Package: php5-suhosin
Version: 0.9.32.1-1
Severity: important

Hi,

am I missing something here?

Jan  3 19:08:19 myhost ALERT - function within blacklist called: phpinfo() 
(attacker '1.2.3.4', file '/var/www/phpinfo.php', line 2)

if I recall correctly, some time ago there were also suhosin[$pid] logged after 
the hostname.

If I log suhosin alerts to a file also, there's a pid inside the log entry in 
the file but
not in syslog. I'm using rsyslog 5.8.6-1.

Just double-checked that on a Lenny and a Squeeze, the log entries via syslog 
are OK, or
at least, I like them to be that way also on SID:

Jan  3 19:14:18 otherhost suhosin[28077]: ALERT - function within blacklist 
called: phpinfo() (attacker '1.2.3.4', file '/var/www/phpinfo.php', line 2)

thank you.


-- System Information:
Debian Release: wheezy/sid
Architecture: amd64 (x86_64)

Kernel: Linux 3.1.6-grsec (SMP w/8 CPU cores; PREEMPT)
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/bash

Versions of packages php5-suhosin depends on:
ii  libapache2-mod-php5 [phpapi-20090626]  5.3.8.0-1+b1
ii  libc6                                  2.13-24
ii  php5-cgi [phpapi-20090626]             5.3.8.0-1+b1
ii  php5-cli [phpapi-20090626]             5.3.8.0-1+b1

php5-suhosin recommends no packages.

php5-suhosin suggests no packages.

-- no debconf information



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to