From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pigeon.gentoo.org ([69.77.167.62] helo=lists.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1L5AEV-0007Po-Nt for garchives@archives.gentoo.org; Wed, 26 Nov 2008 02:34:27 +0000 Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 62323E03DD; Wed, 26 Nov 2008 02:34:26 +0000 (UTC) Received: from powerman.name (powerman.name [85.90.198.1]) by pigeon.gentoo.org (Postfix) with ESMTP id 22238E03DD for ; Wed, 26 Nov 2008 02:34:24 +0000 (UTC) Received: (qmail 23475 invoked by uid 1000); 26 Nov 2008 02:34:21 -0000 Date: Wed, 26 Nov 2008 04:34:21 +0200 From: Alex Efros To: gentoo-hardened@lists.gentoo.org Subject: Re: [gentoo-hardened] Re: hardened workstation - is that worth it? Message-ID: <20081126023421.GQ1806@home.power> Mail-Followup-To: gentoo-hardened@lists.gentoo.org References: <200811251700.45540.janklodvan@gmail.com> <492CAE52.5050709@gmail.com> Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-hardened@lists.gentoo.org Reply-to: gentoo-hardened@lists.gentoo.org MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <492CAE52.5050709@gmail.com> Organization: http://powerman.name/ User-Agent: Mutt/1.5.16 (2007-06-09) X-Archives-Salt: bce19a15-8851-417e-aad9-d68ebb25a304 X-Archives-Hash: ac32809a5963c0d7a2a3883fe3c64be1 Hi! On Tue, Nov 25, 2008 at 09:02:58PM -0500, 7v5w7go9ub0o wrote: > I run the "old" hardened toolchain, grsecurity-enhanced hardened kernel, > rbac control, and jails for anything that accesses the LAN/WAN.(heh... I > even chroot and kill dhcpcd after 5 seconds). Avira has hundreds of Linux > rootkit signatures in its database, so I run Avira and Dazuko > realtime/on-access scanning on my /home directory, the chroot jails, and on > the portage workspace used during download and compilation. Wow. While I'm a paranoiac in this sense too, I'm too lazy to do most of these things. It's good to know there are potential for me to advance on this way! ;-) BTW, is your workstation really was under attack (don't counting ssh worms and the like script kiddie games)? Is there was attacks which was able to break first circle of protection (GrSec+PaX+toolchain)? As for me, I decide not to worry about these things (browser chroot, etc.) for now because on workstation most important information is files in my home directory... and applications I use (like browser, mail client, etc.) MUST have access to these files or these applications because nearly unusable for me. So, even with RSBAC, if my mutt will be owned by some malicious email, and it will delete/damage files it usually have access to (like my mailbox :)), that will be _enough_ and make much more damage for me than installing rootkit. So, I choose to do regular automated backups and run chkrootkit/rkhunter from cron just for the case they detect something interesting to play with. :) -- WBR, Alex.