Re: A new kind of security needed



In message <200807241639.m6OGda4b004216@xxxxxxxxxxxxxxxxxxxx>, Matthew Dillon w
rites:
Doesn't OpenBSD have a syscall filtering mechanic where one can restrict
the file paths the program is allowed to access?

Yes they do.

Really smart programs modify the strings after the check and get
to access the files anyway.

--
Poul-Henning Kamp | UNIX since Zilog Zeus 3.20
phk@xxxxxxxxxxx | TCP/IP since RFC 956
FreeBSD committer | BSD since 4.3-tahoe
Never attribute to malice what can adequately be explained by incompetence.
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Could not load or run "C:Users
    ... Check the run keys in the registry for strings that reference those file paths. ... Run regedit from the start/search line, expand and examine these keys: ...
    (microsoft.public.windows.vista.performance_maintenance)
  • Re: Comparing strings from the back?
    ... I'm comparing *random* character strings or ... all strings in the English language (having a given number of characters) is ... The distribution is not uniform over the set of all possible character ... strings representing file paths then it is not uncommon that many of those ...
    (comp.lang.python)
  • Oracle StoredProc from VB 6.0
    ... I am trying to find out how to Call Oracle Stored Proc from VB6.0 + ... ado that takes in three strings as IN parameters and outputs an array ... of records or result set having file names and file paths. ...
    (microsoft.public.data.ado)
  • Oracle StoredProc from VB 6.0
    ... I am trying to find out how to Call Oracle Stored Proc from VB6.0 + ... ado that takes in three strings as IN parameters and outputs an array ... of records or result set having file names and file paths. ...
    (comp.databases.oracle.server)
  • convert structured strings to possibly deep hash of hashes
    ... I have a list of well structured strings, actually they are file paths. ... have read perlref and perlreftut and my perl bookbut I am not ... seeing how to recursibely build/populate a HOH in this situation. ...
    (comp.lang.perl.misc)