LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-22-2018, 09:16 PM   #1
wzis
LQ Newbie
 
Registered: Dec 2013
Posts: 17

Rep: Reputation: 0
Why for better security, All linux kernel should have fanotify enabled


and a way to limit programs that can use fanotify should be implemented.
fanotify allows security software to truly block others' access to certain files. But that also will allow the hacker to use it to hide illegal change to critical files. That's why there should be some certification system to allow and deny program's access to it.
 
Old 01-23-2018, 02:27 PM   #2
MensaWater
LQ Guru
 
Registered: May 2005
Location: Atlanta Georgia USA
Distribution: Redhat (RHEL), CentOS, Fedora, CoreOS, Debian, FreeBSD, HP-UX, Solaris, SCO
Posts: 7,831
Blog Entries: 15

Rep: Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669
Quote:
Originally Posted by wzis View Post
That's why there should be some certification system to allow and deny program's access to it.
You mean like SELinux?

 
Old 01-23-2018, 03:50 PM   #3
syg00
LQ Veteran
 
Registered: Aug 2003
Location: Australia
Distribution: Lots ...
Posts: 21,119

Rep: Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120Reputation: 4120
Hardly new news - when I looked at it (years ago) fanotify_init needed CAP_SYS_ADMIN. That would be root.
 
Old 01-26-2018, 05:26 PM   #4
wzis
LQ Newbie
 
Registered: Dec 2013
Posts: 17

Original Poster
Rep: Reputation: 0
Both SELinux and just limit it to root are not good enough.
It needs something that only certain certified programs can use fanotify and even root can't easily change that.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Lack of FANOTIFY support in kernel in 14.2? horizn Slackware 4 07-27-2016 02:29 PM
mongodb performance with security enabled tripialos Linux - Server 2 06-29-2014 11:06 AM
how to programatically determine if hyperthreading is enabled in linux kernel shawshank_blr Linux - Kernel 2 07-03-2009 07:14 AM
FTP failing when security enabled DavidCasper Linux - Security 1 12-30-2004 04:10 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:35 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration