avatar
g*s
1
【 以下文字转载自 Linux 讨论区 】
【 原文由 GTS 所发表 】
Design such a logging facility for an open system
such as Linux.
Assume that the attacker's penetration will be logged,
but the attacker will then have root privilege.
How do we ensure that the attacker cannot
then modify the log without the admin detecting that?
多谢多谢
avatar
p*e
2
不知道这样回答对不对?
如果你设置成让root只从console登陆, 其他的登陆只有su权限, 是不是可以?

【在 g*s 的大作中提到】
: 【 以下文字转载自 Linux 讨论区 】
: 【 原文由 GTS 所发表 】
: Design such a logging facility for an open system
: such as Linux.
: Assume that the attacker's penetration will be logged,
: but the attacker will then have root privilege.
: How do we ensure that the attacker cannot
: then modify the log without the admin detecting that?
: 多谢多谢

avatar
p*f
3

no, hackers can get root shell without logon or su, they can overflow
server deamons from remote, or SUID progrom with local access.

【在 p**e 的大作中提到】
: 不知道这样回答对不对?
: 如果你设置成让root只从console登陆, 其他的登陆只有su权限, 是不是可以?

avatar
j*y
4
use a printer to print out the log in real time by configuring the
output file to the printer.
or use a serial cable to connect to a standalone machine, and dump the log
file to that machine through the serial cable synchronously.
or use a cd-writer which doesn't have the erase function as the log file.

【在 g*s 的大作中提到】
: 【 以下文字转载自 Linux 讨论区 】
: 【 原文由 GTS 所发表 】
: Design such a logging facility for an open system
: such as Linux.
: Assume that the attacker's penetration will be logged,
: but the attacker will then have root privilege.
: How do we ensure that the attacker cannot
: then modify the log without the admin detecting that?
: 多谢多谢

avatar
g*s
5
那一天要打印多少次啊
查起来不累死了
定时打印是不安全的 只有一有新数据就打印 而且只打印上回没有的部分
是不是呢?

【在 j***y 的大作中提到】
: use a printer to print out the log in real time by configuring the
: output file to the printer.
: or use a serial cable to connect to a standalone machine, and dump the log
: file to that machine through the serial cable synchronously.
: or use a cd-writer which doesn't have the erase function as the log file.

相关阅读
logo
联系我们隐私协议©2024 redian.news
Redian新闻
Redian.news刊载任何文章,不代表同意其说法或描述,仅为提供更多信息,也不构成任何建议。文章信息的合法性及真实性由其作者负责,与Redian.news及其运营公司无关。欢迎投稿,如发现稿件侵权,或作者不愿在本网发表文章,请版权拥有者通知本网处理。