TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

What does SELinux do to contain the the bash exploit?

39 点作者 nsaje超过 10 年前

7 条评论

616c超过 10 年前
I think a lot of people will disparage and mock Dan (FYI he is a core SELinux developer for Fedora if you do not know), but I think he outlines that it does prevent the medium risk stuff which I think no base Linux system (without MAC systems (SELinux, RBAC, AppArmor,etc.), just DAC of Unix file permissions) would let pass easily. All the logs, all the non-root data which hackers would use to build up to move forward in their operation.<p>I guess CGI scripting is convenient and necessarry for most of us (just like bash itself), and SELinux did not prevent Heartbleed either. But that does not mean I will make coloring jokes about its inefficacy.
评论 #8371878 未加载
评论 #8371847 未加载
评论 #8372604 未加载
willvarfar超过 10 年前
I&#x27;m a big fan of SELinux, and for many shellshock attacks it will limit exposure, but Dan should know better than invite people to ask him how SELinux helps mitigate a dchp shellshock attack...
mrmondo超过 10 年前
Big fan of SELinux here - it&#x27;s really saved my ass a few times and the best thing about it is that these days it&#x27;s so damn easy to configure that you&#x27;re mad not to use it.
devicenull超过 10 年前
<p><pre><code> Lets look at what it can read. ... It can read apache static content, like web page data. Well what can&#x27;t it read? user_home_t - This is where I keep my credit card data *db_t - No database data. </code></pre> So, it can&#x27;t read database data directly, but presumably your website can already connect to the database. Which means it can read out your database credentials, and just connect to the database?
treed超过 10 年前
There are lots of stories of SELinux saves out there now. This is one I saw just recently:<p><a href="https://www.reddit.com/r/linux/comments/1xdokz/selinux_saved_our_asses_xpost_rselinux/" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;linux&#x2F;comments&#x2F;1xdokz&#x2F;selinux_saved...</a><p>I myself have had several SELinux saves. It&#x27;s definitely proven itself valuable as an additional security control.
qwerta超过 10 年前
It is like asking if it would catch SQL injections. Just sanitize your inputs !
yarrel超过 10 年前
&quot;SELinux does not block the exploit&quot;<p>Of course not. The exploit doesn&#x27;t come in coloring book form.
评论 #8371632 未加载