All of lore.kernel.org
 help / color / mirror / Atom feed
* pam_namespace
@ 2006-05-05  6:23 Russell Coker
  2006-05-05  7:50 ` pam_namespace Valdis.Kletnieks
  2006-05-11 13:45 ` pam_namespace Rogelio Serrano
  0 siblings, 2 replies; 29+ messages in thread
From: Russell Coker @ 2006-05-05  6:23 UTC (permalink / raw)
  To: SE-Linux

I was just playing with pam_namespace.  It seems to me that the current setup 
of having tmp/tmp.inst-$USER- does not provide adequate protection.  A 
process that is hostile to the user and which runs in the system name space 
(EG any cracked daemon) can access the user's instance of /tmp.

If we had tmp/tmp.inst-$USER-/tmp (or something similar) and 
gave /tmp/tmp.inst-$USER- permission mode 000 (and something equivalent in 
terms of SE Linux access) then processes in the global name space would not 
be able to try anything.


PS  I am posting here because I am no longer subscribed to the LSPP list.

-- 
http://www.coker.com.au/selinux/   My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/  Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/    Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/  My home page

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 29+ messages in thread

end of thread, other threads:[~2006-05-12  5:00 UTC | newest]

Thread overview: 29+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-05-05  6:23 pam_namespace Russell Coker
2006-05-05  7:50 ` pam_namespace Valdis.Kletnieks
2006-05-05  9:14   ` pam_namespace Russell Coker
2006-05-05 10:06     ` pam_namespace Valdis.Kletnieks
2006-05-07  9:28       ` pam_namespace Russell Coker
2006-05-08  1:07         ` pam_namespace Valdis.Kletnieks
2006-05-08  3:27           ` pam_namespace Russell Coker
2006-05-08 13:44             ` pam_namespace Janak Desai
2006-05-08 20:32               ` pam_namespace Valdis.Kletnieks
2006-05-09 12:57               ` pam_namespace Russell Coker
2006-05-09 14:02                 ` pam_namespace Russell Coker
2006-05-09 14:41                   ` pam_namespace Janak Desai
2006-05-09 14:13                 ` pam_namespace Janak Desai
2006-05-09 22:53                   ` pam_namespace Russell Coker
2006-05-10 14:10                     ` pam_namespace Janak Desai
2006-05-11  0:04                       ` pam_namespace Russell Coker
2006-05-11 13:28                         ` pam_namespace Janak Desai
2006-05-12  4:14                           ` pam_namespace Rogelio Serrano
2006-05-12  5:00                             ` pam_namespace Russell Coker
2006-05-08  1:37         ` pam_namespace Russell Coker
2006-05-08 22:39           ` pam_namespace Thomas Bleher
2006-05-09 12:07             ` pam_namespace Stephen Smalley
2006-05-09 13:12             ` pam_namespace Janak Desai
2006-05-11 13:45 ` pam_namespace Rogelio Serrano
2006-05-11 13:57   ` pam_namespace Stephen Smalley
2006-05-12  4:09     ` pam_namespace Rogelio Serrano
2006-05-11 23:09   ` pam_namespace Russell Coker
2006-05-12  4:00     ` pam_namespace Rogelio Serrano
2006-05-12  4:52       ` pam_namespace Russell Coker

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.