Re: [AppArmor 01/41] Pass struct vfsmount to the inode_create LSM hook



On Sat, 26 May 2007 15:58:50 PDT, Casey Schaufler said:
Fair enough, I don't believe that an argv[0] check ought to
be used as a security mechanism. I am not convinced that everyone
would agree with us.

Having seen my share of argv[0]-related security bugs in my years, I have to
agree that it's a security crock. As to why some might not agree, you already
put your finger on it earlier:

On Fri, 25 May 2007 12:06:19 PDT, Casey Schaufler said:
nefarious schemes. Remember that security is a subjective thing, and
using argv[0] and AppArmor together might make some people feel better.

Some people would rather just feel better...

Attachment: pgp4JLJ8AKzWq.pgp
Description: PGP signature



Relevant Pages

  • Re: Custom Forms role-based security and HttpModules
    ... I think u can't have different security mechanism in subdirectory ... other than the one u use in the root directory. ... Could I install it only for a folder, by registering it ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • RE: hoping this is easy - passwords
    ... reports being automatically created with the correct user information. ... Access have it's own security mechanism called workgroup ... With the help of mdw files, ... you may make your own security mechanism. ...
    (microsoft.public.access.forms)
  • [NT] Microsoft ASP.NET Request Validation Bypass Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... The "Request Validation" mechanism designed to protect against Cross-Site ... Don't rely on this security mechanism to protect against Cross-Site ...
    (Securiteam)