Howto monitor system security

Sergei Gnezdov use-reply-to at nofrom.not
Sun Mar 13 13:59:59 PST 2005


Sorry, it is a rather generic message, but the problem is a generic as
well.

I am running my FreeBSD machine on DMZ.  I use ipfw and I expose http
and smtp ports.  I also expose sshd port, but only to a trusted
network (work).  I'd like to know what is the best way to monitor my
machine security.

FreeBSD security email is rather anoying, because it keeps sending
messages even if nothing has changed.  I need an email sent to me only
if there is something abnormal.

For example, I'd like to know if there is a significant change in
network activity.  My mailserver might be hijacked and is sending
spam.

I am running snort, but most of the time it simply reports MySQL warm
attempts.

Is there a log to see messages sent by sendmail?



More information about the freebsd-questions mailing list