learning mode for directories

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

learning mode for directories

Postby dontask87 » Tue Oct 01, 2002 10:38 pm

hi again, was trying to use learning mode to capture everything done by applications under a certain directory. To be specific I was trying to watch all executables under /etc/rc.d/init.d during a shutdown. It appears that you can only enable learning mode one application at a time and not for a directory acl entry. An error or warning message telling me i was using learning mode incorrectly would have helped. Having said that, perhaps it's an expensive error to test for.

Anyway, i'm still having fun locking my machine down and really just wanted to say thanks for the effort you've put into Grsecurity.

Now, anyone know where i can find a decent hacker to check my work so far :wink:
dontask87
 
Posts: 4
Joined: Mon Sep 30, 2002 11:55 am

Postby spender » Wed Oct 02, 2002 1:47 pm

you can use learning mode on a directory. You were probably just having problems using it with /etc/rc.d/init.d, because shell scripts are difficult to create ACLs for...very little work is actually done by the script itself.

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm


Return to grsecurity support