Bug in all versions of OpenSSH

Austin Gonyou austin at coremetrics.com
Tue Apr 9 08:17:15 EST 2002


What? You don't have a syslog server? You don't log /var/log/messages,
/var/log/syslog, or /var/adm/messages to a remote syslog host or DB and
watch for incidents?

umm...in that case, you seem to be defeating your OWN security.
On Sat, 2002-04-06 at 10:55, Markus Friedl wrote:
> On Fri, Apr 05, 2002 at 03:37:14PM -0800, Dan Kaminsky wrote:
> > As is, it's sort of embarassing that I can evade basic system logs so
> > easily.
> 
-- 
Austin Gonyou
Systems Architect, CCNA
Coremetrics, Inc.
Phone: 512-698-7250
email: austin at coremetrics.com

"It is the part of a good shepherd to shear his flock, not to skin it."
Latin Proverb
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 232 bytes
Desc: This is a digitally signed message part
Url : http://lists.mindrot.org/pipermail/openssh-unix-dev/attachments/20020408/6c7cd680/attachment.bin 


More information about the openssh-unix-dev mailing list