Re: hardening BSD (was systrace/stsh policies)

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Janne Johansson
Date: Monday, October 15, 2007 - 8:46 am

Eduardo Tongson wrote:

I actually dont think it is all worthless. Imagine a machine running a 
server daemon. If you systrace that particurlar daemon to not be able to 
fork()/exec*() or system(), you could be quite sure it wont start random 
apps on your machine in case someone manages to trick it somehow.

Now, if the attacker already has a local account and/or shell, he might 
run races and fool the systrace. But if this daemon was the only way for 
said attacker to gain such shell access, and it can be prevented from 
doing common stuff needed to get a local shell then you would have a 
"safer" system.

In this way, systrace might be usable still, even though it wont suffice 
for systrace'd shells given out to bad guys. Same as all other measures 
you might have like chroots, stack gaps, randomized mem layouts and 
library addresses, they never prevent 100% of all attacks, just many of 
them.

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
systrace/stsh policies, Xavier Mertens, (Thu Oct 11, 11:54 am)
Re: systrace/stsh policies, Joachim Schipper, (Thu Oct 11, 3:05 pm)
hardening BSD (was systrace/stsh policies), Aaron, (Sun Oct 14, 1:27 pm)
Re: hardening BSD (was systrace/stsh policies), Darren Spruell, (Sun Oct 14, 2:07 pm)
Re: hardening BSD (was systrace/stsh policies), Steve Shockley, (Sun Oct 14, 8:40 pm)
Re: hardening BSD (was systrace/stsh policies), Francesco Toscan, (Sun Oct 14, 11:31 pm)
Re: hardening BSD (was systrace/stsh policies), Eduardo Tongson, (Sun Oct 14, 11:32 pm)
Re: hardening BSD (was systrace/stsh policies), Nick Guenther, (Mon Oct 15, 8:37 am)
Re: hardening BSD (was systrace/stsh policies), Janne Johansson, (Mon Oct 15, 8:46 am)
Re: hardening BSD (was systrace/stsh policies), Ted Unangst, (Mon Oct 15, 10:54 am)
Re: hardening BSD (was systrace/stsh policies), Joachim Schipper, (Mon Oct 15, 1:10 pm)
Re: hardening BSD (was systrace/stsh policies), Joachim Schipper, (Wed Oct 17, 12:15 pm)
Re: hardening BSD (was systrace/stsh policies) , Theo de Raadt, (Wed Oct 17, 12:28 pm)