Re: [Security-Discuss] 2006 su problem

Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]> Tue, 18 Oct 2005 22:53:04 -0600
Newsgroups gmane.linux.mandrake.security.general
Organization Mandriva
Message-ID <[email protected]>
* AAW <[email protected]> [2005-10-18 21:48:09 -0500]:

> > Out of curiosity... what is it about msec that you actually like/need?
> > I find msec to be more trouble than it's worth.  Frankly, I like the
> > idea of the various reports it sends, but I really can't stand how it
> > monkeys with files behind your back (and changing configs is even
> > worse).  Do you actually find msec "fixing" things is reliable and
> > worth it?
> >
> > I'm curious because I've been using an msec replacement I fudged
> > together over a year ago on my servers (haven't tried it on desktops
> > since I don't really care on the desktop).  If all you're interested in
> > is reports, maybe giving rsec a try would be worth it (rsec == msec's
> > baby brother who isn't prone to putting fingers in cookie jars that
> > don't belong to him).
> 
> As a matter of fact, msec was the reason I originally chose Mandrake over 
> several other distros. As a desktop user, I like the very things you 
> don't. It's a convenient way to control basic security settings. The 
> defaults, at least level 3, are reasonable for a desktop system and it's 
> easy to customize once you wade through the mseclib man page. Aside from 
> a couple of recent bugs (now fixed), I don't recall any real problems 
> with it.

For desktop use, msec is fine.  I have no problem with it.  On a server,
I'd rather attempt to hang myself with a wet noodle.

The last time I used msec on a server was when it seemed to think it
was smarter than me and because I had a symlink of /usr/bin/sendmail
pointing to /usr/bin/exim (which was suid), it would change the
destination of the symlink and strip the suid bit.  The msec file perms
were for /usr/bin/sendmail, which was a symbolic link... strip suid from
the symlink all you like, but leave /usr/bin/exim (which was expliticlty
defined to be suid in the msec config) alone.

Following symlinks like that is plain naughty and it caused me no end of
grief trying to figure out what in the heck was breaking the mail server
my clients were hollering at me about.  =(

Haven't touched msec on a server since then.


-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
signature.asc (application/pgp-signature, 186 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (Darwin)

iD8DBQFDVdEwLrxeMv7jCtQRAleFAJ42LyffAJtr5bcxek+AMEUVAxTBGgCbBRGZ
0Bg2Ee8eeKcY4aVq+UIPSZE=
=GUwr
-----END PGP SIGNATURE-----