Contributed by jose on from the sandbox dept.
"Michael Lucas (of Absolute BSD fame) does a nice job of explaining what systrace does and how to write a systrace policy in this article. "It's a very brief article, but serves as useful documentation on Systrace (found in NetBSD as well as OpenBSD).
(Comments are closed)
By Justin () on
Tools like this require that you understand more of the system than I am used to understanding, which is good and bad. Bad because then I have go to take some time to know what I am doing. Good because of the same reason as bad.
This goes well with the previous post on deadly about documentation. Good timing and well done Michael.
By Script Kiddie! () on
- Non-executable stack
- Systrace
It's like breaking into a house and being stuck in a box with nothing to do :(
You never let me have any fun lol
By Anonymous Coward () on
Does it really need the frontend? My OpenBSD box is headless, what are my options?
Comments
By jose () on http://monkey.org/~jose/
the normal Xsystrace that ships with the system uses simple X widgets. the extended gtksystrace uses the gtk widgets.
you dont need gtk or even X to run systrace.
By Anonymous Coward () on
Comments
By Andrew Thomas Pinski () pinskia@physics.uc.edu on mailto:pinskia@physics.uc.edu
By tedu () on
By RC () on
It's a bit more advanced, and doesn't require the user to setup config files either. I tried it for a short time, a nd decided that I perfered systrace's method, despite the advanced setup. One thing in Cylant's favor is that it is more mature, and some companies are using it in real-world situations.
By MK () on
AFAICT there have been no openbsd systrace commits since Dec 11, and Provos' page states that systrace is now part of netbsd -current.
And please no fucking "speculation". Does anyone have any FACTS about this?
Comments
By Anonymous Coward () on
Comments
By Anonymous Coward () on
I'd like to know how did that happen. I mean, Provos is an awesome coder and well respected security developer. Why in the world would we want to lose someone like him? (by going to NBSD is not actually losing, but it certainly is a step farther away).
Comments
By Anonymous Coward () on