Re: Proposal: ReadOnlyDirectories /etc and /usr for network-services

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Thu, Jul 25, 2013 at 6:36 PM, Reindl Harald <h.reindl@xxxxxxxxxxxxx> wrote:
>
>
> Am 25.07.2013 17:57, schrieb drago01:
>>> in theory yes
>>>
>>> practically a exploit is not that easy like fire
>>> a bundle of commands as root like a script
>>>
>>>> So we're talking about limited circumstances where
>>>> the attacker can modify files and not execute code, or where the
>>>> attacker is root but not CAP_SYS_ADMIN (or whatever it is)
>>>
>>> a httpd running with SElinux disabled or in permissive mode with
>>
>> Here is your problem ... How about running it in enforcing mode? I mean you care ab out security and disable
>> security features at the same time. If there are selinux bugs file and/or fix them
>
> if you are able to marry pure-ftpd, samba and 250 cms-installations predictable
> on a machine running also *self developed* managment-software for a complete
> infrastructure on 20 Fedora servers with SElinux go ahead :-)

You missed the "and/or fix and file bugs" part.
It does not work so lets disable it and add hacks to get the same
functionality back is bad practice.
If it does not work we should fix it.
-- 
devel mailing list
devel@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/devel





[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux