Re: [PATCH 2/3] Security: Implement disablenetwork semantics. (v4)

From: Pavel Machek
Date: Tue Jan 12 2010 - 02:59:33 EST


> On Sun, 10 Jan 2010 22:58:48 +0100, Pavel Machek said:
>
> > Scenario 2:
> >
> > Mallory calls disablenetwork, calls sendmail as the first user after
> > boot; sendmail can't deliver anything (its network is disabled), but
> > starts forking and taking requests for other users, DoSing the mail
> > delivery.
>
> You need to be root to start sendmail as a daemon.

Well, maybe, but mailer system where first user starts is as a daemon
makes sense... same for authentication system, etc. And it was okay
before disablenetwork come.
Pavel

--
(english) http://www.livejournal.com/~pavelmachek
(cesky, pictures) http://atrey.karlin.mff.cuni.cz/~pavel/picture/horses/blog.html
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/