Gentoo Archives: gentoo-hardened

From: pageexec@××××××××.hu
To: gentoo-hardened@l.g.o
Cc: spender@××××××××××.net
Subject: Re: [gentoo-hardened] Security Level: high/server/workstation/virtualization
Date: Sat, 28 Jan 2012 19:30:06
Message-Id: 4F244C58.2738.3357B651@pageexec.freemail.hu
In Reply to: Re: [gentoo-hardened] Security Level: high/server/workstation/virtualization by Alex Efros
1 On 28 Jan 2012 at 15:23, Alex Efros wrote:
2
3 > On Sat, Jan 28, 2012 at 02:12:19PM +0200, pageexec@××××××××.hu wrote:
4 > > > $ dumpcap
5 > > > dumpcap: Can't get list of interfaces: Can't open /sys/class/net: Permission denied
6 > >
7 > > i think it's GRKERNSEC_SYSFS_RESTRICT that could cause this, do you have it enabled?
8 >
9 > Hmm. Sure. You think I shouldn't have it enabled?
10 > dumpcap is suid, why it can't access it? Or it doesn't execute as root
11 > already/yet at point when it try to enumerate available interfaces?
12 > If this is the case, then it looks like one more bug to fix in dumpcap...
13
14 you should at this point probably talk to spender or the grsecurity related
15 list/forum as all this is his stuff, not mine ;)