[syslog-ng]destination X { program(); }; and security

Tommi Virtanen tv@debian.org
08 Jun 2001 08:36:09 +0300


David Douthitt <ssrat@mailbag.com> writes:

> Also, I noticed that items run via program() run as root - at least
> when syslog-ng is run as root.  Is it possible to have syslog-ng drop
> priveledges?  In fact, is it possible to have syslog-ng drop its own
> priveledges as soon as possible and run as a normal user?  Perhaps as
> nobody?

	I made a patch for the latter, it's included in a modified
        form in current releases. You are not doing your studies :)

-- 
tv@{{hq.yok.utu,havoc,gaeshido}.fi,{debian,wanderer}.org,stonesoft.com}
unix, linux, debian, networks, security, | First snow, then silence.
kernel, TCP/IP, C, perl, free software,  | This thousand dollar screen dies
mail, www, sw devel, unix admin, hacks.  | so beautifully.