Gentoo Archives: gentoo-hardened

From: Alex Efros <powerman@××××××××.name>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Security Level: high/server/workstation/virtualization
Date: Sat, 28 Jan 2012 13:24:50
Message-Id: 20120128132358.GM5600@home.power
In Reply to: Re: [gentoo-hardened] Security Level: high/server/workstation/virtualization by pageexec@freemail.hu
1 Hi!
2
3 On Sat, Jan 28, 2012 at 02:12:19PM +0200, pageexec@××××××××.hu wrote:
4 > > $ dumpcap
5 > > dumpcap: Can't get list of interfaces: Can't open /sys/class/net: Permission denied
6 >
7 > i think it's GRKERNSEC_SYSFS_RESTRICT that could cause this, do you have it enabled?
8
9 Hmm. Sure. You think I shouldn't have it enabled?
10 dumpcap is suid, why it can't access it? Or it doesn't execute as root
11 already/yet at point when it try to enumerate available interfaces?
12 If this is the case, then it looks like one more bug to fix in dumpcap…
13
14 > > And one more questions - why core wasn't dumped here?
15 >
16 > check /proc/sys/fs/suid_dumpable
17
18 0. Thanks.
19
20 --
21 WBR, Alex.

Replies