OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: chroot question: Hardlinks or softlinks

From: Luca Berra (blucacomedia.it)
Date: Tue Dec 02 2003 - 03:54:36 CST


On Tue, Dec 02, 2003 at 10:35:55AM +0100, Ralf Hildebrandt wrote:
>* Luca Berra <blucacomedia.it>:
>
>> Btw iirc postfix daemons open a socket to syslog before chrooting.
>
>But if you restart syslogd, you lose that (along with nqmgr logging!),
>unless you also restart postfix.
>
uhm, right, i'll have to rework my chroot script for that
occurrence :(

we remain with the hope that a decent syslogd implementation should not
be attackable via the socket. i tend to replace syslogd with syslog-ng
if i can.

L.

--
Luca Berra -- blucacomedia.it
        Communication Media & Services S.r.l.
 /"\
 \ / ASCII RIBBON CAMPAIGN
  X AGAINST HTML MAIL
 / \