View previous topic :: View next topic |
Author |
Message |
cascamorto Guru
Joined: 28 Feb 2005 Posts: 373
|
Posted: Mon Apr 04, 2005 7:45 am Post subject: root security |
|
|
can i block root from accesing internet appart from emerges? so that if someone gains root access to my pc they can't connect it? and is there a way to password protect portage? _________________ The real world isn't what you thought it was going to be?
re-emerge it with gentoo linux! |
|
Back to top |
|
|
moocha Watchman
Joined: 21 Oct 2003 Posts: 5722
|
Posted: Mon Apr 04, 2005 8:01 am Post subject: Re: root security |
|
|
cascamorto wrote: | can i block root from accesing internet appart from emerges? so that if someone gains root access to my pc they can't connect it? | No, unless you give up the traditional concept of root altogether and use rsbac-sources. It's difficult though. Take a look at http://www.rsbac.org/ for more info.
cascamorto wrote: | and is there a way to password protect portage? | Er, what? Password-protect exactly what? The emerge binary? Access to the /usr/portage directory? The Gentoo mirrors? _________________ Military Commissions Act of 2006: http://tinyurl.com/jrcto
"Those who would give up essential liberty to purchase a little temporary safety deserve neither liberty nor safety."
-- attributed to Benjamin Franklin |
|
Back to top |
|
|
cascamorto Guru
Joined: 28 Feb 2005 Posts: 373
|
Posted: Mon Apr 04, 2005 9:37 am Post subject: |
|
|
I want to make it so u can't use emerge or similar things enless u insert a passsword so that theres less probability of emerging programs without it being me... _________________ The real world isn't what you thought it was going to be?
re-emerge it with gentoo linux! |
|
Back to top |
|
|
moocha Watchman
Joined: 21 Oct 2003 Posts: 5722
|
Posted: Mon Apr 04, 2005 9:45 am Post subject: |
|
|
cascamorto wrote: | I want to make it so u can't use emerge or similar things enless u insert a passsword so that theres less probability of emerging programs without it being me... | It would be theoretically possible, by writing a wrapper script for emerge, but what's the point? root can do pretty much anything - that wouldn't stop someone to install software the manual configure - make - make install way...
Once an attacker has successfully gained access to your system you can't trust anything any more anyway. _________________ Military Commissions Act of 2006: http://tinyurl.com/jrcto
"Those who would give up essential liberty to purchase a little temporary safety deserve neither liberty nor safety."
-- attributed to Benjamin Franklin |
|
Back to top |
|
|
|