LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-10-2004, 04:09 PM   #16
stickman
Senior Member
 
Registered: Sep 2002
Location: Nashville, TN
Posts: 1,552

Rep: Reputation: 53

The ksyms logfiles are not created by syslog, but by rc.sysinit as I suggested. Not all files in /var/log are created by syslog. It's a generic log location. If you look in rc.sysinit for ksyms, you'll see where the logfiles are rotated with a simple while loop and the new one is created. Also, what do you consider to be arbitrary about the ksyms manpage? It appears to work as advertised.

Last edited by stickman; 08-10-2004 at 04:15 PM.
 
Old 08-10-2004, 04:15 PM   #17
Obie
Member
 
Registered: Apr 2004
Distribution: Red Hat
Posts: 290

Original Poster
Rep: Reputation: 30
stickman,

I though the rc.sysinit would start the software that logs ksyms.0, etc. As for my comment on it being arbitrary, I think I should have used the word vague. In a gist, it only seems to come across to me as kernel messaging and if so for what reason?
 
Old 08-10-2004, 04:20 PM   #18
stickman
Senior Member
 
Registered: Sep 2002
Location: Nashville, TN
Posts: 1,552

Rep: Reputation: 53
There is no software behind ksyms other than the kernel (ie module insertion and removal). The logfiles are created with a simple cat command.
 
Old 08-10-2004, 04:30 PM   #19
Obie
Member
 
Registered: Apr 2004
Distribution: Red Hat
Posts: 290

Original Poster
Rep: Reputation: 30
stickman,

Thanks. How does ksyms help with security and why log it?
 
Old 08-11-2004, 08:00 AM   #20
stickman
Senior Member
 
Registered: Sep 2002
Location: Nashville, TN
Posts: 1,552

Rep: Reputation: 53
ksyms basically tells you what kernel symbols exists and where they are. Typically this should be static from day to day unless you are making adjustments to your kernel or the modules that get loaded. You might want to start looking at your system if you suddenly have new symbols.
 
Old 08-11-2004, 04:04 PM   #21
Obie
Member
 
Registered: Apr 2004
Distribution: Red Hat
Posts: 290

Original Poster
Rep: Reputation: 30
stickman,

Thank you.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
weird stuff in /var/log/auth.log bschiett Linux - Security 3 03-12-2005 08:29 AM
Deleted /var/log/messages, can't log any files-iptables chingyenccy Linux - Newbie 7 02-27-2005 04:03 PM
Strange results in /var/log/apache/access.log subt13 Linux - Security 2 08-03-2004 01:21 PM
pppd logging to /var/log/ppp.log problem mrtwice Linux - Software 1 01-10-2004 05:38 PM
iptables, changing log file from /var/log/messages acid2000 Linux - Networking 3 03-11-2003 08:38 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:08 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration