All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] Allowing aplication to run bin_t
@ 2009-08-20 14:14 Nicky726
  2009-08-20 16:01 ` Christopher J. PeBenito
  0 siblings, 1 reply; 2+ messages in thread
From: Nicky726 @ 2009-08-20 14:14 UTC (permalink / raw)
  To: refpolicy

Hello,

when writing a policy for Konqueror I came by to an issue 
of allowing it to run an aplication in bin_t (drkonqi).

According to Dominick Grift it is no big deal to allow that
(http://oss.tresys.com/pipermail/refpolicy/2009-
August/001291.html)

So is that considered safe and what would be possible 
security riscs of allowing it?


Thanks for responses,

Ondrej Vadinsky

^ permalink raw reply	[flat|nested] 2+ messages in thread

* [refpolicy] Allowing aplication to run bin_t
  2009-08-20 14:14 [refpolicy] Allowing aplication to run bin_t Nicky726
@ 2009-08-20 16:01 ` Christopher J. PeBenito
  0 siblings, 0 replies; 2+ messages in thread
From: Christopher J. PeBenito @ 2009-08-20 16:01 UTC (permalink / raw)
  To: refpolicy

On Thu, 2009-08-20 at 16:14 +0200, Nicky726 wrote:
> when writing a policy for Konqueror I came by to an issue 
> of allowing it to run an aplication in bin_t (drkonqi).
> 
> According to Dominick Grift it is no big deal to allow that
> (http://oss.tresys.com/pipermail/refpolicy/2009-
> August/001291.html)
> 
> So is that considered safe and what would be possible 
> security riscs of allowing it?

The main risk is arbitrary code execution.  Many system programs are
labeled bin_t, and konqueror would be able to execute any of them.
These programs are system binaries, so they should be safe to execute
(few domains can write to bin_t).  They would still be constrained by
konqueror's domain, so the risk depends on how privileged konqueror is.

-- 
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2009-08-20 16:01 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-08-20 14:14 [refpolicy] Allowing aplication to run bin_t Nicky726
2009-08-20 16:01 ` Christopher J. PeBenito

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.