Re: syslog fra remote host

From: Michael Lyngbøl (none@michael--lyngbol.dk.lh.bsd-dk.dk)
Date: Fri 04 Jun 2004 - 19:53:05 CEST


Date: Fri, 4 Jun 2004 19:53:05 +0200
From: Michael Lyngbøl <none@michael--lyngbol.dk.lh.bsd-dk.dk>
To: bsd-dk@bsd-dk.dk
Subject: Re: syslog fra remote host

On 04.06.2004 18:59:55 +0000, Morten Winther wrote:
> Michael Knudsen wrote:
>
> >Har du husket at sige, at den gerne maa modtage log fra netvaerket?
> >
> > -u Select the historical ``insecure'' mode, in which
> > syslogd will accept input from the UDP port. Some software
> > wants this, but you can be subjected to a variety of attacks
> > over the network, including attackers remotely filling logs.
> >
> >Ovenstaaende stammer fra OpenBSD's syslogd, der altid aabner en socket,
> >da denne ogsaa skal bruges, hvis man skal _sende_ logs.
>
> Glemte at skrive jeg bruger FreeBSD som ikke har den option

Default er '-s' option til syslogd.

lyngbol@freesbee$ grep syslogd_flags /etc/defaults/rc.conf
syslogd_flags="-s" # Flags to syslogd (if enabled).

     -s Operate in secure mode. Do not log messages from remote
             machines. If specified twice, no network socket will be opened
             at all, which also disables logging to remote machines.

syslogd_flags="" i /etc/rc.conf

/Michael

-- 
Michael Lyngbøl -- michael at lyngbol dot dk
Network Architect, AS3292 TDC, IP·backbone



This archive was generated by hypermail 2b30 : Wed 15 Nov 2006 - 18:24:41 CET