Gentoo Archives: gentoo-hardened

From: Jan Krueger <jk@×××××××××××.net>
To: solar@g.o
Cc: Alexander Gabert <pappy@g.o>, gentoo-hardened@g.o
Subject: Re: [gentoo-hardened] Ports Security
Date: Sat, 06 Sep 2003 00:52:24
Message-Id: 200309060257.50557.jk@microgalaxy.net
In Reply to: Re: [gentoo-hardened] portage hooks/modules (was Ports Security) by Ned Ludd
1 On Friday 05 September 2003 23:51, Ned Ludd wrote:
2 > And a slightly improved patch that will make silly sounds and prompt for
3 > user interaction before installing said code.
4 > http://dev.gentoo.org/~solar/ebuild-flawfinder.diff
5 Absolutely fantastic.
6
7 > But from what I've seen in the last few mins of playing with this code
8 > is that we will end up with alot of false postives. bin86 triggers at
9 > level 5 about chmod vs fchmod but psmisc seems clean.
10 It shows, that flawfinder is far from perfect :)
11 the achievable security is as good as the scanner. If they get widely used,
12 they will improve, i hope :)
13
14 I get some sleep now and come back with ebuilds for some of the scanners in
15 the next days + patches to ebuild.sh.
16
17 At least it helps with an ebuild security policy for gentoo hardened that,
18 except me, nobody addressed so far. It resides on my desk, top priority :)
19
20 Jan
21
22
23 --
24 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Ports Security Jan Krueger <jk@×××××××××××.net>