<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to prevent a Splunk forwarder from passing passwords from auditd? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200894#M39682</link>
    <description>&lt;P&gt;&lt;CODE&gt;source = auditd sourcetype = auditd&lt;/CODE&gt; suggests there are two ways the forwarder is ingesting the audit logs - the file is fine, but it's getting the info from somewhere else as well.&lt;/P&gt;

&lt;P&gt;What inputs have you deployed onto the forwarder besides the file monitors listed above?&lt;/P&gt;</description>
    <pubDate>Mon, 01 Aug 2016 16:32:22 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2016-08-01T16:32:22Z</dc:date>
    <item>
      <title>How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200886#M39674</link>
      <description>&lt;P&gt;I've got a Splunk forwarder installed on a server.  This server is also logging its commands via auditd.  &lt;/P&gt;

&lt;P&gt;When I do something like &lt;CODE&gt;sudo su -&lt;/CODE&gt;, auditd captures the output, but doesn't expose passwords.  An example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;type=USER_AUTH msg=audit(1469642237.076:4664554): user pid=29165 uid=565 auid=565 ses=225532 msg='op=PAM:authentication acct="ME" exe="/usr/bin/sudo" hostname=? addr=? terminal=/dev/pts/14 res=failed'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, the Splunk forwarder gives much more information, including the password you type on the command line.  This is a pretty straight forward install of the forwarder - no fancy stuff going on.   How can I use the Splunk forwarder without exposing users' passwords, like auditd does?&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 22:46:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200886#M39674</guid>
      <dc:creator>gregcain</dc:creator>
      <dc:date>2016-07-29T22:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200887#M39675</link>
      <description>&lt;P&gt;The forwarder likely isn't collecting the password itself, instead it's reading log files. I'd check what log files the forwarder is configured to read, and manually check for passwords in those. Then configure whatever's writing those log files to not log passwords.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 23:03:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200887#M39675</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-07-29T23:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200888#M39676</link>
      <description>&lt;P&gt;gregcain, keep in mind please that there is a Splunk app called &lt;A href="https://splunkbase.splunk.com/app/2642/"&gt;Linux Auditd&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I wonder whether this app handles the data streaming as well...&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2016 17:10:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200888#M39676</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-07-31T17:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200889#M39677</link>
      <description>&lt;P&gt;That's the behavior I expected, but the audits logs have the sensitive information removed, whereas the splunk logs have it.  I couldn't find a log file on the server that had the sensitive information.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2016 20:52:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200889#M39677</guid>
      <dc:creator>gregcain</dc:creator>
      <dc:date>2016-07-31T20:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200890#M39678</link>
      <description>&lt;P&gt;If there is no log file with that information, where is the forwarder reading it from?&lt;BR /&gt;
Check its input configuration with &lt;CODE&gt;splunk list monitor&lt;/CODE&gt; on the command line. Any information the forwarder is forwarding must have been read from such a file. (plus other types of input such as scripts, network, etc)&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2016 20:57:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200890#M39678</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-07-31T20:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200891#M39679</link>
      <description>&lt;P&gt;This is what I've got:&lt;/P&gt;

&lt;P&gt;splunk list monitor&lt;BR /&gt;
Monitored Directories:&lt;BR /&gt;
                [No directories monitored.]&lt;BR /&gt;
Monitored Files:&lt;BR /&gt;
        /etc&lt;BR /&gt;
        /Library/Logs&lt;BR /&gt;
        /opt/secret-directory/aide/reports/ro/&lt;BR /&gt;
        /var/adm&lt;BR /&gt;
        /var/log&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 15:45:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200891#M39679</guid>
      <dc:creator>gregcain</dc:creator>
      <dc:date>2016-08-01T15:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200892#M39680</link>
      <description>&lt;P&gt;I am aware of that splunk app, but we don't have it installed.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 16:05:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200892#M39680</guid>
      <dc:creator>gregcain</dc:creator>
      <dc:date>2016-08-01T16:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200893#M39681</link>
      <description>&lt;P&gt;When I see passwords, I have:&lt;/P&gt;

&lt;P&gt;host = MYHOST source = auditd sourcetype = auditd&lt;/P&gt;

&lt;P&gt;When I don't see passwords, I have:&lt;/P&gt;

&lt;P&gt;host = MYHOST  source = /var/log/audit/audit.log sourcetype = linux_audit&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 16:08:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200893#M39681</guid>
      <dc:creator>gregcain</dc:creator>
      <dc:date>2016-08-01T16:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200894#M39682</link>
      <description>&lt;P&gt;&lt;CODE&gt;source = auditd sourcetype = auditd&lt;/CODE&gt; suggests there are two ways the forwarder is ingesting the audit logs - the file is fine, but it's getting the info from somewhere else as well.&lt;/P&gt;

&lt;P&gt;What inputs have you deployed onto the forwarder besides the file monitors listed above?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 16:32:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200894#M39682</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-08-01T16:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200895#M39683</link>
      <description>&lt;P&gt;Under data inputs &amp;gt;&amp;gt; scripts, I have one script with a sourcetype of auditd.  It is part of the Splunk Add-on for Unix and Linux, and lives under /opt/splunk/etc/apps/Splunk_TA_nix/bin/rlog.sh.&lt;/P&gt;

&lt;P&gt;That script has a SEEK_FILE that looks interesting, but it doesn't exist.  &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:29:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200895#M39683</guid>
      <dc:creator>gregcain</dc:creator>
      <dc:date>2020-09-29T10:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200896#M39684</link>
      <description>&lt;P&gt;What does an event with a password look like? (password censored, of course)&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 17:31:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200896#M39684</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-08-01T17:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200897#M39685</link>
      <description>&lt;P&gt;type=TTY msg=audit(07/27/2016 11:05:22.357:4664859) : tty pid=31096 uid=ME auid=ME ses=225532 major=136 minor=14 comm=ssh data="sudo su -",,"PASSWORD",,"PASSWORD",,"PASSWORD",,,,"PASSWORD",,"cd /var/log",,"ls -l",,"ls -l btmp",,"mkdi",,,,,"touch btmp",,"chown 6000",,,,,"root:utmp btmp",,"chmod 600 btmp",,"ls -l btmp",,"lastb",,"su - alkjadfkljasd",,"lasb",,"tb",,"lastb",,"exit",,&amp;lt;^D&amp;gt;&lt;BR /&gt;
host = MYHOST source = auditd sourcetype = auditd&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 18:41:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200897#M39685</guid>
      <dc:creator>gregcain</dc:creator>
      <dc:date>2016-08-01T18:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200898#M39686</link>
      <description>&lt;P&gt;Ah, I see. Let me guess - you also find events for &lt;CODE&gt;sourcetype=linux_audit type=TTY&lt;/CODE&gt;, but the data field is a bunch of hex code? (please don't post that hex uncensored!)&lt;/P&gt;

&lt;P&gt;If so, your linux_audit also contains passwords - just as hex-encoded ascii. As a corollary, your /var/log/audit/audit.log also contains virtually-plaintext passwords.&lt;BR /&gt;
The difference between the two? The rlog.sh script you mentioned pipes the events through ausearch which decodes the hex-encoded ascii back into actual ascii.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 18:51:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200898#M39686</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-08-01T18:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200899#M39687</link>
      <description>&lt;P&gt;Hey, you're exactly right.  So the finger is pointed directly at the auditd on MYHOST.    &lt;/P&gt;

&lt;P&gt;This appears to be the intended behavior of the rlog.sh script, so I expect it's auditd that's mis-configured.  &lt;/P&gt;

&lt;P&gt;Thanks again for your help.  I'm off to fix auditd.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 19:30:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200899#M39687</guid>
      <dc:creator>gregcain</dc:creator>
      <dc:date>2016-08-01T19:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200900#M39688</link>
      <description>&lt;P&gt;\o/ would have been weird for the forwarder to make up correct passwords... take a very good look at your auditd, afaik TTY-logging doesn't log sudo passwords.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 20:18:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200900#M39688</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-08-01T20:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200901#M39689</link>
      <description>&lt;P&gt;&lt;A href="https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Security_Guide/sec-Configuring_PAM_for_Auditing.html"&gt;https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Security_Guide/sec-Configuring_PAM_for_Auditing.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2016 11:32:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200901#M39689</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2016-08-02T11:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200902#M39690</link>
      <description>&lt;P&gt;Thanks for this.  It was exactly what I needed.  This forum, and redhat support, came in with a virtual tie for the solution.  Kudos.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2016 15:31:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200902#M39690</guid>
      <dc:creator>gregcain</dc:creator>
      <dc:date>2016-08-02T15:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200903#M39691</link>
      <description>&lt;P&gt;The problem ended up being this line added to /etc/pam.d/sshd&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;session required pam_tty_audit.so enable=*&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Removing that line fixed the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:30:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200903#M39691</guid>
      <dc:creator>gregcain</dc:creator>
      <dc:date>2020-09-29T10:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200904#M39692</link>
      <description>&lt;P&gt;Let's rerun that race with an actually splunk-related question and see how the wrongly-coloured-hat people do &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2016 16:35:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200904#M39692</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-08-02T16:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent a Splunk forwarder from passing passwords from auditd?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200905#M39693</link>
      <description>&lt;P&gt;hi,&lt;BR /&gt;
I did re-configure the auditd, by removing the log_passwd from the /etc/pam.d/system-auth. Still from "ausearch -i" displays the plain text password.&lt;BR /&gt;
How it be avoided, kindly suggest.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Apr 2020 15:36:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-a-Splunk-forwarder-from-passing-passwords-from/m-p/200905#M39693</guid>
      <dc:creator>kudhawan</dc:creator>
      <dc:date>2020-04-04T15:36:41Z</dc:date>
    </item>
  </channel>
</rss>

