linux based terminal key logger?

Issues related to applications and software problems
Post Reply
dkoleary
Posts: 51
Joined: 2013/01/07 19:18:14
Contact:

linux based terminal key logger?

Post by dkoleary » 2013/10/08 17:01:16

Hey;

I have a client who's interested in monitoring access to and activity in sensitive accounts (application admin accounts, root, etc). One idea I had was to put a key logger on a centralized system that'll be used to ssh into these accounts. Googling keylogger keeps popping up lkl, though, and that seems to be for the physical keyboard only... and, somewhat suspect even with that. The client has a need to monitor this activity due to HIPAA and PCI rules/regs. Requiring sudo for every command is an ugly option as it's straight single factor authentication and really limits flexibility on automating tasks.

Does anyone know of a key logger that'll log ptys? Extra helping of eternal gratitude if it can filter logging based on commands entered... (don't really care user A does on the mgmt server as himself. only care if he access oracle@prod_db_server)

thanks for any hints/tips/suggestions.

Doug

moonpup
Posts: 118
Joined: 2008/11/20 20:38:18

Re: linux based terminal key logger?

Post by moonpup » 2013/10/09 00:40:30

If they can afford it, this commercial product is good although it may be a bit overkill.

http://www.beyondtrust.com/Products/PowerBrokerUnixLinux/

pjwelsh
Posts: 2632
Joined: 2007/01/07 02:18:02
Location: Central IL USA

Re: linux based terminal key logger?

Post by pjwelsh » 2013/10/09 16:14:20

[url=http://www.tridia.com/]Tridia[/url] has a product called [url=http://www.tridia.com/doublevision/]DoubVision Pro[/url] that we have used on Unix systems for years... for a price...

Guest

Re: linux based terminal key logger?

Post by Guest » 2013/10/29 07:51:00

Maybe you can try this keylogger which is designed for Linux :http://sourceforge.net/projects/lkl/ , I can't comment with it, because I didn't use this before.

[Moderator edited to remove a link to a commercial product for [i]Windows[/i] systems.]

Post Reply