Image

Imagefallenairmen wrote in Imagelinux

Audit tool suggestions

I have 3-4 machines that are money producers for a client, the previous admin/dev quit and left them high and dry with only a 10 day notice.  I have no idea about anything with these machines except their very badly configured.  Today, the one machine recieved 3362 UNIQUE attempts against SSHD.  My lead is setting up iptables and I am installing denyHosts, but in the meantime I'd like some sort of audit record so I can start digging into how the other services are setup and what user accounts exist.   Preferably the tool would run from local, ssh into the machines, record information like uname, /etc/*, iptables, passwd, and anything else.  Yeah I can do all this manually, but there are other mini-sites in the companies portfolio as well so automation would be nice.