RE: [Syslog] delineated datagrams

Balazs Scheidler <> Wed, 09 August 2006 07:46 UTC

Received: from [] ( by with esmtp (Exim 4.43) id 1GAimG-0002UB-4H; Wed, 09 Aug 2006 03:46:56 -0400
Received: from [] ( by with esmtp (Exim 4.43) id 1GAimF-0002U5-9e for; Wed, 09 Aug 2006 03:46:55 -0400
Received: from ([]) by with esmtp (Exim 4.43) id 1GAimC-0006ed-Su for; Wed, 09 Aug 2006 03:46:55 -0400
Subject: RE: [Syslog] delineated datagrams
From: Balazs Scheidler <>
To: John Calcote <>
In-Reply-To: <>
References: <00f801c6af25$a5423c30$> <> <>
Content-Type: text/plain
Date: Wed, 09 Aug 2006 09:46:50 +0200
Message-Id: <1155109610.6312.10.camel@bzorp.balabit>
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Spam-Score: 0.0 (/)
X-Scan-Signature: bb8f917bb6b8da28fc948aeffb74aa17
Cc:, 'Tom Petch' <>
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security Issues in Network Event Logging <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>

On Tue, 2006-08-08 at 13:44 -0600, John Calcote wrote:
> Chris,
> While I agree with you in principle that both forms of delineation are
> nice to have for interop, I _wish_ we could get rid of LF - that so
> limits the sort of data that can be sent in the message. My two
> cents...

The message you send are _already_ limited as most syslog daemons
replace "\n" character with something else as it would clobber the
message file when it is written to disk. 

In fact leaving the CR LF characters in the message could be a security
risk as that way messages can be "hidden", for instance if a daemon
writes the following message:

This is a foo message, bar=<data supplied by external entity>

Then the value for "bar" might contain CR, putting the cursor to the
beginning of the line on a usual VT100 compatible terminal, and the rest
of can pose as a regular log message, overwriting the previous one on
the screen.

Of course this can be worked around by using some form of escaping while
data is written to files, but again the LF character does not remain

syslog-ng for instance replaces CR and LF characters in the message with
a space as it comes in. I rarely heard any complaints about this
behaviour. And another fact is syslog/RAW also uses LF line terminators
when multiple messages are delivered in a single BEEP frame.


Syslog mailing list