All of lore.kernel.org
 help / color / mirror / Atom feed
* strange audit messages from the dhcpc_t domain
@ 2002-02-02 16:43 Paul Krumviede
  2002-02-04 15:07 ` Stephen Smalley
  0 siblings, 1 reply; 3+ messages in thread
From: Paul Krumviede @ 2002-02-02 16:43 UTC (permalink / raw)
  To: selinux

i just noticed a few strange denials on a RH 7.2 system running the 
2.4.17-kernel
version. the machine is using DHCP on eth1 and gets assigned an address of
172.16.218.138.

1)	Feb  1 04:02:05 fermat kernel: avc:  denied  { recvfrom } for  pid=2235 
	exe=/usr/sbin/sendmail saddr=0.4.172.16 daddr=218.138.0.0 netif=eth1 
	scontext=system_u:system_r:dhcpc_t
	tcontext=system_u:object_r:netmsg_eth1_t tclass=packet_socket

why is sendmail running in the dhcpc_t domain? and the saddr and daddr 
values look
mangled.

2)	Feb  2 02:37:10 fermat kernel: avc:  denied  { recvfrom } for
	saddr=172.16.218.254 source=17680
	daddr=172.16.218.138 dest=328
	netif=eth1
 	scontext=system_u:system_r:dhcpc_t
	tcontext=system_u:object_r:netmsg_eth1_t tclass=packet_socket

this looks correct, while

3)	Feb  2 02:42:06 fermat kernel: avc:  denied  { recvfrom } for
	saddr=0.8.172.16
	daddr=218.1.0.0
	netif=eth1 scontext=system_u:system_r:dhcpc_t
	tcontext=system_u:object_r:netmsg_eth1_t
	tclass=packet_socket

this also seems to have mangled the saddr/daddr fields (and if i reconstruct
the fields as 172.16.218.1, i don't think that machine would ever emit DHCP
or BOOTP messages, although i could be wrong).

-paul


--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2002-02-04 17:01 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-02-02 16:43 strange audit messages from the dhcpc_t domain Paul Krumviede
2002-02-04 15:07 ` Stephen Smalley
2002-02-04 16:52   ` Paul Krumviede

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.