mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* grsec chroot; deny raw access (WAS: RE: chroot() breaks syslog() ?)
@ 2003-08-07 12:02 Oliver Pitzeier
  0 siblings, 0 replies; only message in thread
From: Oliver Pitzeier @ 2003-08-07 12:02 UTC (permalink / raw)
  To: herbert, linux-kernel

Oliver Pitzeier wrote <oliver@linux-kernel.at> wrote:
> Herbert Pötzl <herbert@13thfloor.at> wrote:
> [ ... ]
> > hmm, how will you avoid creation of special (devicenodes) 
> > files if I have raw access to any partition? I can 'simply'
> > use xxd to create my special inodes on the medium ... and I
> > would not care if mount is enabled or not when I wipe the
> > root partition with dd ...
> 
> AFAIK, there are possibilities to deny _RAW_ access to 
> partitions, while in a chroot-jail... If not, I'll tell the 
> grsec-team to implement a new feature. :)

I had contact to one of the grsec folks. He told me that it IS
possible, if you have enabled the ACL system...

The original mail he sent me was:

> I noticed your lkml post.  grsecurity will indeed deny raw
> access to block devices in a chroot, but only if the ACL
> system is enabled.

Herbert, I hope that helps? :)

Best regards,
 Oliver


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2003-08-07 12:04 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2003-08-07 12:02 grsec chroot; deny raw access (WAS: RE: chroot() breaks syslog() ?) Oliver Pitzeier

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®