Re: [logs] adduser log

From: Jose Nazario (joseat_private)
Date: Wed Jan 22 2003 - 10:12:34 PST

  • Next message: Tom Perrine: "Re: [logs] adduser log"

    why reinvent the wheel? systrace for linux exists:

    you simply permit all things and permit with logging on execve calls. you
    have to systrace wrap everything, tho, but its not that hard to do. you
    launch any parent shell/process with systrace and any children will
    inherit. we've been doing this for a while on bsd and it's a nice system.
    also, BSD adduser logs. rmuser doesn't tho :/ (C code vs perl script.)
    maybe steal from there.
    jose nazario, ph.d.			joseat_private
    LogAnalysis mailing list

    This archive was generated by hypermail 2b30 : Wed Jan 22 2003 - 11:12:48 PST