Gentoo Archives: gentoo-hardened

From: Miguel Figueiredo Mascarenhas Sousa Filipe <miguel.filipe@×××××.com>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Reducing the number of setuids, root user daemons..et al
Date: Thu, 05 Oct 2006 15:11:42
Message-Id: f058a9c30610050807u72e93dc3u7c5df841e8959621@mail.gmail.com
1 Hi all,
2
3 What do you guys think of:
4
5 - reduce the number of setuid to the maximum
6 - reduce the number of daemons running has root.
7
8 has example, openbsd and openwall (among others) both try to have sane
9 setuids and setguids for things like:
10 - cron/at service
11 - syslog and klogd
12 - passwd (on openwall, not shure about openbsd)
13 and much more..
14
15 those are the things I miss most, a sane default filesystem system
16 permissions and a lot of services that can be running without root
17 privileges..
18
19 One interesting Idea would be to use the /etc/shadow replacement that
20 is present in openwall
21
22 anyone knows if any of these things/ideas is being followed, if so,
23 were can I find pointers to it?
24
25 I
26
27
28 best regards,
29
30
31 --
32 Miguel Sousa Filipe
33 --
34 gentoo-hardened@g.o mailing list

Replies