Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Most webservers that I am familiar with have configurable log formatting, so you could prevent it from being logged in the first place.


Yes, but the guy I replied to said he scrubbed it, which implies that they did not prevent anything from being logged, but instead they cleaned it up afterwards. Thus the reason for me saying what I did.


The logs sit on a ramdisk before being scrubbed; power removed before scrubbing? Logs are lost, but PCI compliance is maintained.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: