Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: What server hardening are you doing these days? |
|---|---|
| Date: | Fri, 11 Nov 2005 00:02:33 +0000 |
On Thu, 2005-11-10 at 14:28 -0800, Kurt Dillard wrote:
If you're looking for mandatory access control, no general purpose commercial software supports that out of the box. MACs is, in my opinion, not viable for the vast majority of users and businesses. As for localsystem having full access to the file system, your comment suggests that you don't realize localsystem has full access to virtually everything. Its analogous to root on *nix. If you have data you want to protect from even localsystem you'll have to encrypt it and store the key separate from the computer.
Out of interest (and don't get me wrong, it is out of friendly interest, I don't want to start a fight!), is your "no general purpose" statement solely directed towards windows as a platform and software which adds functionality to it, or towards operating systems for midrange systems in general? If the latter (ie. if you're referring to Operating Systems in general), how would apply that statement to the (several) distributions of linux (redhat being a prime example - for instance https://www.redhat.com/en_us/USA/rhel/details/features/, about half-way down) which include Mandatory Access Control as part of their default kernel and enable/bundle support for it? Although redhat swings towards 'targeted' MAC by default, it will support 'full' MAC, and the 'targeted' access control which wraps system services is fairly powerful. - James. --------------------------------------------------------------------------- ---------------------------------------------------------------------------
| Previous by Date: | Re: What server hardening are you doing these days?, Syv Ritch |
|---|---|
| Next by Date: | Re: What server hardening are you doing these days?, Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] |
| Previous by Thread: | RE: What server hardening are you doing these days?, Kurt Dillard |
| Next by Thread: | Re: What server hardening are you doing these days?, Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] |
| Indexes: | [Date] [Thread] [Top] [All Lists] |