Re: [AppArmor 01/41] Pass struct vfsmount to the inode_create LSM hook

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: david
Date: Saturday, June 2, 2007 - 7:27 am

On Sat, 2 Jun 2007, Valdis.Kletnieks@vt.edu wrote:


actually, this is _exactly_ where AppArmor is the most useful. if the PHP 
script is restricted by AppArmor it won't be able to go out and touch 
things that it's not supposed to.


if you are targeting one specific company or one specific server then you 
are correct, however most attacks are not that targeted, they do things 
like useing google to find random servers that are running vunerable 
software and attack that (or just try the attack against random IP 
addresses in case it happens to be running the vunerable software)

David Lang
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_cre ..., david, (Sat Jun 2, 7:27 am)