LIDS, SELinux, etc
Posted Mar 19, 2004 1:51 UTC (Fri) by
AnswerGuy (guest, #1256)
In reply to:
Allowed modules list by LogicG8
Parent article:
A new Adore root kit
It's not quite true that root-compromised systems *have* to be
inherently, persistenly compromised. It's CLOSE to true; but
some features in LIDS and SELinux could protect a well configured system
even from a rogue root process. These patches work by limiting root's
power and imposing additional authentication/authorization measures for
some operations.
JimD
(
Log in to post comments)