Re: [DNG] ..forensics on systemd or journald logs

2017-11-23 Thread golinux
On 2017-11-23 15:06, Rick Moen wrote: Seriously, guys, less bullshit on security matters, please. Some of us can actually detect it and find it annoying. What I'm finding annoying is that someone who has been moderated still has a presence on this list via a reply to an off-list email. go

Re: [DNG] ..forensics on systemd or journald logs

2017-11-23 Thread Rick Moen
Quoting Arnt Karlsen (a...@iaksess.no): > On Thu, 23 Nov 2017 14:47:40 +0100, John wrote in message > <02372660-5727-d160-fe49-e3a4963f8...@atlantech.com>: > > > On 23/11/17 12:28, Arnt Karlsen wrote: > > > ..the kernel guys has this far proven more trustworthy, IME. > > > > Number of times u

Re: [DNG] ..forensics on systemd or journald logs

2017-11-23 Thread Arnt Karlsen
On Thu, 23 Nov 2017 14:47:40 +0100, John wrote in message <02372660-5727-d160-fe49-e3a4963f8...@atlantech.com>: > On 23/11/17 12:28, Arnt Karlsen wrote: > > ..the kernel guys has this far proven more trustworthy, IME. > > Number of times unknown third parties have inserted bad code into the >

Re: [DNG] ..forensics on systemd or journald logs

2017-11-23 Thread Arnt Karlsen
On Thu, 23 Nov 2017 11:32:57 +0100, John wrote in message <51f391b3-2c10-78b0-d1ce-39f56f8e0...@atlantech.com>: > Replying directly because Jaromil has said I am not welcome. ..no problem, I'll cc the list. ;o) > On 23/11/17 11:06, Arnt Karlsen wrote: > > > ..which leaves in place that "system

Re: [DNG] ..forensics on systemd or journald logs

2017-11-23 Thread Arnt Karlsen
On Thu, 23 Nov 2017 08:20:05 +0100, John wrote in message <25c55d20-a650-5ec7-5943-f2224ba21...@atlantech.com>: > On 22/11/17 17:35, Arnt Karlsen wrote: > > ..to reiterate: Is there a way to decode and read those binary > > systemd journal logs on classic POSIX/Unix etc forensic systems > > _not_

Re: [DNG] rc.local removed from Debian 9, rly?

2017-11-23 Thread Jaromil
On Wed, 22 Nov 2017, John Hughes wrote: > On 22/11/17 11:42, Jaromil wrote: > > On Wed, 22 Nov 2017, John Hughes wrote: > > > > > No way to do that?  Seriously?  No way at all? > > jeez, is John a troll? > > My little joke about the usefulness of the systemd journal in diagnosing the > /etc/rc.l

Re: [DNG] rc.local removed from Debian 9, rly?

2017-11-23 Thread Tomasz Torcz
November 22, 2017 11:21 AM, "John Hughes" wrote: > On 22/11/17 08:48, Didier Kryn wrote: > >> Le 22/11/2017 à 07:19, John Hughes a écrit : >>> Is there any way to read a file in format X without a program that >>> reads format X? >> >> The question is why use yet another "proprietary format"? J