Es un marchi de seguridad avanzado para el kernel, con estas features:

#       grsecurity 2.0 RBAC features Role-Based Access Control
# User, group, and special roles
# Role transition tables
# IP-based roles
# Non-root access to special roles
# Special roles that require no authentication
# Nested subjects
# Variable support in configuration
# And, or, and difference set operations on variables in configuration
# Object mode that controls the creation of setuid and setgid files
# Create and delete object modes
# /dev/grsec entry for kernel authentication and learning logs
# Next-generation code that produces least-privilege policies for the entire system 
with no configuration
# Full pathnames for offending process and parent process
# RBAC status function for gradm
# /proc/<pid>/ipaddr gives the remote address of the person who started a given process
# All other features of grsecurity 1.9.x MAC system

# Chroot restrictions No attaching shared memory outside of chroot
# No kill outside of chroot
# No ptrace outside of chroot (architecture independent)
# No capget outside of chroot
# No setpgid outside of chroot
# No getpgid outside of chroot
# No getsid outside of chroot
# No sending of signals by fcntl outside of chroot
# No viewing of any process outside of chroot, even if /proc is mounted
# No mounting or remounting
# No pivot_root
# No double chroot
# No fchdir out of chroot
# Enforced chdir("/") upon chroot
# No (f)chmod +s
# No mknod
# No sysctl writes
# No raising of scheduler priority
# No connecting to abstract unix domain sockets outside of chroot
# Removal of harmful privileges via capabilities
# Exec logging within chroot

Y tiene una BANDA mas, es MUY bueno, pero configura y lee con detalle, aca sigue:

http://www.grsecurity.org/features.php

On Mon, 12 Jan 2004 12:58:35 -0300
[EMAIL PROTECTED] wrote:

> Disculpen mi ignoracia, pero que caraj... es GR-Security?
> 
> -----Mensaje original-----
> De: Alberto Ferrer 
> 
> Compilate un Kernel con GR-Security, y mientras no tenga ningun software
> viejo o "explotable dale una shellcita, conseguite alguna proteccion para
> bombas fork, asi
> no te intentan colgar la pc, con eso creo que basta.
> 
> On Sun, 11 Jan 2004 22:40:48 +0000
> _______________________________________________
> Lugro mailing list
> [EMAIL PROTECTED]
> http://www.lugro.org.ar/mailman/listinfo/lugro
> 
> 


-- 
--------------------------
     Alberto Ferrer
  [EMAIL PROTECTED]
 http://www.barrahome.org
JID: [EMAIL PROTECTED]
--------------------------
SNMP = Security? Not My Problem!

Attachment: pgp00000.pgp
Description: PGP signature

Responder a