Re: [suse-security] Trace user logins in SAMBA
My knowledge is somewhat sketchy and from Samba 2.2.1a so forgive me if it's no use. My crude understanding is that a login to a domain from a Windows box isn't quite like a unix log in, what you're doing is logging on to the *Windows* box and Windows is asking the unix (samba) domain server whether the user has permission to log on locally. Later the user will probably start to use shared network resources (shared drives, etc.) from the unix box and these requests will then start a "session" (in SMB terminology) from that user on that Windows box to that share - these "sessions" are the things that are easy to see on the STATUS page of SWAT* or using smbstatus. But I doubt that's what you want to see. After all, a user could log on and never use network shared resources in theory. The samba log files (eek! - not sure where they've gone! used to be in /var/lock/samba/log.nmbd think they are now in /var/log/samba/) will record what the smbd daemon is doing so somewhere in there there should be some unique kind of SMB message received that corresponds to a domain logon request. Unfortunately I'm not an SMB protocol expert so I couldn't tell you the exact call! The loglevel parameter increases the amount of logging. At 3 you get a log of stuff, probably more than enough. Remember you'll probably need to restart the smbd daemon to make it pick up the change to the loglevel in smb.conf (YMMV). Good luck! Carl *SWAT, if you haven't used it before, is an invaluable tool. It usually comes as part of the samba package (in the rpm) and will probably already be installed. You may need to modify inetd.conf to get it to run. Basically it listens to HTTP requests on port 901. The upshot of this is that you can administer your samba server remotely using a web browser, see who's using what shares, change configuration, restart the servers, etc. Plus view lots of help online!
From: João Reis <joao.reis@2000comp.pt> To: suse-linux-e@suse.com, suse-security@suse.com Subject: [suse-security] Trace user logins in SAMBA Date: Tue, 04 Nov 2003 10:32:25 +0000
Hi to all
I have read a lot of documentation but i cannot find a way to track user logins, from a Windows machine, in Samba. Does the log parameter in the smb.conf file does the job. I have the log files of the machines present (log.%m) but they do not register the time when the users login and logout.
is there a way to register this information?
Thanks
-- \|/ "Do or do not. There is no try" - Yoda \|/ |==============================================| | 2000Comp - Consultoria e Informática, Lda | | Tel: +351 22 941 99 32 | \|/ | Fax: +351 22 941 99 34 | \|/ O | www: http://www.2000comp.pt | O -|--| |--|- \| | João Reis | |/ / \ |==============================================| / \ ==========================================================
-- Check the headers for your unsubscription address For additional commands, e-mail: suse-security-help@suse.com Security-related bug reports go to security@suse.de, not here
_________________________________________________________________ Hotmail messages direct to your mobile phone http://www.msn.co.uk/msnmobile
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Tuesday 04 November 2003 13:10, J J wrote:
My knowledge is somewhat sketchy and from Samba 2.2.1a so forgive me if it's no use.
<snip> Entering this "log file = /var/log/%m.log" in the smb.log this make for each indivual Windoze machine a log. When someone logs in from that machine you should find this information [2003/03/04 18:02:45, 1] smbd/service.c:make_connection(615) xxxx (192.168.100.4) connect to service netlogon as user xxxx (uid=502, gid=100) (pid 24501) And that is at log level = 1 Ian - -- A child of five would understand this. Send someone to fetch a child of five. Groucho Marx - ---------------------------------------------------- This mail has been scanned for virus by AntiVir for UNIX Copyright (C) 1994-2003 by H+BEDV Datentechnik GmbH. PGP ID: 589F8449 Fingerprint: EB1C FACF 6BEB 540E 8AC0 F04E 2A25 A2F1 589F 8449 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQE/p+5wKiWi8VifhEkRAiLUAKCLk7F1B9CMqfBjqs7gmrqw7rB2ggCeI6cx ME6JymmNzT/bkKSXKderoCg= =Wlvx -----END PGP SIGNATURE-----
Hi Pals Yahoo Messenger works fine with Linux Suse 8.0. Just download the file RedHat 7.x(8d6ebad8eee0260ef9f53a535ced5f68) and Install it as intructed and finally from your X window run ymessenger.. Voila you will in chat with your pals..the other version of RedHat will not work with Suse 8.0 but this one works perfect. Rgds Drew ________________________________________________________________________ BT Yahoo! Broadband - Save £80 when you order online today. Hurry! Offer ends 21st December 2003. The way the internet was meant to be. http://uk.rd.yahoo.com/evt=21064/*http://btyahoo.yahoo.co.uk
Hi Everyone, I am new to this list. I just wanted to point out that the Yahoo messenger version for RedHat 9.0 available on yahoo's web site works on Suse Linux Pro 8.2. That is if some one is interested in using it on that version. Thanks George --- Andrew dACHI <andrewadk@yahoo.co.uk> wrote:
Hi Pals
Yahoo Messenger works fine with Linux Suse 8.0. Just download the file RedHat 7.x(8d6ebad8eee0260ef9f53a535ced5f68) and Install it as intructed and finally from your X window run ymessenger.. Voila you will in chat with your pals..the other version of RedHat will not work with Suse 8.0 but this one works perfect.
Rgds Drew
________________________________________________________________________
BT Yahoo! Broadband - Save �80 when you order online today. Hurry! Offer ends 21st December 2003. The way the internet was meant to be.
http://uk.rd.yahoo.com/evt=21064/*http://btyahoo.yahoo.co.uk
-- Check the headers for your unsubscription address For additional commands, e-mail: suse-security-help@suse.com Security-related bug reports go to security@suse.de, not here
__________________________________ Do you Yahoo!? New Yahoo! Photos - easier uploading and sharing. http://photos.yahoo.com/
Am Mittwoch, 10. Dezember 2003 18:43 schrieb George Stoianov:
Hi Everyone,
I am new to this list. I just wanted to point out that
I want to point out that this list is "suse-security", not "spam-me-silly". Now, please explain how the fact that some program made for some linux distribution also works on some other linux distribution is related to anything security. You have 15 minutes. Do not write more than 300 words. bye, MH
participants (5)
-
Andrew dACHI
-
George Stoianov
-
Ian David Laws
-
J J
-
Mathias Homann