5 msgDSA/DSS keys and DSA 1576-1/CVE-2008-0166.
2 msgopenssl/openssh fixes for lenny (testing)
2 msgopenssl / x509 certs
2 msgleakage of keys?
2 msgdowkd.pl - how the blacklist data is generated ?
8 msgRe: [SECURITY] [DSA 1576-1] New openssh package...
4 msgdowkd.pl via Package
1 msgCHAO BAN
32 msgRe: [SECURITY] [DSA 1571-1] New openssl package...
4 msgBroken link on Debian CVE Web page (Was: [SECUR...
10 msgRe: [SECURITY] [DSA 1571-1] New openssl package...
3 msgRe: [SECURITY] [DSA 1575-1] New Linux 2.6.18 pa...
1 msgMystery of Lyle & Louise is Making Headlines
1 msgHerr Bühler Arbeite nicht mehr bei der V-ZUG AG
5 msgRe: [SECURITY] [DSA 1573-1] New php5 packages f...
4 msgRe: [SECURITY] [DSA 1572-1] New php5 packages f...
3 msgQuestion about Security

securing server
\ Jean-Paul Lacquement (7 May 2008)
. \ Yves-Alexis Perez (7 May 2008)
. . \ Jean-Paul Lacquement (7 May 2008)
. . . \ Abdul Bijur Vallarkodath (7 May 2008)
. . . . \ Steve (7 May 2008)
. . . . . \ Arture Le Coiffeur (7 May 2008)
. . . . . \ Abdul Bijur Vallarkodath (7 May 2008)
. . . . . . \ Steve (7 May 2008)
. . . . . . \ Harry Jackson (7 May 2008)
. . . . . . \ Daniel Leidert (7 May 2008)
. . . . . \ Bernd Eckenfels (7 May 2008)
. . . . \ Oliver Antwerpen (7 May 2008)
. . . . . \ Rich Healey (13 May 2008)
. \ weakish (7 May 2008)
. . \ martin f krafft (7 May 2008)
. \ Bernd Eckenfels (7 May 2008)
. . \ Jean-Paul Lacquement (7 May 2008)
. . . \ Julien Gormotte (7 May 2008)
. . . \ Maik Holtkamp (8 May 2008)
. \ Brent Clark (7 May 2008)
. \ Holger Wesser (7 May 2008)
. \ Stephen Vaughan (7 May 2008)
. \ Alex Mestiashvili (7 May 2008)
. . \ Alex Mestiashvili (7 May 2008)
. \ Ticlea Petru Alexandru (7 May 2008)
. \ Simon Brandmair (7 May 2008)
. . \ martin f krafft (7 May 2008)
. \ Simon Valiquette (7 May 2008)
. \ Onno Gabriel (7 May 2008)
. \ P PRABHU (8 May 2008)
. . \ Rich Healey (13 May 2008)
. \ Bjørn Mork (8 May 2008)
. \ phobot (9 May 2008)
. . \ Noah Meyerhans (9 May 2008)
. . . \ weakish (9 May 2008)
. . \ Johannes Graumann (9 May 2008)
. \ Simon Brandmair (9 May 2008)

1 msgRe: [SECURITY] [DSA 1570-1] New kazehakase pack...
2 msgRe: [SECURITY] [DSA 1569-1] New cacti packages ...
Subject:Re: securing server
Group:Debian-security
From:Simon Brandmair
Date:9 May 2008


 
On Thu, 08 May 2008 08:40:12 +0200 Bjørn Mork wrote:

> martin f krafft <madduck> writes:
>> also sprach Simon Brandmair <sbrandmair> [2008.05.07.2020 +0100]:
>>> > no security benefit
>>>
>>> Just wondering: Why not?
>>
>> http://www.bpfh.net/simes/computing/chroot-break.html
>
> You still need to be root before breaking the jail, and one of the
> benefits of the chroot is the ability to limit access to potentionally
> vulnerable setuid root applications.

1. And isn't it quite likely that you don't have a C compiler or a Perl
interpreter inside your chroot?

2. IMHO, kernel patches like grsecurity are able to prevent some breaking
strategies.

Simon


--
To UNSUBSCRIBE, email to debian-security-REQUEST
with a subject of "unsubscribe". Trouble? Contact listmaster



© 2004-2008 readlist.com