OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [suse-security] SuSE Security Announcement: cups (SuSE-SA:2003:028)

From: Dirk Mueller (dmuellgmx.net)
Date: Fri Jun 06 2003 - 15:35:22 CDT


On Fre, 06 Jun 2003, Dirk Schreiner wrote:

> The crash of syslogd can be detected by Management Tools,
> so that the Administrator can react.

I don't buy this. every crash is a bug, and a crash of an important daemon
even more.

> Otherwise, there might be the ability to hide hacking by
> making files _not_ writable.

When an attacker can make log files not writeable its too late anyway.

> If you want to change this, try out treating the files
> as pipes ( put a | in front of the Filename )

Doesn't work for me.

--
Dirk

--
Check the headers for your unsubscription address
For additional commands, e-mail: suse-security-helpsuse.com
Security-related bug reports go to securitysuse.de, not here