-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Aug 16, 2010, at 6:23 PM, jplee3 wrote:
> Hi all,
> 
> Just wondering if OSSEC has the ability to capture all commands run
> after sudoing or su'ing to root (or another privileged user, etc).

I think this is outside of the scope of ossec..  Sudo itself doesn't log that 
information (at least, not by default), and it doesn't appear in the audit.log 
either..

- ---------------------------
Jason 'XenoPhage' Frisvold
[email protected]
- ---------------------------
"Any sufficiently advanced magic is indistinguishable from technology."
- - Niven's Inverse of Clarke's Third Law



-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.14 (Darwin)

iEYEARECAAYFAkxsRCEACgkQ8CjzPZyTUTRHuQCfYPs8sJoIj5697P279vOlfjKZ
klAAoJqD2WvSSdFgP4nlIdSfKbvmkt8N
=okLD
-----END PGP SIGNATURE-----

Reply via email to