OK started on this now, just to tweak the scripts.
I've found that there are a whole bunch of programs using
syslog impoperly, but I'm guessing for 99% of them it
won't be a problem.
(eg. non-setuid, non-networked programs such as 3ddesktop).
Javier if I come across a /tmp file issue should I report
it - or are you still working your way through the backlog
of reports? (eg. postman).
One thing that is becoming clear is that auditing every
'syslog' call is not liable to be sufficient. A *lot* of
programs will setup aliases, or macros such as 'LOG' or
'DEBUG'.
Tracing their usage is also going to be required.
Steve
--
|
|