Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> With SELinux root can build systems which are so secure that root himself cannot hack them.

Sounds like your administrator would be well served to spend more time studying real-world vulnerabilities and less time focusing on SELinux :)

See eg. http://grsecurity.net/~spender/exploits/exploit2.txt



The exploiting process wouldn't have access to /dev/net/tun if SELinux was configured properly...

So it technically would extinguish itself there and then.

It works on the principle of least privilege so you start with nothing and add what the process needs.


No True SELinuxman, I see




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: