Re: Secure Linux From Scratch
ashes <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | Utopia Inc |
| Message-ID | <[email protected]> |
I have a feeling there's a way to enforce a systrace policy on suid programs, maybe on all programs. If we know what a program is supposed to, and is permited to do, maybe some kind of simple wrapper, or again a special user, can be used to drop root privs where posible, cage the enviroment, and log/crash if the program does something outside its policy or profile. There could be access controls for this in selinux or grsecurity, I dont know if its posible to keep this out of the kernel. -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page