wiki:experiences:igraltist:jail_cron
=>  Releases

Current version
Git/Latestdiff: 1.5.6

Latest Snapshots
Produced after each commit or rebase to new upstream version

GIT
RSBAC source code, can be unstable sometimes

=>  Events

No events planned

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision Both sides next revision
wiki:experiences:igraltist:jail_cron [2008/07/12 06:08]
127.0.0.1 (old revision restored)
wiki:experiences:igraltist:jail_cron [2008/07/12 06:20]
127.0.0.1 (old revision restored)
Line 1: Line 1:
-===== +This is the modified ​cron init-script
-So now the next is the cron for setup. +
- +
-I do the same like for the syslogd. +
- +
-First modify the cron init-script+
    diff -u cron_org cron    diff -u cron_org cron
    --- cron_org 2008-07-03 04:​10:​46.000000000 +0200    --- cron_org 2008-07-03 04:​10:​46.000000000 +0200
Line 31: Line 26:
  
  
-After the cron init-script is modified. +Firstly ​what to do is, add the jail_flag **'​allow-ipc-syslog'​**
- +
- +
-This first what to do is, add the jail_flag **'​allow-ipc-syslog'​**+
    ​(allow-ipc-syslog)    ​(allow-ipc-syslog)
    ()    ()
Line 40: Line 32:
    ()    ()
  
-All services ​need this wich send data to the syslogd. +All services ​which send data to the syslog ​need thisif the syslogd is jailed too.
-Thatswhy i started with the syslog-jail firstlyremeber add **'​allow-ipc-syslog'​** to all services wich get entry in the syslog fileServices like '​squid'​ or '​postfix'​+
  
-I stop the service /​etc/​init.d/​cron stop + 
-Then I start the service and look on the other terminal ​+I stop the service /​etc/​init.d/​cron stop and then I start the service and look on the other terminal
  
   /​etc/​init.d/​cron start    /​etc/​init.d/​cron start 
Line 53: Line 44:
   <​6>​0000001237|rsbac_adf_request():​ request WRITE_OPEN, pid 4631, ppid 1, prog_name cron, prog_file /​usr/​sbin/​cron,​ uid 0, remote ip 192.168.1.5,​ target_type DEV, tid char 01:03, attr open_flag, value 32834, result NOT_GRANTED by JAIL   <​6>​0000001237|rsbac_adf_request():​ request WRITE_OPEN, pid 4631, ppid 1, prog_name cron, prog_file /​usr/​sbin/​cron,​ uid 0, remote ip 192.168.1.5,​ target_type DEV, tid char 01:03, attr open_flag, value 32834, result NOT_GRANTED by JAIL
  
-Again search for target_type and request+search for target_type and request
    ​target_type DEV :: request WRITE_OPEN    ​target_type DEV :: request WRITE_OPEN
  
Line 86: Line 77:
    "​allow-dev-read":​ "​-d" ​      "​allow-dev-read":​ "​-d" ​  
  
-So add this to the cron-jailfile+The rsbac_jail say:    
 +   \- wiki display error 
 +   -D = allow read access on devices 
 + 
 +So add this to the cron-jailfile
    ​(allow-ipc-syslog ​    ​(allow-ipc-syslog ​
     allow-dev-write     allow-dev-write
Line 103: Line 98:
 And nothing appears on the security-users terminal. And nothing appears on the security-users terminal.
 So far ok. So far ok.
 +
 **B**ut crond job will comming son, with access to thinks wich are not setup in the moment. **B**ut crond job will comming son, with access to thinks wich are not setup in the moment.
 +
  
 For this a speed up the clock (only virtual :-)) to next cronjobs For this a speed up the clock (only virtual :-)) to next cronjobs
 +=====
  
  
//
wiki/experiences/igraltist/jail_cron.txt · Last modified: 2008/07/12 06:35 by 127.0.0.1

wiki/experiences/igraltist/jail_cron.txt · Last modified: 2008/07/12 06:35 by 127.0.0.1
This website is kindly hosted by m-privacy