LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-18-2010, 07:08 PM   #1
vlad031
LQ Newbie
 
Registered: Nov 2010
Location: Europe
Distribution: RedHat
Posts: 3

Rep: Reputation: 0
Question /proc permissions


I'm looking for a kernel patch that will make new dirs in /proc to be 0550 instead of 0555... I'm building an hosting server and I don't want the users see what other processes are running on the sys...
What I want to achieve: when a new process gets started, it's "pid" directory will have 0550 perms...

I did some modifying on kernel/sysctl.c in the kernel code, but with no luck... any ideas?!

cheers!
 
Old 11-18-2010, 08:43 PM   #2
stress_junkie
Senior Member
 
Registered: Dec 2005
Location: Massachusetts, USA
Distribution: Ubuntu 10.04 and CentOS 5.5
Posts: 3,873

Rep: Reputation: 335Reputation: 335Reputation: 335Reputation: 335
You might have a look at SELinux. That is highly configurable. It's probably already installed in your system.
 
Old 11-18-2010, 09:35 PM   #3
vlad031
LQ Newbie
 
Registered: Nov 2010
Location: Europe
Distribution: RedHat
Posts: 3

Original Poster
Rep: Reputation: 0
Wink

nope ... Selinux is not an option due to some implementation on my system which made me remove selinux... I'm looking strictly for an answer to my problem, not workarounds!
cheers!
 
Old 11-18-2010, 09:45 PM   #4
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by vlad031 View Post
I'm building an hosting server and I don't want the users see what other processes are running on the sys...
The grsecurity patch includes this functionality.

Well, it can make it so that a user only sees his/her own processes.

Last edited by win32sux; 11-18-2010 at 09:58 PM.
 
1 members found this post helpful.
Old 11-18-2010, 11:14 PM   #5
syg00
LQ Veteran
 
Registered: Aug 2003
Location: Australia
Distribution: Lots ...
Posts: 20,823

Rep: Reputation: 4004Reputation: 4004Reputation: 4004Reputation: 4004Reputation: 4004Reputation: 4004Reputation: 4004Reputation: 4004Reputation: 4004Reputation: 4004Reputation: 4004
I would have thought that if you were doing hosting, use a system designed for it from the ground up. The devs have ironed out all the problems you haven't even thought of. Containers provides this isolation "out of the box" with something like vserver.
 
Old 11-19-2010, 08:16 AM   #6
vlad031
LQ Newbie
 
Registered: Nov 2010
Location: Europe
Distribution: RedHat
Posts: 3

Original Poster
Rep: Reputation: 0
Talking

Quote:
Originally Posted by win32sux View Post
The grsecurity patch includes this functionality.

Well, it can make it so that a user only sees his/her own processes.
GREAT!!! That's exactly what I was looking for! Thanks a lot!
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Automatic RW Permissions to all users for /proc/bus/usb/BN/DN avjrb Linux - Newbie 1 09-22-2009 11:30 PM
Boot hang after 'proc on /proc type proc (rw)' Hagoromo Slackware 13 10-05-2007 05:03 PM
/proc permissions help oldtincup Linux - Security 6 03-27-2006 01:39 PM
Accidentally changed the permissions of /proc/, help restoring them please Th3James Linux - General 5 01-24-2006 03:24 AM
/proc Permissions VCore5.0 Linux - Security 3 11-28-2005 05:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:43 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration