Re: Help with local security checks

cfw_security <[email protected]>
Newsgroups gmane.comp.security.nessus.devel
Message-ID <[email protected]>
>Date: Sun, 22 Aug 2004 14:17:35 +0200
>From: Renaud Deraison <[email protected]>
>Subject: Re: [Nessus-devel] Help with local security checks
>To: [email protected]
>  
>
>
>Because if you can change the configuration file, then you are root. If
>you are root, you can already execute commands with super-user
>privileges. There's nothing Nessus can do to lower the damages you can
>do.
>
>Now, if you choose to set nasl_no_signature_check to yes in the config
>file, then you're aiming a gun at your foot. For most users, this option 
>must remain untouched. For people who want to write their own plugins,
>then it can be enabled.
>
>
>				-- Renaud
>  
>
I am new to the list, so hi all.

Renaud, would it be possible to allow users to sign scripts and then 
include in the config file a list of "trusted" signers (along with their 
public key) which by default would be just you?  That way users can 
still write and run their own scripts but don't have to turn off the 
signature checking entirely.  Just a thought.

Chuck
_______________________________________________
Nessus-devel mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.