Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old July 9th, 2012, 10:22 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: Chrome sandboxing method, for other applications?

@ m00n,

Apparmor does work by pathname, that's correct. SELinux does not though.

Quote:
Microsofts own 64-bit kernel protection seems to hold off some bad software but at the same time "preventing" good software like sandboxie or full blown av products to do their job well. Hence the "64-bit experimental mode" inside sandboxie to somehow work with 64bit kernel of windows.

Anyway, I'm going on a limb here, please forgive me for saying this but:
It almost seems if Microsoft doesn't want software like shadow defender or returnil or deep freeze to work, so that AV/anti-malware companies stay in business !
They likely don't. Linux allows for multiple different LSMs through the kernel but this actually opens up a hole for attack. The only way around this is to choose only a single LSM and have it be the only one allowed to work. Taht would mean all distros would have to use AppArmor or SELinux or whatever other one.

Microsoft decided they don't want to give that choice to the users so they created their own security model, MIAC, and they're enforcing only that.
__________________
  #27  
Old July 9th, 2012, 10:42 PM
Gullible Jones
 
Posts: n/a
Default Re: Chrome sandboxing method, for other applications?

Opens up a hole for attack how? I was under the impression that LSMs could only be changed or disabled on boot. And is this something purely theoretical, or has it been exploited in practice?
  #28  
Old July 9th, 2012, 11:55 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: Chrome sandboxing method, for other applications?

Quote:
Because LSM is compiled and enabled in the kernel, its symbols are exported. Thus, every rootkit and backdoor writer will have every hook he ever wanted in the kernel. This will allow for a new generation of sophisticated backdoors and rootkits that will be nearly impossible to detect.
-httxs://grsecurity.net/lsm.php-

https://www.linux.com/learn/linux-tr...dule-what-isnt
__________________
  #29  
Old July 10th, 2012, 07:57 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,457
Default Re: Chrome sandboxing method, for other applications?

Quote:
Originally Posted by Hungry Man
@ m00n,

Apparmor does work by pathname, that's correct. SELinux does not though.[...]

Yep. I'd pick SELinux if I were using Linux. I prefer its method of protection over AppArmor.
  #30  
Old July 10th, 2012, 11:30 AM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: Chrome sandboxing method, for other applications?

You say that now =p but when you see a SELinux profile you'll change your mind.
__________________
  #31  
Old July 10th, 2012, 11:40 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,457
Default Re: Chrome sandboxing method, for other applications?

Quote:
Originally Posted by Hungry Man
You say that now =p but when you see a SELinux profile you'll change your mind.

No pain, no gain.
  #32  
Old July 10th, 2012, 03:28 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: Chrome sandboxing method, for other applications?

True. I would rather just use SELinux but it's a huge amount of pain for not a ton of gain =p
__________________
 

Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:41 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums