LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-12-2006, 03:22 PM   #1
mshang
LQ Newbie
 
Registered: Feb 2006
Posts: 2

Rep: Reputation: 0
How to use linux capability


does anyone know how to use linux capability commands, including getcaps, setcaps, sucap and execcap.

I tried many times, like
#getpcaps $$
Capabilities for '2735': =ep cap_setpcap-eq
#setpcaps CAP_SETUID+p 2735
[caps set to: = cap_setuid+p]
Failed to set cap's on process '2735': (Operating not permitted)

Actually I also tried other processes, cannot achieve on any process. Could someone tell me how to use it in correct way?
 
Old 02-14-2006, 08:32 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
AFAIK this doesn't work and any digging around reveals the package to be b0rken or a kernel needed with SETCAP(?) flags. If you want to take away caps on a "global" scale (like module loading) I would suggest using Spoon's lcap package, elif you want to take away per-process caps use features from SELinux or GRSecurity's RBAC.
 
Old 02-14-2006, 02:00 PM   #3
mshang
LQ Newbie
 
Registered: Feb 2006
Posts: 2

Original Poster
Rep: Reputation: 0
how to make capability work

Since I don't want to disable all capabilty, I want to play with it and make sure how it works. The message "operation is not permitted" just stuck me there.

My system is fedora core4. Any suggestions to make it work? Thanks!
 
Old 02-15-2006, 08:42 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Any suggestions to make it work?
None except maybe look into SELinux or GRSecurity RBAC.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux presentation software with preview (or dual-head capability) kkempter Linux - Software 1 12-21-2006 12:20 PM
Capability g26108 Linux - General 1 09-30-2005 04:47 PM
"Excel Solver" like capability in Linux bdika Linux - Software 2 03-11-2004 03:42 PM
I can do it with less capability! Anniebaby Linux - Security 3 10-30-2003 08:51 PM
Linux Capability nitr0gen Programming 0 02-15-2002 07:31 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:32 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration