There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
access audio avg avg 8 bios blue screen boot bsod computer connection cpu crash css dell desktop dma driver drivers dvd email error excel explorer firefox firefox 3 freeze gimp graphics hard drive hardware hijackthis hjt install internet internet explorer itunes keyboard laptop macro malware monitor motherboard network networking outlook outlook 2003 outlook 2007 outlook express pio problem problems router seo server slow sound sp3 spyware trojan usb video virtumonde virus vista vundo windows windows vista windows xp winxp wireless
UNIX/Linux
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Operating Systems > UNIX/Linux >
A seatbelt for server software: SELinux blocks real-world exploits


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

 
Thread Tools
lotuseclat79's Avatar
Distinguished Member with 10,037 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
25-Feb-2008, 11:15 AM #1
A seatbelt for server software: SELinux blocks real-world exploits
LinuxWorld article (4 pages) here.

A security framework originally published by the US National Security Agency has begun to rack up an impressive list of protections agains security holes.

-- Tom

P.S. Some folks get paranoid when NSA is mentioned. There is no reason for this with regard to SELinux software when you can get the finer grain of blocking security that it offers after you get compromised and it stops the worst that can happen from happening - for example, if the root account has been compromised by malware, it can policy block changing the root password - see article for more.

Note: I checked my own Ubuntu Live CD (7.10) Gutsy Gibbon and there are some installed SELinux libs, not all of the tools, but enough to consider installing the entire set.
__________________
The independence created by philosophical insight is - in my opinion - the mark of distinction between a mere artisan or specialist and a real seeker after truth. - Einstein wrote in 1944.

Some say knowledge is power, I say knowledge without action is powerless. - lotuseclat79

Don't confuse action with movement. - Hemingway to Gardner

Imagination is more important than knowledge. - Einstein
tomdkat's Avatar
Computer Specs
Distinguished Member with 3,515 posts.
 
Join Date: May 2006
Location: S.F. Bay Area, CA
Experience: Intermediate
25-Feb-2008, 03:52 PM #2
I've been putting off configuring a SELinux enabled FC7 server I'm building because it can be "challenging", to put it nicely, to get things up and running with SELinux but I'm looking forward to the educational experience.

I just need to get motivated....

Peace...
lotuseclat79's Avatar
Distinguished Member with 10,037 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
26-Feb-2008, 03:59 PM #3
Hi tomdkat,

I assume you meant that SELinux was default enabled in FC7, and you would be reconfiguring it from its default settings - which I would save to be able to restore if needed.

-- Tom
tomdkat's Avatar
Computer Specs
Distinguished Member with 3,515 posts.
 
Join Date: May 2006
Location: S.F. Bay Area, CA
Experience: Intermediate
26-Feb-2008, 04:48 PM #4
Quote:
Originally Posted by lotuseclat79 View Post
Hi tomdkat,

I assume you meant that SELinux was default enabled in FC7, and you would be reconfiguring it from its default settings - which I would save to be able to restore if needed.
Sort of. I like to build the servers I run from source (grab the latest versions, etc) so I don't install Apache or MySQL when I install Fedora Core. As a result, I've got to do the SELinux setup by hand since the files that set that up for me don't get installed. Right now, I'm fighting with getting VsFTPd running with SELinux and I need to get the config files setup right so I can login remotely, etc.

Peace...
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are Off
Refbacks are Off

You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 03:53 PM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.