Re: selinux is a pain

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> If so, no wonder you're having grief.  While SELinux was off, your
> system was writing files without setting any SELinux contexts.  So,

If SELinux was set to permissive then it was writing data but allowing
actions, if not then when you switched it on it would have done an
automatic relabel on boot.

This looks like the standard SELinux and cgi stuff. It's in the
RHEL/Centos manual and very well documented elsewhere.

Essentially however file permissions are not enough to enable the
security policy to tell the difference between 'I've just busted your
php script again' and 'legitimate access'. Labelling the cgi, scripts and
data files allows you to tell it which files should be acessible and in
what way - which dramatically cuts the impact of the php exploit.

Alan
-- 
users mailing list
users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe or change subscription options:
https://admin.fedoraproject.org/mailman/listinfo/users
Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines

[Index of Archives]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [EPEL Devel]     [Fedora Magazine]     [Fedora Summer Coding]     [Fedora Laptop]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Desktop]     [Fedora Fonts]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Yosemite News]     [Gnome Users]     [KDE Users]     [Fedora Art]     [Fedora Docs]     [Fedora Sparc]     [Libvirt Users]     [Fedora ARM]

  Powered by Linux