Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

Re: EU approves data retention rules

Subject: Re: EU approves data retention rules
Date: Tue, 20 Dec 2005 21:43:08 +0100
On Tuesday 20 December 2005 13:17, Alvin Oga wrote:

logs should be time stamped and gpg signed to minimize tampering

worst still, what if they admins turn off all logging on the
machines so there is zero-ized log files ... silly admins forgot to
check that syslogd is running or other that /var/log exists

/var/log typically get moved to a remote loghost .. that may or
may not be writable by that host

Whether logs are legal evidence or have any meaning in a court of 
justice or even in a less formal environment like an HR office that's 
a very different kind of story. EU directives and Member States Laws 
ask us to retain them for a certain period of time. Period. How to 
use them for what purpose is somebody else's issue.

To us techies is very clear that logs are just.... logs. Text files 
with lines of rubbish one after the other that maybe are genuine 
maybe are not, and that can easily be tampered with a simple text 
editor. Depending on who you are dealing with logs may be the the 
source of truth, nothing at all, or anything in between....

-- 
Alessandro Bottonelli
CISSP, BS7799 LA
http://www.axis-net.it

---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management 
education and the case study affords you unmatched consulting experience. 
Tailor your education to your own professional goals with degree 
customizations including Emergency Management, Business Continuity Planning, 
Computer Emergency Response Teams, and Digital Investigations. 

http://www.msia.norwich.edu/secfocus
----------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>