Chris S wrote:

> Rumen Yotov wrote:
>
>> Hi,
>>
>> Beside grsec in hardened (grsec2&PaX) there is also the
>> PaX-kernel-patch.
>> If an app tries to exec data as code, then it's PaX thing. PaX refuses
>> to run data as code (if configured).
>> Check the logs to see why/who stops the program/s.
>> HTH. Rumen
>>  
>>
> Thank you, I will check that. However, short of emerging
> hardened-sources I actually have not yet turned a single security
> feature on (I was waiting until I had the system sorted first). So I
> doubt syslog will show much. I will find out however and let you know!
>
> Cheers

Hi,
Think there are some (PaX&grsec) features turned ON by default in kernel
config.
Check the kernel-config and read the PaX docs at: http://pax.grsecurity.net.
IMHO PaX config is only done/active in the kernel, later you could
change something throu: paxctl or chpax utils on some binaries/apps.
Grsec could be configured/changed later more easy (/etc/sysctl.conf &
/proc) RBAC/ACL throu gradm.
HTH. Rumen

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to