Re: [PATCH] kernel: make /proc/kallsyms mode 400 to reduce ease of attacking

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: H. Peter Anvin
Date: Monday, November 29, 2010 - 12:03 pm

On 11/25/2010 11:38 PM, Ingo Molnar wrote:

The setting of these policies needs to be figured out sensibly.

One of my great complaints about several Linux distributions is that
they keep forcing log files to be readable only by root, even though
they do put the adm group in their default group file -- the adm group
is traditionally the group allowed to read log files.

It is a *good* thing for a *restricted set* of users to have *readonly*
access to this kind of information -- i.e., a group.  It is *not* a good
thing for system security or reliability to force the administrator to
assert root privileges to merely monitor information.

	-hpa
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [PATCH] kernel: make /proc/kallsyms mode 400 to reduce ..., Richard W.M. Jones, (Sat Nov 20, 4:05 am)
Re: [PATCH] kernel: make /proc/kallsyms mode 400 to reduce ..., H. Peter Anvin, (Mon Nov 29, 12:03 pm)