Re: [logs] log review policies

From: Ralf Hildebrandt (Ralf.Hildebrandtat_private)
Date: Tue Oct 16 2001 - 00:32:23 PDT

  • Next message: peff-loganalat_private: "Re: [logs] log review policies"

    On Mon, Oct 15, 2001 at 06:12:04AM -0400, peff-loganalat_private wrote:
    
    > Are you suggesting that admin workstations run SMTP servers? This seems
    > a tad dangerous from a security perspective; they otherwise have no need
    > to be running any services actively listening on the network.
    
    A send-only MTA need not be an SMTP server, not even with sendmail:
    
    % sendmail -q15m
    
    > But if all of the admin workstations are cookie-cuttered, then breaking
    > into the SMTP server on one means you can break into all of them.
    
    Well, you don't have to use sendmail. There are still Postfix and qmail.
    
    -- 
    Ralf Hildebrandt                            Tel.  +49 (0)30-450 570-155
                                                Fax.  +49 (0)30-450 570-916
    Without C, We would only have Pasal, Basi, and obol
    
    
    
    ---------------------------------------------------------------------
    To unsubscribe, e-mail: loganalysis-unsubscribeat_private
    For additional commands, e-mail: loganalysis-helpat_private
    



    This archive was generated by hypermail 2b30 : Tue Oct 16 2001 - 17:00:33 PDT