you are viewing a single comment's thread
view the rest of the comments
[–] 46 points 2 years ago (2 children)

information itself is a liability. best to have a policy of 'we keep no IPs in logs, so are happy to hand over whatever'.. dump data the moment you dont require it

  • source
  • parent
  • hideshow 4 child comments
  • [–] 9 points 2 years ago (1 child)

    Just store what logs you need on a ram drive. The logs will be gone the instant the server shuts down and there is no way to recover them.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 8 points 2 years ago (1 child)

    Downsides include : if any intrusion happens on the server, red team just needs to reboot it to wipe evidence.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 5 points 2 years ago*

    If they have the root access typically needed to reboot a server^1^ they could also just wipe the logs without rebooting.

    ^1^: GUIs typically have a way to reboot without such privileges, but those are typically not installed on machines just used as servers.

  • source
  • parent