hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : grsecurity kernel
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

grsecurity kernel

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 07-17-2008, 12:39 AM
gpl24 gpl24 is offline
Aspiring Evangelist
 
Join Date: May 2007
Posts: 438

grsecurity kernel


Emphasize the point in the Wikipedia entry:
Quote:
Its typical application is in web servers and systems that accept remote connections from untrusted locations, such as systems offering shell access to its users.
My server is private, I don't resell it's space to people I do not know.

Do I need grsecurity or am I safe on a standard kernel?

Reply With Quote


Sponsored Links
  #2  
Old 07-17-2008, 03:16 AM
PCS-Chris PCS-Chris is offline
Premium Member
 
Join Date: Dec 2005
Location: Berkshire, UK
Posts: 2,854
Your fine with a standard kernel really.

__________________
System Administrator
» Follow me on twitter: Here

Reply With Quote
  #3  
Old 07-17-2008, 04:51 AM
gpl24 gpl24 is offline
Aspiring Evangelist
 
Join Date: May 2007
Posts: 438
Thank you!
So it does not offer much other than what the wikipedia article explains?



One thing I did like about it was the segfault errors.. . it told me what program started & what program the error forced a kill on.
Does any other application offer more expletive info for errors is this manner? (other than grsecurity)

Reply With Quote
Sponsored Links
  #4  
Old 07-17-2008, 09:29 PM
zacharooni zacharooni is offline
Community Guide
 
Join Date: Apr 2005
Posts: 1,214
My policy is 'never trust anyone but yourself'. Put it on anyway, might make you feel safer, which is all that really matters anyway. Pretty simple to do

Reply With Quote
  #5  
Old 07-20-2008, 09:04 AM
atomicturtle atomicturtle is offline
Junior Guru Wannabe
 
Join Date: Sep 2003
Location: Earth!
Posts: 55
Grsec is an extremely effective addition to your overall security policy. Youve got PaX, which more or less mitigates the risks of buffer overruns. Trusted Path Execution, which prevents untrusted users from executing commands not owned by root, client/server policies that dictate if a user id can create listeners, or connect outbound. Restricts access to /proc, has a learning mode, RBAC, etc. Its also far more practical than SElinux in a web hosting environment.

__________________
Secure your server now: Atomic Secured Linux
Troubleshooting Linux Firewalls in stores today

Reply With Quote
  #6  
Old 07-20-2008, 04:45 PM
gpl24 gpl24 is offline
Aspiring Evangelist
 
Join Date: May 2007
Posts: 438
I put it back on, now I am seeing these:
Jul 20 02:10:02 host kernel: grsec: denied resource overstep by requesting 92793384673280 for RLIMIT_STACK against limit 8388608 for /[grep:18782] uid/euid:0/0 gid/egid:0/0, parent /usr/local/sim/sim[sim:18780] uid/euid:0/0 gid/egid:0/0

Jul 20 02:40:01 host kernel: grsec: denied resource overstep by requesting 92758867386368 for RLIMIT_STACK against limit 8388608 for /[grep:22215] uid/euid:0/0 gid/egid:0/0, parent /usr/local/bfd/bfd[bfd:22213]uid/euid:0/0 gid/egid:0/0

Jul 20 04:20:01 host kernel: grsec: denied resource overstep by requesting 93307418767360 for RLIMIT_STACK against limit 8388608 for /[cut:25973] uid/euid:0/0 gid/egid:0/0, parent /etc/apf/ad/antidos[antidos:25954] uid/euid:0/0 gid/egid:0/0

Anybody know what this is all about?

Reply With Quote
  #7  
Old 07-22-2008, 03:37 AM
ifastsupport ifastsupport is offline
Newbie
 
Join Date: Jul 2008
Posts: 6
grsecurity offers among many other features:

* An intelligent and robust Role-Based Access Control (RBAC) system that can generate least privilege policies for your entire system with no configuration
* Change root (chroot) hardening
* /tmp race prevention
* Extensive auditing
* Prevention of arbitrary code execution, regardless of the technique used (stack smashing, heap corruption, etc)
* Prevention of arbitrary code execution in the kernel
* Randomization of the stack, library, and heap bases
* Kernel stack base randomization
* Protection against exploitable null-pointer dereference bugs in the kernel
* Reduction of the risk of sensitive information being leaked by arbitrary-read kernel bugs
* A restriction that allows a user to only view his/her processes
* Security alerts and audits that contain the IP address of the person causing the alert

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Web Host PromptSpace Launches Shared Hosting Platform Web Hosting News 2011-12-27 18:15:25
Web Host SiteServing Launches Eight VPS Hosting Plans Web Hosting News 2011-09-13 17:58:05
Web Hosting Software Firm CloudLinux Releases CloudLinux OS Version 6.1 Web Hosting News 2011-09-13 14:08:49
Linux Foundation Website Down After Security Breach Last Week Web Hosting News 2011-09-12 20:32:11
Cloud Infrastructure Developer Hexagrid Joins Open Virtualization Alliance Web Hosting News 2011-07-07 20:46:22


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?