some grsec problems :)
Posted: Mon Sep 22, 2003 10:52 am
Hi All,
I have a few questions about grsec, if anyone can comment, I'd be grateful:
A) Can you change the "lockout time" for the password retry lockout
without a reboot? It doesn't appear so, but I thought I'd ask.
B) The password lockout appears to affect all IP addresses once it
is done. It is a good idea, however, if a hacker obtains root, and runs
gradm with a bad password 3 times, it will lock us both out. Which means it limits my ability to deal with him. I would consider this a logic flaw, or
am I missing something? How should I deal with this?
C) Is there a way (I can't seem to find it) to set restrictions on a login ID other than simply putting those restrictions on thier home directory? It would seem to me that it would be available, but I must be missing it in the ACL documentation.
Great job on GRSEC guys We used a commercial product previously (Argus Pitbull LX), and I must say, I beleive your product surpasses thier functionality.
I could patch it for the above 2 things, but I thought I'd check to make sure I wasn't missing them somewhere first
Regards,
Dale.
I have a few questions about grsec, if anyone can comment, I'd be grateful:
A) Can you change the "lockout time" for the password retry lockout
without a reboot? It doesn't appear so, but I thought I'd ask.
B) The password lockout appears to affect all IP addresses once it
is done. It is a good idea, however, if a hacker obtains root, and runs
gradm with a bad password 3 times, it will lock us both out. Which means it limits my ability to deal with him. I would consider this a logic flaw, or
am I missing something? How should I deal with this?
C) Is there a way (I can't seem to find it) to set restrictions on a login ID other than simply putting those restrictions on thier home directory? It would seem to me that it would be available, but I must be missing it in the ACL documentation.
Great job on GRSEC guys We used a commercial product previously (Argus Pitbull LX), and I must say, I beleive your product surpasses thier functionality.
I could patch it for the above 2 things, but I thought I'd check to make sure I wasn't missing them somewhere first
Regards,
Dale.