All of lore.kernel.org
 help / color / mirror / Atom feed
From: LeRoy Cressy <lcressy@telocity.com>
To: SELinux@tycho.nsa.gov
Subject: Re: [Fwd: Partial TOC for Comment]
Date: Sat, 18 Aug 2001 07:43:00 -0400	[thread overview]
Message-ID: <3B7E54C4.E19EA07E@telocity.com> (raw)
In-Reply-To: 20010817122305.P18183@vnl.com

Dale Amon wrote:
> 
> On Fri, Aug 17, 2001 at 10:49:14AM -0700, John Scroggins wrote:
> > > I find the idea of real time revokation interesting, because if
> > > you see signs of an attack in progress, you can pull the rug
> > > right out from under it... but again, only if you *realize* it
> > > is an attack.
> > >
> > After reading constantly for the last few days, help me out, please
> > point me to the portion of text that speaks about R/T revocation, so I
> > can build some info on that subject.
> 
> I'm certainly not the best person here to discuss this: it is simply
> something that I found of interest when I read the papers on the
> technology. If you revoke a capability, the change will percoloate
> through to even those who have already passed the gate and it will
> stop them cold. (However I'm not sure now that I think of it whether
> this feature was specific to FLASK or is part of SELinux).
There are some on this list using various forms of RPM or Debian package
management systems.  There is a package in the admin section of the
debian system called `slay' which will slay all the process of the user
mentioned.  If you see an unauthorized attack in progress happening you
can slay the user who is initiating the attack.  Slay will stop that
yser dead in their tracks.  As a system administrator you can then go
back and edit edit the /etc/passwd file and set the user's login shell
as false and place an * in the password field.  This will keep the
user's password in the shadow password file, but the user who's password
has been ``hacked'' can be reviewed to find the flaws in the user's
password.  


One way to tighten up security is to assign passwords and turn off the
SUID bit on /bin/passwd.  

> 
> I remember years back madly trying to finish up a project on
> a computer account that was due to expire. I pulled an all-nighter
> and the "revocation" of my account on that machine did not take
> affect until *after* I logged out. While this was a nice feature
> for a someone trying to finish a late project at a university,
> it is not the best way to run a high security system ;-)
> 
> I think the designers like Dr. Smalley are much better sources
> of information on this than I.
> 
> --
> ------------------------------------------------------
> Use Linux: A computer        Dale Amon, CEO/MD
> is a terrible thing          Village Networking Ltd
> to waste.                    Belfast, Northern Ireland
> ------------------------------------------------------
> 
> --
> You have received this message because you are subscribed to the selinux list.
> If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
> the words "unsubscribe selinux" without quotes as the message.

-- 
Rev. LeRoy D. Cressy   mailto:lcressy@telocity.com   /\_/\
                       http://www.netaxs.com/~ldc   ( o.o )
                       Phone:  215-535-4037          > ^ <

Jesus saith unto him, I am the way, the truth, and the life: 
no man cometh unto the Father, but by me. (John 14:6)

--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2001-08-18 11:43 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2001-08-17  2:07 [Fwd: Partial TOC for Comment] John Scroggins
2001-08-16 23:12 ` Dale Amon
     [not found]   ` <3B7D591A.EA28B00C@earthlink.net>
2001-08-17 11:23     ` Dale Amon
2001-08-18 11:43       ` LeRoy Cressy [this message]
     [not found]         ` <20010818084601.A7060@vnl.com>
     [not found]           ` <3B7FD0EE.398E6F02@telocity.com>
2001-08-19  4:58             ` Dale Amon
2001-08-17 17:20   ` Benjamin D. Thomas
2001-08-17 19:00     ` John Scroggins
2001-08-17 17:37   ` Conan Callen
2001-08-17 20:05     ` John Scroggins
2001-08-16 23:18 ` Dale Amon
2001-08-17 18:03 ` Conan Callen
2001-08-17 19:51   ` John Scroggins
2001-08-17 20:09     ` Conan Callen
2001-08-17 11:42       ` Dale Amon
2001-08-17 22:21       ` John Scroggins

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=3B7E54C4.E19EA07E@telocity.com \
    --to=lcressy@telocity.com \
    --cc=SELinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.