Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interface foron access scanning

From: Alan Cox
Date: Tue Aug 05 2008 - 08:57:27 EST


> Much better solution:

And one which was found lacking about 1950...

> Problem solved. Untrusted and possibly-compromised files can't be
> executed, or even if they could be they can't do anything

Two things
- Scripts
- Attacks based on compromising a live binary

You can use SELinux to control what is executed and it is a very
effective management control technique. However it doesn't control
javascript in web pages, exploits that popen perl and chat to it and so
on...
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/