1 |
On 12/11/2011 03:30 PM, Kevin Chadwick wrote: |
2 |
> On Sun, 11 Dec 2011 10:18:51 +0000 |
3 |
> Sven Vermeulen wrote: |
4 |
> |
5 |
>> Also consider hardening your system settings-wise. I would appreciate if you |
6 |
>> take a look at |
7 |
>> http://dev.gentoo.org/~swift/docs/previews/oval/gentoo-xccdf-guide.html. |
8 |
>> With the instructions given, you can even have your system validated (as far |
9 |
>> as possible) automatically. |
10 |
> |
11 |
> I was expecting to find here what one distro uses which is binary |
12 |
> signature checking upon execution. |
13 |
> |
14 |
> Another thing that I try to do as a better method of TPE which is a |
15 |
> breeze on OpenBSD and sometimes I find myself working against Linux |
16 |
> developers¹ is to make it so that any writeable area of the filesystem |
17 |
> is mounted noexec and mounts have the least priviledges required. |
18 |
> |
19 |
> |
20 |
> ¹ "https://bugs.launchpad.net/ubuntu/+source/udisks/+bug/880965" |
21 |
> set as won't fix and also e.g. apt-get expecting /tmp exec. |
22 |
|
23 |
How would you handle /etc/ ? You can't separate it from / which needs |
24 |
to be exec and yet /etc/ needs to be writeable. |
25 |
|
26 |
-- |
27 |
Anthony G. Basile, Ph. D. |
28 |
Chair of Information Technology |
29 |
D'Youville College |
30 |
Buffalo, NY 14201 |
31 |
(716) 829-8197 |