Posting successful SSH logins to Slack
sandrinodimattia.net
sandrinodimattia.net
I mean the next step is to have an automated phone call go out to people (which is what we do for critical alerts).
Short of that, slack is on my desktop, laptop, and phone. If i don't have one of those around me at the time, you aren't getting ahold of me for any reason.
So yeah i think it's perfectly valid for security-critical notifications. Plus this isn't as security critical as you'd think. I don't want klaxons going off every time someone sshs into a server... This can just be an additional layer of security.
Nobody is selling IRC.
>We're sorry but Grove isn't currently accepting new customers right now.
I guess with that pricing structure they don't need to.
* File uploads
* Embedding portions of links (tweets, images)
* A very good search
* Multi-line posts
* Code-formatting, including multi-line posts, and also snippets.
* A mobile client that alerts you when someone mentions you.
* Scroll-back history when you sign on at any time.
* Syncing between multiple clients.
Yes, you could create a bot or modify an irc server to do this, and then find or write a client that will do all that stuff, and an irc bouncer can fill in for a lot of this.
But Slack does it out of the box. Zero extra work needed.
I like IRC, but if you claim that Slack doesn't offer anything more than IRC, you're either delusional or using an incredibly broad definition of IRC.
Yes.
echo "`whoami` logged in at `date` from `echo $SSH_CLIENT`" | mail -s "`hostname` login" youremail@example.com
Note that people can still ssh execute remotely etc.
This post explains how to set it up:
https://blog.sucuri.net/2016/01/server-security-integrating-...
ip=`echo $SSH_CONNECTION | cut -d " " -f 1`
curl -X POST --data-urlencode 'payload={"channel": "#<your channel>", "username": "SSH Login watcher", "text": "User '${USER}' just logged in from '${ip}'", "icon_emoji": ":robot_face:"}' https://hooks.slack.com/services/<rest of the webhook>
If you start overriding DND, now the user is going to want super-DND. Which somebody will then want to override, and so on. The correct solution is that your users need to not set DND when they in fact need to be disturbed, and your systems shouldn't be disturbing unnecessarily, and to the extent that's a really hard problem, well, yes, it very much is, but an unboundedly-large hierarchy of "bother that person, no don't bother me, SUPER bother that person, no SUPER don't bother me, SUPER MEGA bother that person" isn't part of the solution set.
This caused more than a few missed announcements and made escalation hard for a bit.
# Adapted from https://unix.stackexchange.com/questions/207813/how-to-log-every-command-typed-into-bash-and-every-file-operation
export ETERNAL_AUDIT_LOGFILE=~/.bash_eternal_auditlog
PROMPT_COMMAND='RET_VAL=$?; history -a; echo "$(who am i | sed -e "s/[[:space:]]\+/ /g") [$$]: $(history 1 | sed "s/^[ ]*[0-9]\+[ ]*//" ) [$RET_VAL]" >> $ETERNAL_AUDIT_LOGFILE'
Output including return code and all parameters: ubuntu pts/0 2016-01-22 13:24 (example-loggedinuser-rdns.yourisp.com) [4379]: [2016-01-22 13:25:37] ps aux | grep python [0]
If you assume no malicious users this will work just fine.If you are interested in a commercial solution in this space, check out ScaleFT. Besides the dynamic SSH certificates, we also track both SSH keys used and access events, which you can then pull via an API across all your machines. We also have a Slack notifier, though It needs a little love & cleanup.
We're currently in what I could best call a beta: https://www.scaleft.com/
Micromanagement at its finest!
> it's just good to know what sort of general administration is being done.
Your change management process will give you an overview of what your admins are doing.
And yes a change management process is very nice and all, and I suppose that at Amazon no line is entered into a root sshd shell without each character being vetted thrice, but at your regular shop you can bet that there's loads of admins that type "ps aux" three times before getting it right. Not that that's terrible, but if you want to look at system administration as an engineering problem you have to know what's going on.
But that's getting into no-man's land I guess
Ever accidentally typed your sudo password at the wrong prompt?
You could run your own IRC or Mattermost server accessible only in your LAN or over VPN and this would be fairly safe. Heck, even SSL-only with cranked up SSL options would be fairly safe.
Instead, people ship all their data off to a 3rd party company, often letting that 3rd party have control over their servers and such. Their customer data, their payment data, even code exec on all their servers is exposed and out of their control.
It's insanity, I can't believe people have so little regard for security. Especially with a 3rd party company with a less-than-great security record.
https://blog.sucuri.net/2016/01/server-security-integrating-...