by piavka » Mon Dec 16, 2002 7:32 am
/etc/grsec#gradm -E
Viewing access is allowed to /dev/mem. This would allow an attacker to modify the code of programs running on your system.
There were 1 holes found in your ACL configuration. These must be fixed before the ACL system will be allowed to be enabled.
The / acl:
/ l {
/ r
/opt r
/home rx
/mnt r
/tmp rw
/boot r
/root r
/usr r
/usr/share/locale rx
/etc r
/etc/grsec h
/var r
/var/tmp rw
/var/log rw
/dev w
/dev/mem h
/dev/kmem h
/proc rw
/proc/sys r
/proc/kcore h
/lib rx
/usr/lib rx
/usr/local/lib rx
/usr/X11R6/lib rx
/bin rx
/sbin rx
/usr/bin rx
/usr/sbin rx
/usr/local/bin rx
/usr/X11R6/bin rx
-CAP_LINUX_IMMUTABLE
-CAP_NET_RAW
-CAP_SYS_MODULE
-CAP_SYS_RAWIO
-CAP_MKNOD
}