Page 1 of 1

"learned" ACLs: no network rules?

PostPosted: Tue Sep 24, 2002 6:38 am
by meyerm
Hi,

I'm totally new to grsecurity. So please forgive me. :)

I've just created an acl.learn containing exactly the contents out of the documentation. I used it to learn ACLs for my sshd. But after flushing the new learned ACL it doesn't even containg anything but shared libraries. No networkrealted stuff.

When I then try to start sshd using a startscript from SuSE with ACLs enabled, it crashes with a segv. After that I have to restart my computer, doing anything else almost always leads to a complete lock of the used console.

Then I tried to teach him the ACLs by calling sshd directly (no rc-script). And after reactivating with those rules fired I started the sshd again "alone". Now it doesn't crash, but just says "too many open files". Oh, the learned ACL didn't contain any network stuff either. Therfore I think I did something wrong while learning (perhaps this "script" doesn't work. BTW: I did it by hand of course, but "bash" is faster than "english" ;):
Code: Select all
echo $STUFF_FROM_DOCU > /etc/grsec/acl.learn
# cat /etc/grsec/acl.learn | sed s/bin/\/usr\/sbin\/sshd/ > /etc/grsec/acl.sshd
# echo "include </etc/grsec/acl.sshd>" > /etc/grsec/acl
# rcsshd stop
# gradm -E
# /usr/sbin/sshd
> remote: several succeding and failing logins using different users
# killall /usr/sbin/sshd
# gradm -D
# rm /etc/grsec/acl.sshd
# gradm -L -O /etc/grsec/acl.sshd
# gradm -E
# /usr/sbin/sshd
bash: /usr/sbin/sshd: Too many open files


But my /var/log/grsec file doesn't say anything! :cry:

I'm quite confused. As already mentioned in this forum, I should update to the newest version. I'm using grsec-1.9.7-2.4.19 with gradm-1.5. Is there perhaps any hidden CVS I should know about? ;)

Thanks a lot for your help!
Marcel

PostPosted: Tue Sep 24, 2002 6:57 am
by meyerm
Add:

When I put a # in front of the line RES_NOFILE 0 0, which was not at all changed by the learning process, sshd tries to start. But the only respone I get is "Killed"... :-?

The log says nothing despite of the starting message again.

PostPosted: Tue Sep 24, 2002 10:36 am
by spender
paste your ACL set, so I can see what you did.

-Brad

PostPosted: Tue Sep 24, 2002 10:56 am
by meyerm
Thanks for your offer. But I've started over by hand. Well, it is very slow, since I don't want to offer too much to sshd (not after these securityholes found in the last time) so that I'm setting the permissions file by file. *pfew*

But I hope your ACL-example will be a great help!