OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: [RFC] environment sanitisation wrapper
From: John Flux (johntmsp.screaming.net)
Date: Wed May 31 2000 - 09:53:24 CDT


On Wed, 31 May 2000, you wrote:
.....

> secure-syslog
> The major problem with syslog however is that tampering with log files is
> trivial (setting the log files append only with "chattr +a" helps, but if an
> attacker gains root, they can unset the attribute).

I was thinking how to slow down a cracker - assuming they have root - from
deleteing logs....
I could delete the chattr file - but then they could upload a new version or
just write it in c....
can I disable modification of the attributes at a kernel level?
I could for personal use just hook the call and look for specific files then
fail the call... - but much as I love kludging, thats otp ...

 --
Children are unpredictable. You never know what inconsistency they're
going to catch you in next.
                -- Franklin P. Jones