|
|||||||||||
|
Re: Debian suggestion on File Deletion
From: Marcin Owsiany <porridge(at)debian.org>
Date: Thu Dec 13 2007 - 03:08:27 EST
Thanks for your suggestion,
On Wed, Dec 12, 2007 at 12:19:28PM -0800, David de Hilario Richards wrote:
The problem is, a malicious program (virus, etc) does not need a Terminal or Trash to delete files. It just directly asks the operating system kernel to do that. The kernel obeys if (simplifying) the program is running as the user who owns the file to be deleted. This is often the case. However, there is functionality called SELinux (Security Enhanced Linux if memory serves) which allows to say specifically which programs are allowed to perform what actions. It makes it possible to restrict malicious programs from doing anything malicious. SELinux is available in the current stable release of Debian. Unfortunately, it is quite difficult to configure, and currently causes problems with programs which are not malicious as well. We hope to get it more useful in future Debian releases. Regards, -- Marcin Owsiany < porridge(at)debian.org> http://marcin.owsiany.pl/ GnuPG: 1024D/60F41216 FE67 DA2D 0ACA FC5E 3F75 D6F6 3A0D 8AA0 60F4 1216 -- To UNSUBSCRIBE, email to debian-security-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.orgReceived on Thu Dec 13 03:09:25 2007 This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 06:54:26 EDT |
||||||||||
|
|||||||||||