Post by Philip Hallstro

Hi all -
        I've just decided that I want to automate a lot of my daily chores
(monitoring log files/disk space, etc...) and would like some tools to
handle it for me.  I had a couple of adhoc scripts that did some of it,
but there must be some better tools out there (that I wouldn't have to
write :).  I took a quick glance at COPS and Watcher and they look like
they would do the trick.  I've also heard of, but never played with
        Any and all comments, on the above programs or other programs that
do similar things would be greatly appreciated.  I'm primarily interested
in monitoring disk space, logins, various log files, etc...  What would be
really cool is a program that "learned" users login behaviours and would
notify me when the deviate from it (ie. joeuser tends to login b/n 8-5
from these machines, but today he logged in at 3am from this host in
germany, type of thing)

If there's interest I'll summarize any comments I receive.


Philip Hallstrom                 Sierra Online Services


1. Shambler - A Firewall trap/tool (security tool)


                  The Shambler Version 1.0b
                    A Firewall Tool/Trap

   The shambler is a small program that is periodicly run on firewalls.  The
shambler uses it's config file to get a list of valid user IDs and then cruises
the process table looking for UIDs that are not explicitly allowed.  If any
user's are found that are not allowed, the event is logged, and all the
offending process are killed. -Zap- Normally Shambler would be run periodically
via cron.  Shambler is written in straight C, so is portable that way, but DOES
depend on the /proc filesystem to do it's thing.

Expect a Solaris version soon.

   This is BETA software, so use at your own risk, and please notify me if you
have any comments or questions.  The production version will be included in a
soon to be announced firewall package called "Wild Weasel", which will be
available for beta soon.

Shambler is Available at*
          and should move to /pub/Linux/system/misc ?

Please send comments and questions to:


