Gentoo Archives: gentoo-hardened

From: "Lamont R. Peterson" <lrp@××××××××.com>
To: Martin Bene <martin.bene@×××××××××.com>, gentoo-hardened@g.o
Subject: Re: AW: [gentoo-hardened] Question WRT Grsecurity/PAx and AV Scanner
Date: Thu, 18 Sep 2003 17:31:35
Message-Id: 200309181131.10628.lrp@xmission.com
In Reply to: AW: [gentoo-hardened] Question WRT Grsecurity/PAx and AV Scanner by Martin Bene
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 On Thursday 18 September 2003 11:13 am, Martin Bene wrote:
5 - --SNIP--
6
7 > Definitely true, but I don't think I'm that far wrt my configuration. First
8 > I need to really understand how the system works and what's going on -only
9 > then does it make sense to start tuning.
10 >
11 > I think the default grsecurity policies could use some updates to make them
12 > a really useful starting point instead of a source of pitfalls for the
13 > unwary
14
15 I would have to botagree and disagree with this. We do want it to be easy for
16 people to not "fall in the pit". However, grsecurity is a "security"
17 enhancement. We do want the defaults to be secure. Where does one draw the
18 line between these goals? I am certain I would recieve agreement if I said
19 that we all have a different viewpoint on the "correct" or "appropriate"
20 answer to that one. :-)
21
22 > Back to the log entries: the sshd entry is obvious now, I had overlooked
23 > the "o" subject in the sshd acl and /dev/urandom is not explicitely listet
24 > in the sshd acl.
25
26 Ah, I missed that, too.
27
28 > Understanding WHY it's not a good idea to let sshd inherit the default acls
29 > is another matter.
30
31 Because sshd is a tool to open a hole into your machine that allows people to
32 remotely run whatever they want to. Under WinNT/2000/etc. ACLs on filesystem
33 object (i.e.directories) are far to easy to abuse this way without realizing
34 it. I could give examples, but I will hold off unless someone is really
35 confused about this.
36
37 > Could the /dev/urandom message for gradm -R be an artefact of reloading the
38 > ruleset?
39
40 That sounds reasonable to me (but I do not know that this is "the" truth).
41 - --
42 Sincerely,
43 Lamont R. Peterson <lrp@××××××××.com>
44 -----BEGIN PGP SIGNATURE-----
45 Version: GnuPG v1.2.2-rc1-SuSE (GNU/Linux)
46
47 iD8DBQE/aeveg5LkF3+ZgzARAsNsAJwKlyNe+VpjairMtlExpmtEVWeSVwCeMB4d
48 ICOxBhO2DiLXGjKWGucMkuo=
49 =7cyq
50 -----END PGP SIGNATURE-----
51
52
53 --
54 gentoo-hardened@g.o mailing list