Grsecurity
- 管理工具
- Grsecurity/The Administration Utility链接en.wikibooks.org/wiki/Grsecurity/The_Administration_Utilityhttps://grsecurity.net/ · 管理工具 · Grsecurity/The Administration Utility · 附加工具 · Grsecurity/Additional Utilities · paxctl笔记:Grsecurity
- 附加工具
-
Grsecurity/Additional Utilities链接en.wikibooks.org/wiki/Grsecurity/Additional_Utilitieshttps://grsecurity.net/ · 管理工具 · Grsecurity/The Administration Utility · 附加工具 · Grsecurity/Additional Utilities · paxctl笔记:Grsecurity
-
paxctl
- Controlling PaX Flags
- 控制可执行文件的 PaX 标记
-
pspax
- Displaying Program Capabilities
en.wikibooks.org/wiki/Grsecurity/Application-specific_Settings
-
Wikipedia:GrsecurityWikipediaGrsecurity
- moby/moby#20303GitHub Issuemoby/moby#20303
grep -e PAX_MPROTECT= -e GRKERNSEC= /boot/config-hardened
sysctl kernel.grsecurity.chroot_deny_chmod
grep -e GRKERNSEC_CHROOT /boot/config-hardened
# https://pkgs.alpinelinux.org/package/v3.7/main/x86_64/paxctl
apk add paxctl
# https://pkgs.alpinelinux.org/package/v3.7/main/x86_64/gradm
# https://en.wikibooks.org/wiki/Grsecurity/The_Administration_Utility
# gradm grsecurity RBAC administration and policy analysis utility
apk add gradmsysctl -w kernel.pax.softmode=1 echo 'kernel.pax.softmode=1' >> /etc/sysctl.conf
wiki.gentoo.org/wiki/Hardened/PaX_Quickstart
hardenedlinux.github.io/system-security/2016/08/10/grsec-kernel-full-commentary.html
use of CAP_SYS_ADMIN in chroot denied
sysctl -w kernel.grsecurity.chroot_caps=0 sysctl -w kernel.grsecurity.chroot_deny_mount=0
en.wikibooks.org/wiki/Grsecurity/Appendix/Grsecurity_and_PaX_Configuration_Options
PAX_MPROTECT Enabling this option will prevent programs from
- changing the executable status of memory pages that were not originally created as executable,
- making read-only executable pages writable again,
- creating executable pages from anonymous memory,
- making read-only-after-relocations (RELRO) data pages writable again.
You should say Y here to complete the protection provided by the enforcement of non-executable pages.
NOTE: you can use the 'chpax' or 'paxctl' utilities to control this feature on a per file basis.
PAX_SOFTMODE Enabling this option will allow you to run PaX in soft mode, that is, PaX features will not be enforced by default, only on executables marked explicitly. You must also enable PT_PAX_FLAGS or XATTR_PAX_FLAGS support as they are the only way to mark executables for soft mode use.
Soft mode can be activated by using the "pax_softmode=1" kernel command line option on boot. Furthermore you can control various PaX features at runtime via the entries in /proc/sys/kernel/pax.
关联信息
反向链接、本文链接的其他页面和外部资料。
反向链接
- Alpine 入门笔记 · Hardened
Small. Simple. Secure. · Alpine Linux is a security-oriented, lightweight Linux distribution based on musl libc and busybox.
参考资料
GitHub1 条
- moby/moby#20303github.com/moby/moby/issues/20303
Wikipedia1 条
- GrsecurityWikipedia:Grsecurity
其他外链7 条
- en.wikibooks.org/wiki/Grsecurity/Additional_Utilitiesen.wikibooks.org/wiki/Grsecurity/Additional_Utilities
- en.wikibooks.org/wiki/Grsecurity/Appendix/Grsecurity_and_PaX_Configuration_Optionsen.wikibooks.org/wiki/Grsecurity/Appendix/Grsecurity_and_PaX_Configuration_Options
- en.wikibooks.org/wiki/Grsecurity/Application-specific_Settingsen.wikibooks.org/wiki/Grsecurity/Application-specific_Settings
- en.wikibooks.org/wiki/Grsecurity/The_Administration_Utilityen.wikibooks.org/wiki/Grsecurity/The_Administration_Utility
- grsecurity.netgrsecurity.net/
- hardenedlinux.github.io/system-security/2016/08/10/grsec-kernel-full-commentary.htmlhardenedlinux.github.io/system-security/2016/08/10/grsec-kernel-full-commentary.html
- wiki.gentoo.org/wiki/Hardened/PaX_Quickstartwiki.gentoo.org/wiki/Hardened/PaX_Quickstart