Subject: Re: syslog and chroot
To: Michael Richardson <mcr@sandelman.ottawa.on.ca>
From: Jukka Marin <jmarin@pyy.jmp.fi>
List: tech-security
Date: 08/17/1997 10:03:55
On Sat, Aug 16, 1997 at 05:08:21PM -0400, Michael Richardson wrote:
>   What is wrong with syslog:
> 	1. accepts spam from other nodes. Bad guy fills your logs.

>         3. datagram sockets are not reliable. If you run out of mbufs
> 	(obviously bad) you would expect to lose logging.

Yep.  But I still want to be able to log on other machines over the
network.  How could this be done more securely (and without losing
any log events during the moments that the network is down)?  How do
other people do this?

  -jm


-- 

                       1503 kHz @ 22:30 EET DST Mon-Fri

                     ---> http://www.jmp.fi/~jmarin/ <---