Gentoo Logo
Gentoo Spaceship

Installation:
Gentoo Handbook
Installation Docs

Documentation:
Home
Listing
About Gentoo
Philosophy
Social Contract

Resources:
Bug Tracker
Developer List
Discussion Forums
Gentoo BitTorrents
Gentoo Linux Enhancement Proposals
IRC Channels
Mailing Lists
Mirrors
Name and Logo Guidelines
Online Package Database
Security Announcements
Staffing Needs
Supporting Vendors
View our CVS

Graphics:
Logos and themes
Icons
ScreenShots

Miscellaneous Resources:
Gentoo Linux Store
Gentoo-hosted projects
IBM dW/Intel article archive




List Archive: gentoo-hardened
Navigation:
Lists: gentoo-hardened: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-hardened@g.o
From: Javier J. Martínez Cabezón <tazok.id0@...>
Subject: Re: "How hard" is Linux kernel-side hardening?
Date: Sun, 20 Sep 2009 22:09:14 +0200
>2009/9/20, Javier J. Martínez Cabezón <tazok.id0@...>:
> Another question that I think grsec lacks is the control of which
> SETUID binary could change to which uid (for example, permit only
> login to change to the uid 1000 and not 80), or forbid setuid if the
> user does not authenticate itself against the kernel (with a password
> in for example sshd, so remote exploits which affect priviledge parts
> of sshd only could change to uid 22 and not to root or those which
> affect login could be controlated)

I was wrong here as you can see here:
http://en.wikibooks.org/wiki/Grsecurity/Appendix/Subject_Attributes
Sorry by the mistake.


Replies:
Re: "How hard" is Linux kernel-side hardening?
-- Marco Venutti
References:
"How hard" is Linux kernel-side hardening?
-- Marco Venutti
Re: "How hard" is Linux kernel-side hardening?
-- Javier J . Martínez Cabezón
Re: "How hard" is Linux kernel-side hardening?
-- Marco Venutti
Re: "How hard" is Linux kernel-side hardening?
-- Javier J . Martínez Cabezón
Navigation:
Lists: gentoo-hardened: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: "How hard" is Linux kernel-side hardening?
Next by thread:
Re: "How hard" is Linux kernel-side hardening?
Previous by date:
Re: "How hard" is Linux kernel-side hardening?
Next by date:
Re: "How hard" is Linux kernel-side hardening?


Updated Nov 22, 2009

Donate to support our development efforts.

Gentoo Centric Hosting: vr.org

VR Hosted

Tek Alchemy

Tek Alchemy

SevenL.net

SevenL.net

php|architect

php|architect

Copyright 2001-2007 Gentoo Foundation, Inc. Questions, Comments? Email www@gentoo.org.