From owner-freebsd-bugs@FreeBSD.ORG Wed Jan 12 01:00:49 2005 Return-Path: Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id A9B3D16A4CE for ; Wed, 12 Jan 2005 01:00:49 +0000 (GMT) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8F27E43D46 for ; Wed, 12 Jan 2005 01:00:49 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.1/8.13.1) with ESMTP id j0C10nEm016578 for ; Wed, 12 Jan 2005 01:00:49 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.1/8.13.1/Submit) id j0C10nK9016577; Wed, 12 Jan 2005 01:00:49 GMT (envelope-from gnats) Date: Wed, 12 Jan 2005 01:00:49 GMT Message-Id: <200501120100.j0C10nK9016577@freefall.freebsd.org> To: freebsd-bugs@FreeBSD.org From: Yar Tikhiy Subject: Re: bin/66445: Add options to last(1) to ignore ftp logins (usefull for busy ftp servers) [PATCH] X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: Yar Tikhiy List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 12 Jan 2005 01:00:49 -0000 The following reply was made to PR bin/66445; it has been noted by GNATS. From: Yar Tikhiy To: Flemming Jacobsen Cc: freebsd-gnats-submit@freebsd.org Subject: Re: bin/66445: Add options to last(1) to ignore ftp logins (usefull for busy ftp servers) [PATCH] Date: Wed, 12 Jan 2005 03:56:23 +0300 On Sat, Jan 08, 2005 at 08:51:18AM +0100, Flemming Jacobsen wrote: > Yar Tikhiy wrote: > > According to the KISS principle of Unix, one should use such tools > > as grep(1) or awk(1) to exclude some lines from last(1) output. > > Have you considered that? > > This can be seen as violating KISS, yes. > And if people want to dump the patch for that reason, i have no > complaints. This patch is for convinience, not for critical > functionality. You see, the problem with your patch is violating not KISS itself, but the well-established Unix tradition of specialized command-line tools. Filtering ftp login records out isn't a job for last(1). > As for ftpd -W, it doesn't log regular ftp logins, which is > really bad for security. > > Maybe a better lolution would be to teach ftpd not to log annon > logins to wtmp. I hope I found a possible solution. What do you think about changing the -W switch behaviour so that it would turn off logging anonymous and guest FTP logins if specified once or turn wtmp logging completely if specified twice on the command line? E.g., ftpd -W # don't log anonymous and guest logins ftpd -WW # don't touch wtmp at all -- Yar