Re: [gentoo-hardened] RIP hardened-sources

2017-04-29 Thread Brant Williams
Thanks to everyone involved in the Gentoo Hardened project, especially Spender and Pax Guy, for the effort and guidance throughout the years. The anecdotes shared in this thread echo my own experiences to a degree, and I've learned a lot about computer security by trying to get the grsec RBAC syste

Re: [gentoo-hardened] Questions about SELinux

2016-11-12 Thread Brant Williams
Hello, Robert. Do you have the package "app-admin/setools" installed? If so, you can run "cat /var/log/audit/audit.log | audit2why" to get an explanation of why the denials occur, with suggestions for fixing them. Of course, if your system is logging AVC denials elsewhere, adjust the command acco

Re: [Kc] We Are Iron Man

2009-04-24 Thread brant williams
That sounds rad... You'll need a [robust?] box with decent bandwith... I'm not doing much with mine... brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Fri, 24 Apr 2009, ironicf...@earthlink.net wrote: Date: Fri, 24 Apr 2009 15:00:45 -0400 (EDT) Fro

Re: [Kc] We Are Iron Man

2009-04-24 Thread brant williams
nd re-reading the original message real quick, methinks that this would fall under the "Ugly" category... Blah... brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Fri, 24 Apr 2009, Aaron Leonard wrote: Date: Fri, 24 Apr 2009 13:51:45 -0500 From: Aaron Leonard To:

Re: [Kc] late meeting notice

2009-01-13 Thread brant williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 I'd like to go eventually... perhaps next month? I might even know some Perl by then... brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Tue, 13 Jan 2009, Andrew Moore wrote: Date: Tue, 13 Jan 2009 17:21:45 -0600

Re: [gentoo-security] TCP Wrapper Documentation

2009-01-12 Thread brant williams
ithin cron. hth - -brant brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Sat, 10 Jan 2009, Chris O'Regan wrote: Date: Sat, 10 Jan 2009 00:51:47 -0500 From: Chris O'Regan Reply-To: gentoo-security@lists.gentoo.org To: gentoo-security@lists.gentoo.org Subject:

Re: [gentoo-hardened] Grsecurity: Role flag "G" problem

2008-11-23 Thread brant williams
running, are you perhaps trying to run gradm in learning mode while the RBAC system is already active? Hrm... brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Sun, 23 Nov 2008, brant williams wrote: Date: Sun, 23 Nov 2008 16:38:16 -0600 (CST) From: brant williams &

Re: [gentoo-hardened] Grsecurity: Role flag "G" problem

2008-11-23 Thread brant williams
quot;rx" will still not allow you to write to the file. You might want to take a look at this[1] link... [1] http://www.grsecurity.net/wiki/index.php/GrsecurityRBACObjModes Hope that helps... brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Sun, 23 Nov 2008, [EMAIL PR

Re: [gentoo-hardened] bastille

2008-10-24 Thread brant williams
/usr/portage/profiles/package.mask # Bryan Stine <[EMAIL PROTECTED]> (26 Apr 2007) # Masked until it works with current baselayout and # application locations. app-admin/bastille brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Fri, 24 Oct 2008, Chris PeBenito

Re: [gentoo-hardened] /etc/init.d/named stop hangs

2008-10-08 Thread brant williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Well, that would explain the lack of logs... brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Wed, 8 Oct 2008, RB wrote: Date: Wed, 8 Oct 2008 09:59:34 -0600 From: RB <[EMAIL PROTECTED]> Reply-To: gentoo-ha

Re: [gentoo-hardened] /etc/init.d/named stop hangs

2008-10-08 Thread brant williams
issue. I just installed "net-misc/dhcpcd" on my grsec box, but do not see a way to run it chrooted. Can you share your configuration/installation steps? Tschuess! brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Wed, 8 Oct 2008, Markus Bartl wrote: Date: Wed,

Re: [Full-disclosure] n3td3v group members important notice

2008-10-08 Thread brant williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Riker (to Worf): "You /do/ still remember how to fire phasers...?" brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Tue, 7 Oct 2008, James Matthews wrote: > Date: Tue, 7 Oct 2008 23:25:08 -0700 > From

Re: [gentoo-hardened] /etc/init.d/dhcpd start -> error

2008-10-06 Thread brant williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 You might also have turned on socket restrictions... brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Mon, 6 Oct 2008, Markus Bartl wrote: Date: Mon, 06 Oct 2008 17:04:15 +0200 From: Markus Bartl <[EMAIL PROTEC

Re: [gentoo-hardened] /etc/init.d/dhcpd start -> error

2008-10-06 Thread brant williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Did you enable any chroot restrictions in the kernel config? brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Mon, 6 Oct 2008, Markus Bartl wrote: Date: Mon, 06 Oct 2008 17:04:15 +0200 From: Markus Bartl <[EM

Re: [gentoo-hardened] Re: Is gentoo-wiki Down?

2008-04-13 Thread brant williams
dress:4.2.2.2#53 Non-authoritative answer: Name: gentoo-portage.com Address: 69.31.133.16 brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Sun, 13 Apr 2008, Fabiano - deStilaDo wrote: Date: Sun, 13 Apr 2008 23:14:24 -0300 From: Fabiano - deStilaDo <[EMAIL PROTECTED]&g

Re: [gentoo-security] Prince, Samuel is out of the office.

2008-04-01 Thread brant williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Just the right message for a security-minded list! And on April Fool's! =) This reminds me of a recent Wired article[1]. Cheers! [1] http://www.wired.com/politics/security/commentary/securitymatters/2008/03/securitymatters_0320

Re: [gentoo-sparc] Booting the system...

2008-03-27 Thread brant williams
SUN8x16=y # CONFIG_FONT_SUN12x22 is not set # CONFIG_FONT_10x18 is not set CONFIG_LOGO=y # CONFIG_LOGO_LINUX_MONO is not set # CONFIG_LOGO_LINUX_VGA16 is not set # CONFIG_LOGO_LINUX_CLUT224 is not set CONFIG_LOGO_SUN_CLUT224=y # CONFIG_FB_SPLASH is not set brant williams FCAA CDCA 20BC 3925 D634

Re: [gentoo-hardened] SSH nolonger works after update

2008-03-07 Thread brant williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 What kind of 'update' did you run? Can you detail what you did before the change ocurred? You might need to update sshd_config or /etc/init.d/sshd... weird, though. brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002

Re: [gentoo-hardened] pax, core2duo, suspicious activity

2008-02-07 Thread brant williams
d will try to get additional information. I'll also test with 2.6.24 and recheck my configs. As for web-rsync, I've never used it nor had the need... eix-sync has been working fine for several months now. brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Wed, 6

Re: [gentoo-hardened] pax, core2duo, suspicious activity

2008-02-06 Thread brant williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Along with a similar post[1] from December, these all seem to be rsync related... [1] http://www.nabble.com/PAX%3A-suspicious-general-protection-fault-tt14133006.html brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On

Re: [gentoo-hardened] pax, core2duo, suspicious activity

2008-02-06 Thread brant williams
files, though, it looks like I may have rushed through too quickly (sdiff attached). I've got a screenshot of the log entry that occurred right before the crash (png attached), and can provide the System.map and kernel image to you off-list if that would help. Thank you for your effort

Re: [gentoo-hardened] Fwd: hardened gentoo mailman/postfix/apache notes?

2008-01-02 Thread brant williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 You should recompile your kernel and choose a different gid for tpe (anything above 1024 would be a good choice). Alternatively, you could turn the feature off. ;) brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Thu

Re: [gentoo-hardened] How to set up for chrony?

2007-12-31 Thread brant williams
r the errors you get. brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Mon, 31 Dec 2007, Peter Humphrey wrote: Date: Mon, 31 Dec 2007 17:44:14 + From: Peter Humphrey <[EMAIL PROTECTED]> Reply-To: gentoo-hardened@lists.gentoo.org To: gentoo-hardened@lists.gento

Re: [gentoo-hardened] How to set up for chrony?

2007-12-31 Thread brant williams
icy. The error message is the key... ;) brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Mon, 31 Dec 2007, Peter Humphrey wrote: Date: Mon, 31 Dec 2007 16:48:33 + From: Peter Humphrey <[EMAIL PROTECTED]> Reply-To: gentoo-hardened@lists.gentoo.org To:

Re: [gentoo-hardened] How to set up for chrony?

2007-12-31 Thread brant williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 If grsec is denying the write, it should show up in your syslog. Are you running grsec's RBAC system? Can you paste the error you're referring to? brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Mon, 3

Re: [gentoo-hardened] Remote ssh attack: sshd tries to make udp connection to a remote host

2007-12-29 Thread brant williams
nd then see if there are any more of these log entries. I believe the daemon also connects to port 113 (forgot which protocol) for each incoming connection. If it happens again, you can also check current connections with netstat(1) to see what sshd is doing. brant williams FCAA CDCA 20BC 3925

Re: [gentoo-hardened] gnucash "stack smashing detected"

2007-12-28 Thread brant williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi Grant, What does /var/log/kern.log show? brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Fri, 28 Dec 2007, Grant wrote: Date: Fri, 28 Dec 2007 07:33:10 -0800 From: Grant <[EMAIL PROTECTED]> Reply-To: gentoo-ha

Re: [gentoo-hardened] grSecurity warnings about XFree86; Xorg also targeted?

2007-12-24 Thread brant williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 So... yes. X needs direct (privileged) access to video hardware (and hence DRI). brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Tue, 25 Dec 2007, Christian Heim wrote: Date: Tue, 25 Dec 2007 01:53:25 + From

Re: [gentoo-hardened] error building glibc on amd64

2007-12-14 Thread brant williams
`? Also, what steps have you taken so far? You said that you just chrooted into this system; are you just now doing this from the install disc? You might want to compile a kernel and make sure the box will boot without the install disc before emerging other packages or changing the profile. bran

Re: [gentoo-hardened] unsubscribe

2007-12-06 Thread brant williams
please send your request to [EMAIL PROTECTED] brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Thu, 6 Dec 2007, momentics wrote: Date: Thu, 6 Dec 2007 22:34:42 +0300 From: momentics <[EMAIL PROTECTED]> Reply-To: gentoo-hardened@lists.gentoo.org To: gentoo-ha

Re: [gentoo-hardened] Help required in creating a new profile

2007-11-27 Thread brant williams
Wouldn't you want the symlink to be to /etc/make.profile and not /etc/make.conf? brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Tue, 27 Nov 2007, John Eckhart wrote: Date: Tue, 27 Nov 2007 16:12:58 -0500 From: John Eckhart <[EMAIL PROTECTED]> Reply

Re: [gentoo-hardened] Unmerged gcc

2007-09-19 Thread brant williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 If you have gentoolkit installed on another box, you can do `quickpkg gcc` brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Wed, 19 Sep 2007, Shawn Haggett wrote: Date: Wed, 19 Sep 2007 22:55:23 +0930 From: Shawn

Re: [gentoo-sparc] emerging of silo fails

2007-09-17 Thread brant williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Yeah, sorry, I'm a dufus. Re-read your original message... Do you have 'gentoolkit' installed? If so, you might want to run `revdep-rebuild` which will scan the linking on your system and re-emerge any needed packages. bran

Re: [gentoo-sparc] emerging of silo fails

2007-09-17 Thread brant williams
/profiles/default-linux/sparc/sparc32/2006.1/2.4 /etc/make.profile emerge --sync # if you haven't yet emerge -uDav world emerge -av silo brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Tue, 18 Sep 2007, Aggelos wrote: Date: Tue, 18 Sep 2007 00:42:52 +0300

Re: [gentoo-sparc] emerging of silo fails

2007-09-17 Thread brant williams
you could post /usr/src/linux/.config and (if possible) any dmesg output, that'd be great. brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Mon, 17 Sep 2007, Aggelos wrote: Date: Mon, 17 Sep 2007 19:46:21 +0300 From: Aggelos <[EMAIL PROTECTED]> R

Re: [gentoo-sparc] help for silo

2007-08-24 Thread brant williams
fstab? brant williams FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002 On Sat, 25 Aug 2007, Bryan wrote: Date: Sat, 25 Aug 2007 11:36:26 +0800 From: Bryan <[EMAIL PROTECTED]> Reply-To: gentoo-sparc@lists.gentoo.org To: gentoo-sparc@lists.gentoo.org Subject: [gentoo-sparc] help for silo

Re: [gentoo-hardened] 2.6.21-hardened-r3 and vmware scsi disks

2007-07-05 Thread Brant Williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 did you use the same .config for both? Public GPG/PGP key for Brant Williams: 0x88E1AA9E. Available at your friendly local public keyserver. On Fri, 6 Jul 2007, Natanael Copa wrote: > Hi, > > Are anyone running 2.6.21-hardened-r3

Re: [gentoo-hardened] Re: Cannot boot a hardened-sources-2.4.33.4 on a SATA drive

2007-06-21 Thread Brant Williams
hardened-2007.0_pre20070209.tar.bz2 ncftp ...al/x86/hardened/stages > pwd ftp://ftp.osuosl.org/pub/gentoo/experimental/x86/hardened/stages/ This URL is also valid on this server: ftp://ftp.osuosl.org/.1/gentoo/experimental/x86/hardened/stages/ later Public GPG/PGP key for Brant Williams:

Re: [gentoo-hardened] Re: Cannot boot a hardened-sources-2.4.33.4 on a SATA drive

2007-06-21 Thread Brant Williams
...and 'make modules'. 2.6 will make the modules when you do 'make', but 2.4 won't... Public GPG/PGP key for Brant Williams: 0x88E1AA9E. Available at your friendly local public keyserver. On Sun, 17 Jun 2007, René Rhéaume wrote: > I did an experiment by bu

Re: [gentoo-hardened] Re: Cannot boot a hardened-sources-2.4.33.4 on a SATA drive

2007-06-21 Thread Brant Williams
What steps are you taking when running the kernel configuration/compilation? You might have forgotten to do 'make dep'... Public GPG/PGP key for Brant Williams: 0x88E1AA9E. Available at your friendly local public keyserver. On Sun, 17 Jun 2007, René Rhéaume wrote: > I did an

Re: [gentoo-hardened] Re: Cannot boot a hardened-sources-2.4.33.4 on a SATA drive

2007-06-20 Thread Brant Williams
What error(s) do you see? Public GPG/PGP key for Brant Williams: 0x88E1AA9E. Available at your friendly local public keyserver. On Mon, 18 Jun 2007, René Rhéaume wrote: > No, the problem was SCSI and SCSI disk support were built as modules, > not in-kernel. Now, init runs, but e2fsc

Re: [gentoo-hardened] SELinux - Root and sudo commands denied

2007-06-10 Thread Brant Williams
configure a role to allow editing of [certain] system files? Public GPG/PGP key for Brant Williams: 0x88E1AA9E. Available at your friendly local public keyserver. On Sun, 10 Jun 2007, Krzysztof Koz�~Bowski wrote: > Petre Rodan wrote: > > - you're opening up a pandora'

Re: [gentoo-hardened] Idea behind different ebuilds sec-policy/selinux-*

2007-06-09 Thread Brant Williams
inux policy for sudo As you stated, they can be installed via modules...why not just emerge what you need? Not a very helpful response, I know... sorry. =) You may want to look at the "targeted" policy... IIRC, that's where SELinux was heading toward... Public GPG/PGP key

Re: [gentoo-hardened] glibc-2.5-r2 is stable

2007-05-25 Thread Brant Williams
I just emerged it with no problems. As for nptl, I'm running a 2.4 kernel. :) Public GPG/PGP key for Brant Williams: 0x88E1AA9E. Available at your friendly local public keyserver. On Thu, 24 May 2007, [EMAIL PROTECTED] wrote: > Are there any things to consider while upgrading

2nd try

2007-05-13 Thread Brant Williams
No luck last time so I'll fish again! From: Brant Williams <[EMAIL PROTECTED]> Date: May 9, 2007 5:05:12 PM EDT To: yellowdog-newbie@lists.terrasoftsolutions.com Subject: multipart Hello everyone! I have Yellowdog 5 on my Mac mini, and I just wanted to borrow your expertise f

Re: [gentoo-hardened] gradm grsecurity incompatibility errors

2007-05-10 Thread Brant Williams
I've run into this same issue a couple of times. Since I didn't want to spend too much time fixing it, I just use the vanilla sources from kernel.org and patch them against grsecurity. Each release of grsec is dependent on specific kernels, though, so you'd want to check www.grsecurity.net f

multipart

2007-05-09 Thread Brant Williams
Hello everyone! I have Yellowdog 5 on my Mac mini, and I just wanted to borrow your expertise for a bit to answer a few questions. 1) Java. I have Xubuntu running on my iMac G3. By following the instructions posted here: https://help.ubuntu.com/community/Java I have Java, and it run

Re: [gentoo-hardened] Using grsecurity and SELinux

2007-04-19 Thread Brant Williams
That is correct. You could also use RSBAC and/or the GrSecurity RBAC system. Public GPG/PGP key for Brant Williams: 0x88E1AA9E. Available at your friendly local public keyserver. On Thu, 19 Apr 2007, [EMAIL PROTECTED] wrote: > Hello, > > grsecurity kernel configs (like expand

Re: [gentoo-hardened] Upgrading GCC in hardened

2006-11-09 Thread Brant Williams
date" messages that you get? Also, what does `emerge --info` show you? Public GPG/PGP key for Brant Williams: 0x88E1AA9E. Available at your friendly local public keyserver. On Thu, 9 Nov 2006, Derrick Hendricks wrote: > I'm running a firewall for our work network using hardened

Re: [gentoo-hardened] Re: Do I need RBAC?

2006-10-29 Thread Brant Williams
you can find a decent example one at: http://forums.grsecurity.net/viewtopic.php?p=&; Documentation can be found at: http://hardened.gentoo.org http://www.grsecurity.net/papers.php Hope that helps; sorry I don't have an actual policy to show ATM... - -Brant Public GPG/PGP key fo

Re: [gentoo-hardened] How do I use grSecurity mandatory access control?

2006-05-09 Thread Brant Williams
I'd be willing to take a first stab at a howto in about one week. I'm i the middle of giving and grading exams right now. Anyone else interested? Yes. I'm currently learning the RBAC system myself, and have already spent a lot of time researching the (scattered) documentation. As not ever

Re: [gentoo-hardened] 2 lists!

2006-05-06 Thread Brant Williams
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 In my experience, most doctors know little to nothing about computers, let alone developing a hardened Linux distribution... ;) try #gentoo or #gentoo-hardened on irc.freenode.net - -Brant On Sat, 6 May 2006, Jan V wrote: mostly physicians a

Re: Installation problem

2006-04-18 Thread Brant Williams
I have the same problem with an iMac G3 600 MHz. Will not install yaboot. On Tue, 2006-04-18 at 17:11 -0400, Don Nuckols wrote: > I have tried twice to install YDL, and each time it goes through the > whole procedure, then at the end it puts up a small progress window > entitled: > > Perform

RE: [gentoo-sparc] PHP crashing...

2006-03-14 Thread Brant Williams
Correct me if I'm wrong, but doesn't the "hardened" USE flag require the "hardened" profile? AFAIK, that profile doesn't exist for SPARC. -Brant public GPG/PGP key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xEBA14420 On Tue, 14 Mar 2006, Paul Heinlein wrote: On Tue, 14 Mar 2006,

Re: [gentoo-sparc] INIT: Id "c0" respawning too fast: disabled for 5 minutes

2005-01-28 Thread Brant Williams
greetings earthling check /etc/inittab for TTYs...might want to comment them out if it's a headless box some dude named jose isaias cabrera said: > > Greetings! > > I just installed Gentoo kernel 2.4.27 on a sparc64 and I am > getting this > message: > > INIT: Id "c0" respawning too fast: disable