Gentoo Archives: gentoo-hardened

From: Dadi <thewalrus@××××××××××××××.org>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] memlimit
Date: Mon, 03 May 2004 13:11:29
Message-Id: 200405031611.18620.thewalrus@dadi.kicks-ass.org
In Reply to: Re: [gentoo-hardened] Current proposed way of installing gentoo hardened by Ed Wildgoose
1 Hello all,
2 I have a question about the memlimit USE flag.
3 Could anyone tell me what it does? All I know is it adds memory usage limiting in supporting programs.
4 Is that a good thing? From the security point of view, let's say?
5 Btw, are there any special flags I can use to increase te security of the system?
6 I have recently built a new server with apache2 mod_php, mod_ssl and others, scanned it with nessus and killed apache :( with some buffer overflow on https.
7 I have been using selinux-sources and I would like to know what hardened sources would you recommend?
8 Something with grsec, ssp would be better? And if so, do I need to recompile all the packages?
9 Do I also need a special gcc with any kind of buffer overflow protections?
10 Explain to me, point me to some documents or something please. :-)
11 Also, would be ACCEPT_KEYWORDS="~x86" a good idea on a production server? I figure having the latest packages installed sure pays off regarding the previous versions bugs and holes, but they may come with new ones.
12
13 Thanks in advance,
14 Dadi
15
16 --
17 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] memlimit Ed Wildgoose <lists@××××××××××.com>