[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: masking out invalid root logins with logcheck?



On Mon, May 08, 2006 at 09:06:37PM +0200, Emanuele Rocca wrote:
The only situation I've been able to imagine is a human error leading to
a change to your security policy.

For instance, a co-worker which temporary allows remote root logins, god
knows why. I'd be sad of my choice of filtering out root login attempts
in that case.

If this configuration error happened and root logins were suddenly allowed, it would be less effective to focus on a reduction in failed root logins than on the sudden presence of successful root logins.

Mike Stone



Reply to: