LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-26-2010, 03:03 AM   #1
farooq.pathan
LQ Newbie
 
Registered: Mar 2010
Posts: 5

Rep: Reputation: 0
gdm-simple-gree (xdm_t) httpd_sys_content_t.


Summary:

SELinux is preventing gdm-simple-gree (xdm_t) "search" httpd_sys_content_t.

Detailed Description:

SELinux denied access requested by gdm-simple-gree. It is not expected that this
access is required by gdm-simple-gree and this access may signal an intrusion
attempt. It is also possible that the specific version or configuration of the
application is causing it to require additional access.

Allowing Access:

You can generate a local policy module to allow this access - see FAQ
(http://fedora.redhat.com/docs/selinu...fc5/#id2961385) Or you can disable
SELinux protection altogether. Disabling SELinux protection is not recommended.
Please file a bug report (http://bugzilla.redhat.com/bugzilla/enter_bug.cgi)
against this package.

Additional Information:

Source Context system_u:system_r:xdm_t:s0-s0:c0.c1023
Target Context system_ubject_r:httpd_sys_content_t:s0
Target Objects www [ dir ]
Source gdm-simple-gree
Source Path /usr/libexec/gdm-simple-greeter
Port <Unknown>
Host mail.[xyz].net
Source RPM Packages gdm-2.26.1-10.fc11
Target RPM Packages
Policy RPM selinux-policy-3.6.12-39.fc11
Selinux Enabled True
Policy Type targeted
MLS Enabled True
Enforcing Mode Enforcing
Plugin Name catchall
Host Name mail.[xyz].net
Platform Linux mail.[xyz].net 2.6.29.4-167.fc11.x86_64 #1
SMP Wed May 27 17:27:08 EDT 2009 x86_64 x86_64
Alert Count 1497
First Seen Fri Nov 26 15:17:30 2010
Last Seen Fri Nov 26 16:57:08 2010
Local ID f8cd1f18-a337-49b9-9df0-209683dfe750
Line Numbers

Raw Audit Messages

node=mail.[xyz].net type=AVC msg=audit(1290761828.686:613042): avc: denied { search } for pid=2779 comm="gdm-simple-gree" name="www" dev=dm-0 ino=35668 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_ubject_r:httpd_sys_content_t:s0 tclass=dir

node=mail.[xyz].net type=SYSCALL msg=audit(1290761828.686:613042): arch=c000003e syscall=254 success=no exit=-13 a0=12 a1=17e0e10 a2=1002fce a3=1 items=0 ppid=2753 pid=2779 auid=4294967295 uid=42 gid=42 euid=42 suid=42 fsuid=42 egid=42 sgid=42 fsgid=42 tty=(none) ses=4294967295 comm="gdm-simple-gree" exe="/usr/libexec/gdm-simple-greeter" subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 key=(null)
 
Old 11-27-2010, 04:45 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599
Quote:
Originally Posted by farooq.pathan View Post
Summary:
Please be aware we're not your personal 24/7 helpdesk on which you can unload your problems without giving it some thought. This is a Linux-oriented community built on voluntary efforts of its members, meaning mutual respect, positive interaction between members and good manners are appreciated. So next time please provide a short introduction about what what you did to cause this warning. OK?


Quote:
Originally Posted by farooq.pathan View Post
Policy RPM selinux-policy-3.6.12-39.fc11
Are you aware Fedora 11 is (or is about to be) retired?


Quote:
Originally Posted by farooq.pathan View Post
Source Path /usr/libexec/gdm-simple-greeter
Host mail.[xyz].net
Is there a specific reason a mail server should run in runlevel 5 using Xorg?
Are you aware what purpose the greeter serves?
Is there a reason, other than misconfiguration, why the greeter should be able to search your WWW directory for files anyway?


Quote:
Originally Posted by farooq.pathan View Post
You can generate a local policy module to allow this access - see FAQ
(http://fedora.redhat.com/docs/selinu...fc5/#id2961385)
Did you read the FAQ entry?
Did it show you any solutions?
If it did, did you try any of them?
And if you did, what was the result?

Last edited by unSpawn; 11-27-2010 at 04:46 AM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
gdm-simple-greeter.desktop is "Not responding" when I switch user in Fedora 11 fulee1 Linux - Newbie 6 03-26-2012 07:28 AM
[SOLVED] Arch Install with GNOME, system defaults to GDM, GDM no mouse or keyboard lupusarcanus Linux - Newbie 8 01-30-2011 04:30 PM
GDM-Simple-Greeter.desktop Daus Ubuntu 3 02-04-2010 04:48 AM
Two Simple Qs: Alsa & GDM keymap jipe Debian 1 02-24-2005 06:46 PM
KDM && GDM Simple Question shaggz Linux - General 3 02-14-2004 05:37 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:06 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration