Re: Help with local security checks
cfw_security <[email protected]>
| Newsgroups | gmane.comp.security.nessus.devel |
|---|---|
| Message-ID | <[email protected]> |
>Date: Sun, 22 Aug 2004 14:17:35 +0200 >From: Renaud Deraison <[email protected]> >Subject: Re: [Nessus-devel] Help with local security checks >To: [email protected] > > > >Because if you can change the configuration file, then you are root. If >you are root, you can already execute commands with super-user >privileges. There's nothing Nessus can do to lower the damages you can >do. > >Now, if you choose to set nasl_no_signature_check to yes in the config >file, then you're aiming a gun at your foot. For most users, this option >must remain untouched. For people who want to write their own plugins, >then it can be enabled. > > > -- Renaud > > I am new to the list, so hi all. Renaud, would it be possible to allow users to sign scripts and then include in the config file a list of "trusted" signers (along with their public key) which by default would be just you? That way users can still write and run their own scripts but don't have to turn off the signature checking entirely. Just a thought. Chuck _______________________________________________ Nessus-devel mailing list [email protected] http://mail.nessus.org/mailman/listinfo/nessus-devel