![]() |
|
#1
|
||||
|
||||
|
http://outflux.net/teach-seccomp/
Quote:
Very cool. Using this with AppArmor/SELinux/Chroot will provide an incredibly fine-grained sandbox. Hopefully we start getting profiles for common applications. It looks like applications are compiled with it as well.
__________________
|
|
#2
|
||||
|
||||
|
Quote:
Right when I started craving more security this happens
__________________
E-Mail: og8oh@notsharingmy.info |
|
#3
|
||||
|
||||
|
http://scarybeastsecurity.blogspot.c...mp-filter.html
This program is now supporting it as well. The developer (smart guy, he's blogged a bit about security in the past) states that it would effectively prevent multiple kernel exploits (he lists a few examples) that have been used previously. The seccomp filters really compliment LSM. Most sandboxes are bypassed either through a kernel exploit or design flaw and filters really drives up the cost of kernel exploitation. In my opinion seccomp is the biggest security improvement since MAC policies through LSM.
__________________
|
|
#4
|
||||
|
||||
|
Quote:
![]()
__________________
One can't be too rich, too thin, or too secure |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|