Honeypots mailing list archives

Re: Honeyd 0.8b bugs and arpd crashing the access to the wireless network


From: chakl () syscall de (Olaf Schreck)
Date: Tue, 18 May 2004 20:58:33 +0200

Hi Malek,

Honeyd 0.8b is not logging information using the -l command. We have tried 
it many times even the use of ">>" or | tee on Linux Red Hat 9.0 is not 

I was scratching my head over the same issue half an hour ago.  I found 
that honeyd creates its logfile writable by "root" only, but it runs as 
"nobody" (on OpenBSD 3.4/i386 here).  This seems to inhibit writes to the 
logfile.

As a workaround, create the logfile before starting honeyd, and change 
the logfile owner to "nobody" (or whatever honeyd runs as).  This 
did the trick, you should see a message "<time> honeyd log started --". 
Without the chown I would always get an empty logfile, not even the 
"started" line.


ciao,
chakl
-- 
Olaf Schreck    chakl () syscall de        syscall() Network Solutions, Berlin


Current thread: