public inbox for gentoo-hardened@lists.gentoo.org
 help / color / mirror / Atom feed
From: 7v5w7go9ub0o <7v5w7go9ub0o@gmail.com>
To: gentoo-hardened@lists.gentoo.org
Subject: [gentoo-hardened] Re: hardened workstation - is that worth it?
Date: Wed, 26 Nov 2008 12:31:09 -0500	[thread overview]
Message-ID: <492D87DD.4090203@gmail.com> (raw)
In-Reply-To: <20081126023421.GQ1806@home.power>

Alex Efros wrote:
> Hi!
> 
> On Tue, Nov 25, 2008 at 09:02:58PM -0500, 7v5w7go9ub0o wrote:
>> I run the "old" hardened toolchain, grsecurity-enhanced hardened kernel,
>> rbac control, and jails for anything that accesses the LAN/WAN.(heh... I
>> even chroot and kill dhcpcd after 5 seconds). Avira has hundreds of Linux 
>> rootkit signatures in its database, so I run Avira and Dazuko 
>> realtime/on-access scanning on my /home directory, the chroot jails, and on 
>> the portage workspace used during download and compilation.
> 
> Wow. While I'm a paranoiac in this sense too, I'm too lazy to do most of
> these things. It's good to know there are potential for me to advance on
> this way! ;-)

I set this up three+ years ago, and after initial setup, it's been
really easy to maintain. Every now and then I have to "retrain" RBAC,
but I use a training script to do that, so it is pretty automatic as well


> 
> BTW, is your workstation really was under attack (don't counting ssh worms
> and the like script kiddie games)? Is there was attacks which was able to
> break first circle of protection (GrSec+PaX+toolchain)?

I've not had anything break G+P+T.

- I had pax continuously cancel FireFox on a particular site a few years
ago, and never figured out what it was. It might hae been a browser
attack, or it may have simply been a badly-written extension.

I now browse with Opera (in a jail), and use Firefox ("fox in a box") in
a limited way.

- I also today real-time scan the browser jails (which I run in ramdisk,
so that any unintended changes are discarded at the end of the session)
with Dazuko/Antivir, and have had a number of suspicious scripts blocked
by AntiVir before the browser could act on them - so I think that my
exposure is thereby reduced.

> 
> As for me, I decide not to worry about these things (browser chroot, etc.)
> for now because on workstation most important information is files in my
> home directory... and applications I use (like browser, mail client, etc.)
> MUST have access to these files or these applications because nearly
> unusable for me. So, even with RSBAC, if my mutt will be owned by some
> malicious email, and it will delete/damage files it usually have access to
> (like my mailbox :)), that will be _enough_ and make much more damage for
> me than installing rootkit. So, I choose to do regular automated backups
> and run chkrootkit/rkhunter from cron just for the case they detect
> something interesting to play with. :)

Well, that's a good point - it can be a pain, e.g. copying a document
into the mail client chroot jail so that I can send it.

I also use numerous, individual, single-purpose users (e.g.
ooffice:ooffice;, opera:opera, tbird:tbird, etc.) so that, e.g.,
user/jail wireshark:wireshark can not read user tbird:tbird, and vice
versa.

This can be a pain because I need to change privilege, as well as
copying things into - e.g., the tbird jail.

Copying downloads out of jails is easy - a script copies all downloads
from the various jails into a single folder, which is then scanned for
Trojan signatures.

> 





  reply	other threads:[~2008-11-26 17:32 UTC|newest]

Thread overview: 28+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-11-25 15:00 [gentoo-hardened] hardened workstation - is that worth it? Jan Klod
2008-11-25 15:56 ` Alex Efros
2008-11-25 16:39   ` Jan Klod
2008-11-25 20:40     ` Alex Efros
2008-11-25 20:51     ` Javier Martínez
2008-11-25 20:56       ` Alex Efros
2008-11-25 19:58 ` RB
2008-11-25 20:36   ` Javier Martínez
2008-11-25 21:24     ` Jan Klod
2008-12-05 15:29     ` pageexec
2008-12-05 16:38       ` Brian Kroth
2008-12-05 17:21       ` Javier Martínez
2008-12-05 17:22         ` pageexec
2008-12-05 17:31         ` Javier Martínez
2008-12-05 17:48       ` Ned Ludd
2008-12-05 17:11         ` pageexec
2008-11-25 21:12   ` Jan Klod
2008-11-25 21:47     ` RB
2008-11-25 21:58   ` Jan Klod
2008-11-25 22:11     ` atoth
2008-11-25 22:14     ` RB
2008-11-26 11:39       ` Jan Klod
2008-11-25 23:23     ` Javier Martínez
2008-11-26  2:02 ` [gentoo-hardened] " 7v5w7go9ub0o
2008-11-26  2:34   ` Alex Efros
2008-11-26 17:31     ` 7v5w7go9ub0o [this message]
2008-11-26  6:09   ` atoth
2008-11-26 17:41     ` 7v5w7go9ub0o

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=492D87DD.4090203@gmail.com \
    --to=7v5w7go9ub0o@gmail.com \
    --cc=gentoo-hardened@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox