Audit tool suggestions
I have 3-4 machines that are money producers for a client, the previous admin/dev quit and left them high and dry with only a 10 day notice. I have no idea about anything with these machines except their very badly configured. Today, the one machine recieved 3362 UNIQUE attempts against SSHD. My lead is setting up iptables and I am installing denyHosts, but in the meantime I'd like some sort of audit record so I can start digging into how the other services are setup and what user accounts exist. Preferably the tool would run from local, ssh into the machines, record information like uname, /etc/*, iptables, passwd, and anything else. Yeah I can do all this manually, but there are other mini-sites in the companies portfolio as well so automation would be nice.
