Upgrade to Pro — share decks privately, control downloads, hide ads and more …

"Secure Linux" Primer

"Secure Linux" Primer

More Decks by Toshiharu Harada / 原田 季栄

Other Decks in Technology

Transcript

  1. DAC The owner can set the access attributes for his/her

    resource. This is called DAC (Discretionary Access Control). example: % chmod 600 my_diary
  2. ڻ

  3. • Unfortunately, DAC can be overridden • You should set

    DAC carefully, but should not trust it • When is DAC broken?
  4. root user root user is not affected by DAC. root

    user is the God (if your Linux is not “security enhanced” Linux)
  5. setuid a process invoked by a program with setuid attribute

    will be given root privilege. that’s why you can change your password stored in /etc/ shadow which is posessed by “root”.
  6. Trademarks • Linux® is a registered trademark of Linus Torvalds

    in the United States and other countries. • AppArmor® is a registered trademark of Novell, inc in the United States and other countries. • TOMOYO® is a registered trademark of NTT DATA CORPORATION in Japan.
  7. Concept and story by Toshiharu Harada (NTT DATA CORPORATION) Illustration

    by Yumiko Tatsumoto (NTT DATA CORPORATION) and Akira Igarashi in association with Studio Padre Special thanks to ͔͑Δ޻๪ of NTT DATA CORPORATION ݟ ࠶