--- acl.conf.pius Thu Jan 6 17:00:30 2000 +++ acl.conf Thu Jan 20 21:35:26 2000 @@ -43,9 +43,10 @@ Service, identd, normal Service, ftpd, BrightGreen : Note this also does tftpd Service, named, BrightCyan -Service, PAM_pwdb, BrightMagenta +Service, PAM_unix, BrightMagenta Service, login, BrightYellow Service, telnetd, Yellow +Service, inetd, Yellow Service, snort, BrightRed @@ -63,10 +64,11 @@ : More alert stuff we want to highlight -BackgroundBrightYellow,Authentication failure +BackgroundBrightYellow,uthentication failure BackgroundBrightYellow,FAILED LOGIN : telnetd BackgroundBrightYellow,failed login : ftpd BeepBlinkingBackgroundBrightYellow,repeated login failures : ftpd +BrightRed,inetd,warning : Further down the chain are these messages we don't want to miss. @@ -92,13 +94,13 @@ BackgroundWhite,modprobe -: PAM_pwdb stuff +: PAM_unix stuff Hide,(su),for user nobody : Ignore `su nobody` -:BackgroundMagenta,PAM_pwdb,(su),opened : `su nobody` already fell out -BackgroundMagenta,PAM_pwdb,opened -:Magenta,PAM_pwdb,(su) -Magenta,PAM_pwdb,closed -BrightMagenta,PAM_pwdb : Everything else - passwd changes, +:BackgroundMagenta,PAM_unix,(su),opened : `su nobody` already fell out +BackgroundMagenta,PAM_unix,opened +:Magenta,PAM_unix,(su) +Magenta,PAM_unix,closed +BrightMagenta,PAM_unix : Everything else - passwd changes, : auth failures, unforeseen things