Honeypots mailing list archives

Re: honeyd0.8b not logging to syslog


From: Niels Provos <provos () citi umich edu>
Date: Sun, 28 Nov 2004 22:04:51 -0500

Honeyd does not log connections to Syslog unless you start it in debug
mode with -d.  A busy honeyd can generate a lot of logging
information, so it seems better to not bother systrace with it.

Niels.

On Sun, Nov 28, 2004 at 08:49:31PM -0500, Jeff Kloet wrote:
 I've started honeyd with root privileges ( -u 0 -g 0 ) and even set
'/var/log/messages' permissions to 666 ... still no connection messages
showing up in /var/log/messages.  I'm perplexed.
 
Jeff

________________________________

From: Administrador Root [mailto:honeypot_maillist () yahoo es] 
Sent: November 28, 2004 4:38 PM
To: honeypots () securityfocus com
Subject: Re: honeyd0.8b not logging to syslog


Jeff, I haven't honeyd0.8b. But I would checked the effecty user of
henyd0.8b, and who can write to syslog's file. You checked it sure, but
it's the first thing i do.
 
Bye


Jeff Kloet <jkloet () toromont com> wrote:



      I have honeyd0.8b up and running on RedHat 9.0 with a simple
configuration... it listens on unused address space and opens a
connection for any udp/tcp/imcp traffic hitting that address space.
      
      All is well except that honeyd does not log the connections to
syslog. It does log them to a file and it does log honeyd startup
information to syslog.
      
      Ideas?
      
      Thanks
      Jeff K
      
      

________________________________


Nuevo Correo Yahoo!
<http://es.rd.yahoo.com/mail_es/tagline/mail/image/*http://es.mail.yahoo
.com>         


Current thread: