atom feed19 messages in org.freebsd.freebsd-securityRe: Parent Logging Patch for sh(1)
FromSent OnAttachments
Omachonu OgaliJan 16, 2000 10:04 am 
Will AndrewsJan 16, 2000 12:03 pm 
Omachonu OgaliJan 16, 2000 2:10 pm 
Will AndrewsJan 16, 2000 2:29 pm 
Omachonu OgaliJan 16, 2000 3:11 pm 
Sheldon HearnJan 17, 2000 2:57 am 
AdamJan 17, 2000 12:47 pm 
Omachonu OgaliJan 17, 2000 6:03 pm 
Keith StevensonJan 17, 2000 8:20 pm 
Michael RobinsonJan 17, 2000 9:24 pm 
Sheldon HearnJan 17, 2000 10:09 pm 
Omachonu OgaliJan 18, 2000 4:02 am 
Sheldon HearnJan 18, 2000 4:20 am 
Omachonu OgaliJan 18, 2000 7:35 am 
Cy Schubert - ITSD Open Systems GroupJan 18, 2000 8:04 am 
Omachonu OgaliJan 18, 2000 8:15 am 
Sheldon HearnJan 18, 2000 12:14 pm 
Cy SchubertJan 18, 2000 1:42 pm 
Robert WatsonJan 18, 2000 3:59 pm 
Subject:Re: Parent Logging Patch for sh(1)
From:Michael Robinson (robi@netrinsics.com)
Date:Jan 17, 2000 9:24:55 pm
List:org.freebsd.freebsd-security

Keith Stevenson <k.st@louisville.edu> writes:

However in the case of a root compromise all local logs are useless since they may have been altered by the attacker. (After all, they can't _all_ be script kidz.)

That would be the case for logs that don't have the sappnd flag set.

You *do* set the sappnd flag on your security-related logfiles, don't you?

To Unsubscribe: send mail to majo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message