* [PATCH 5/7] procfs privacy: /proc/config.gz
@ 2005-04-18 18:51 Lorenzo Hernández García-Hierro
2005-04-18 19:25 ` Rik van Riel
0 siblings, 1 reply; 2+ messages in thread
From: Lorenzo Hernández García-Hierro @ 2005-04-18 18:51 UTC (permalink / raw)
To: linux-kernel
[-- Attachment #1.1: Type: text/plain, Size: 352 bytes --]
This patch changes the permissions of the procfs entry config.gz, thus,
non-root users are restricted from accessing it.
It's also available at:
http://pearls.tuxedo-es.org/patches/security/proc-privacy-1_kernel_configs.c.patch
--
Lorenzo Hernández García-Hierro <lorenzo@gnu.org>
[1024D/6F2B2DEC] & [2048g/9AE91A22][http://tuxedo-es.org]
[-- Attachment #1.2: proc-privacy-1_kernel_configs.c.patch --]
[-- Type: text/x-patch, Size: 536 bytes --]
diff -puN kernel/configs.c~proc-privacy-1 kernel/configs.c
--- linux-2.6.11/kernel/configs.c~proc-privacy-1 2005-04-17 18:04:39.281600856 +0200
+++ linux-2.6.11-lorenzo/kernel/configs.c 2005-04-17 18:05:33.478361696 +0200
@@ -89,7 +89,7 @@ static int __init ikconfig_init(void)
struct proc_dir_entry *entry;
/* create the current config file */
- entry = create_proc_entry("config.gz", S_IFREG | S_IRUGO,
+ entry = create_proc_entry("config.gz", S_IFREG | S_IRUSR,
&proc_root);
if (!entry)
return -ENOMEM;
[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH 5/7] procfs privacy: /proc/config.gz
2005-04-18 18:51 [PATCH 5/7] procfs privacy: /proc/config.gz Lorenzo Hernández García-Hierro
@ 2005-04-18 19:25 ` Rik van Riel
0 siblings, 0 replies; 2+ messages in thread
From: Rik van Riel @ 2005-04-18 19:25 UTC (permalink / raw)
To: Lorenzo Hernández García-Hierro; +Cc: linux-kernel
[-- Attachment #1: Type: TEXT/PLAIN, Size: 445 bytes --]
On Mon, 18 Apr 2005, Lorenzo Hernández García-Hierro wrote:
> This patch changes the permissions of the procfs entry config.gz, thus,
> non-root users are restricted from accessing it.
Why?
What is the security benefit of doing this ?
--
"Debugging is twice as hard as writing the code in the first place.
Therefore, if you write the code as cleverly as possible, you are,
by definition, not smart enough to debug it." - Brian W. Kernighan
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2005-04-18 19:26 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2005-04-18 18:51 [PATCH 5/7] procfs privacy: /proc/config.gz Lorenzo Hernández García-Hierro
2005-04-18 19:25 ` Rik van Riel
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®