Subject: Re: syslog and chroot
To: None <jmarin@pyy.jmp.fi>
From: Mike Long <mikel@shore.net>
List: tech-security
Date: 08/18/1997 11:13:21
>Date: Sun, 17 Aug 1997 10:03:55 +0300
>From: Jukka Marin <jmarin@pyy.jmp.fi>
>References: <Pine.NEB.3.93.970816122328.16204E-100000@gnostic.cynic.net> <199708162108.RAA00596@morden.sandelman.ottawa.on.ca>
>
>On Sat, Aug 16, 1997 at 05:08:21PM -0400, Michael Richardson wrote:
>>   What is wrong with syslog:
>> 	1. accepts spam from other nodes. Bad guy fills your logs.
>
>>         3. datagram sockets are not reliable. If you run out of mbufs
>> 	(obviously bad) you would expect to lose logging.
>
>Yep.  But I still want to be able to log on other machines over the
>network.  How could this be done more securely (and without losing
>any log events during the moments that the network is down)?  How do
>other people do this?

libwrap support will fix problem (1).
-- 
Mike Long <mikel@shore.net>                http://www.shore.net/~mikel
"Every normal man must be tempted at times to spit on his hands,
hoist the black flag, and begin slitting throats." -- H.L. Mencken