Is Syslogd the best transport method?
Rootkits Vs. Syslogd Due to the fact that both rootkits and attackers will try to kill syslogd immediately after a compromise, odds are that our modified script data will not be sent to the remote host in an appropriate manner. Another issue to consider with sending the script data across the wire via Syslogd is that the text is displayed in clear text. This could definitely tip off the attacker that session monitoring is occurring if the attacker has installed a sniffer program. For example, I started up a SNOOP session on the remote Solaris logging host and could clearly read all of the data that was being sent across the network from the honeypot system. This is due to the fact that syslog uses clear text UDP packets to transfer information.
Related Questions
- I have some live blue crabs and need to transport them a long distance (or store them alive). Whats the best method to ensure they stay alive?
- Which transport method (bus route, taxi, etc.) is best to get to Auto Safari from my location?
- What is the best way to transport my chameleon to get it to the vet?