Chris S wrote: > Rumen Yotov wrote: > >> Hi, >> >> Beside grsec in hardened (grsec2&PaX) there is also the >> PaX-kernel-patch. >> If an app tries to exec data as code, then it's PaX thing. PaX refuses >> to run data as code (if configured). >> Check the logs to see why/who stops the program/s. >> HTH. Rumen >> >> > Thank you, I will check that. However, short of emerging > hardened-sources I actually have not yet turned a single security > feature on (I was waiting until I had the system sorted first). So I > doubt syslog will show much. I will find out however and let you know! > > Cheers
Hi, Think there are some (PaX&grsec) features turned ON by default in kernel config. Check the kernel-config and read the PaX docs at: http://pax.grsecurity.net. IMHO PaX config is only done/active in the kernel, later you could change something throu: paxctl or chpax utils on some binaries/apps. Grsec could be configured/changed later more easy (/etc/sysctl.conf & /proc) RBAC/ACL throu gradm. HTH. Rumen
smime.p7s
Description: S/MIME Cryptographic Signature
