Re: Preventing curl | bash

Manuel Wolfshant <[email protected]>
Newsgroups gmane.linux.redhat.fedora.selinux
Organization Nobug Consulting SRL
Message-ID <[email protected]>
On 10/17/2018 11:13 AM, Tracy Reed wrote:
> On Tue, Oct 16, 2018 at 02:15:39AM PDT, Sheogorath spake thusly:
>> I wonder if there is a way to prevent a direct piping from curl to bash
>> using SELinux.
> No good way to prevent it. If they can install software they can do it.
> Don't install curl. Monitor for process executions. I have auditd log
> execs. Anytime someone runs curl or wget in our production environment
> something's up.
chmod 700 $(which curl)

but a selinux policy preventing those exact pipe invocations would be 
interesting
_______________________________________________
selinux mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.