    http://www.foxnews.com/story/0,2933,301821,00.html

    Kinda scary how I know this stuff, huh?
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  14. #14
    Loyal Client
    Join Date
    Sep 2006
    Posts
    143
    kind of curious how this is related to my question LOL

  15. #15
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Sometimes meaningless distractions are helpful to the creative process...
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

Page 1 of 4 1234 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •