Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-7596

audit plugin - record full query / document line length / make buffer configurable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 10.1.1, 10.0, 5.5
    • Fix Version/s: 5.5.43
    • Component/s: Plugin - Audit
    • Labels:

      Description

      Hey,

      the audit plugin "should" record every part of the query. the current implementation is using a static buffer to shorten the query part. since an audit is used to detect problems or hacking attempts, the audit plugin is unusable. the current size of the buffer is 768 and should be dynamic by default or atleast configurable.
      especially on hacking attacks the last part (where clause) is modified but this part is not part of the audit line. in addition this should be added to the documentation.

      https://github.com/MariaDB/server/blob/10.1/plugin/server_audit/server_audit.c#L1018

        Gliffy Diagrams

          Attachments

            Activity

            Hide
            elenst Elena Stepanova added a comment -

            Alexey Botchkov,

            I remember it being discussed back in days and declared to be by design, but I cannot find any traces of it in JIRA, so maybe I'm wrong. Could you please clarify?

            Show
            elenst Elena Stepanova added a comment - Alexey Botchkov , I remember it being discussed back in days and declared to be by design, but I cannot find any traces of it in JIRA, so maybe I'm wrong. Could you please clarify?
            Hide
            h0nIg Hans-Joachim Kliemeck added a comment -

            Any progress on that issue? Would be cool to know if there will be a change on future releases.

            Show
            h0nIg Hans-Joachim Kliemeck added a comment - Any progress on that issue? Would be cool to know if there will be a change on future releases.
            Hide
            holyfoot Alexey Botchkov added a comment -

            Fixing patch: http://lists.askmonty.org/pipermail/commits/2015-March/007689.html
            The server_audit_query_log_limit variable added to control the length of the log record.

            Show
            holyfoot Alexey Botchkov added a comment - Fixing patch: http://lists.askmonty.org/pipermail/commits/2015-March/007689.html The server_audit_query_log_limit variable added to control the length of the log record.

              People

              • Assignee:
                holyfoot Alexey Botchkov
                Reporter:
                h0nIg Hans-Joachim Kliemeck
              • Votes:
                0 Vote for this issue
                Watchers:
                5 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 1 day
                  1d