Date: Sun, 25 May 2014 23:51:14 -0400 From: Jason Hellenthal <jhellenthal@dataix.net> To: "Ronald F. Guilmette" <rfg@tristatelogic.com> Cc: "freebsd-security@freebsd.org" <freebsd-security@freebsd.org> Subject: Re: NEVERMIND! (was: Local Denial of Service: logger(1)) Message-ID: <61CB0E46-3969-4A00-866E-731F44E0B29A@dataix.net> In-Reply-To: <2218.1401075427@server1.tristatelogic.com> References: <2218.1401075427@server1.tristatelogic.com>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] That and/or you could just disallow the use of logger to that of just a special group say staff and modify the mtree(8) files to keep the changes. These are just medial tasks into hardening a system for its specific needs. security/logcheck should pick up these events pretty quickly and shoot out an email to your admin group to alert them of the miscreant :-) -- Jason Hellenthal Voice: 95.30.17.6/616 JJH48-ARIN > On May 25, 2014, at 23:37, "Ronald F. Guilmette" <rfg@tristatelogic.com> wrote: > > > In message <2091.1401074804@server1.tristatelogic.com>, I wrote: > >> ========================================================================== >> #!/bin/sh >> >> while (1) >> dd if=/dev/random bs=15 count=1 | od -c | xargs logger >> end >> ========================================================================== > > DUH! > > I forgot that newsyslog(8) should limit the size of /var/log/messages, and > that as long as you limit the size of that to a reasnable value, and as > long as you have newsyslog(8) only keeping a finite & reasonable number > of "rotated out" copies, then /var won't fill up. > > My apologies to everyone for the distraction. > _______________________________________________ > freebsd-security@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org" [-- Attachment #2 --] 0 *H 010 + 0 *H 90000 *H 010 UIL10U StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0 130518085048Z 140519220947Z0H10Ujhellenthal@dataix.net1%0# *H jhellenthal@dataix.net0"0 *H 0 '`TmfkܨJ5u+c'Upb`zv)&ȸXZ*VN6JvLoVoh}g pQDŽKf/tZA˳("4Ԅ˻'d2h|IBl'^v^;'e8S99ۿVm|k8_UQtC"5l!kjZ]އQGn\Bh!FTsD%pV^Eӑd¨x"9 г"f 00 U0 0U0U%0++0UڔfmVʢ$䟓0U#0Sr풜\|~5NԸQ0!U0jhellenthal@dataix.net0LU C0?0;+70*0.+"http://www.startssl.com/policy.pdf0+00' StartCom Certification Authority0This certificate was issued according to the Class 1 Validation requirements of the StartCom CA policy, reliance only for the intended purpose in compliance of the relying party obligations.06U/0-0+)'%http://crl.startssl.com/crtu1-crl.crl0+009+0-http://ocsp.startssl.com/sub/class1/client/ca0B+06http://aia.startssl.com/certs/sub.class1.client.ca.crt0#U0http://www.startssl.com/0 *H {0Ӹ,52W{Ey8b[{7 _+P"n["-,@ŽpJ-W$ݍjWA-6z( RdIZ.KzXє[K6}{s+v.Qh0PͅKhTw 0I73lz*Kv4Kkگ63;p1:ױ@)]ok>:W%XwC1þL/o8~#oP0400 *H 0}10 UIL10U StartCom Ltd.1+0)U"Secure Digital Certificate Signing1)0'U StartCom Certification Authority0 071024210155Z 171024210155Z010 UIL10U StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0"0 *H 0 -).2AUGo#G B|NDRpM-B=o-we5JQpa>O.#._<V [~**pz~3WG .ᘟMlr[<Ce6fqO"uxfWN#uicgkv$Lb%y`_{`xK'GN 00U00U0USr풜\|~5NԸQ0U#0N@[i04hCA0f+Z0X0'+0http://ocsp.startssl.com/ca0-+0!http://www.startssl.com/sfsca.crt0[UT0R0'%#!http://www.startssl.com/sfsca.crl0'%#!http://crl.startssl.com/sfsca.crl0U y0w0u+70f0.+"http://www.startssl.com/policy.pdf04+(http://www.startssl.com/intermediate.pdf0 *H }x,\c^#wMq}>UK/^yX֏y frMIŲB61ymQҨݬZ0&
