Re: aide or tripwire

From: Seth Arnold (sarnold@wirex.com)
Date: 12/21/01


Date: Fri, 21 Dec 2001 14:17:32 -0800
From: Seth Arnold <sarnold@wirex.com>
To: focus-linux@securityfocus.com


On Fri, Dec 21, 2001 at 03:28:22PM +0100, Philipp Schulte wrote:
> No, using the kernel capabilities (http://pw1.netcom.com/~spoon/lcap/)
> can give an additional layer of security. One can't simply "chattr -i"
> if the specific capability has been removed.

Note that the *BSDs have 'securelevel' settings that allow immutable to
be turned on in any securelevel state, but can only be turned off in an
insecure state.

As a hint, I would love to see similar support for Securelevels in the
linux kernel, perhaps implemented through an LSM interface. (I've been
meaning to do it myself, but .. there isn't enough time in each day. So,
I offer it as a fun yet hopefully small project for those interested in
kernel programming. :)

Cheers!

-- 
Find out why the United States jailed a Russian citizen over a lecture:
http://www.anti-dmca.com/




Relevant Pages

  • Re: make install error
    ... Now I've again compiled custom kernel. ... That sounds to me as if you're running at a raised securelevel -- if: ... settings, in order to install your new kernel, you should reboot to ... Then you need to reboot to single user mode *again* to check that the ...
    (freebsd-questions)
  • Re: PPPoE
    ... but related aspects within the kernel. ... *** It is specifically my belief that network connections ... offered by securelevel. ... I believe userland implementations ...
    (comp.unix.bsd.openbsd.misc)
  • installing kernel with securelevel set to 2
    ... I just tried installing a kernel after compiling May 31st source and ... figured I would have to reboot to a lower securelevel, ... the kernel file and its modules could not be ... flags may ...
    (freebsd-current)
  • Re: Kernel-loadable Root Kits
    ... Well then, as I wrote to Kris, the kernel has to deny KLD loading ... > 1 Secure mode - the system immutable and system append-only flags may ... securelevel cannot be used. ... An X server is the most documented instance. ...
    (FreeBSD-Security)
  • Re: Kernel-loadable Root Kits < securelevel >
    ... >> securelevel. ... >> process can raise the security level, but no process can lower it. ... If ddb support is compiled into the kernel, then it could be as easy ...
    (FreeBSD-Security)