LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old 08-Mar-2009, 04:19 PM
Junior Member
 
Join Date: Mar 2008
Posts: 11
sigbj 0 reputation points
Default apparmor and /usr/bin/strings

With the command

/usr/bin/strings /dev/mem | less

I am able to read my WPA-PSK password of my router in cleartext. Strings can only be run as root. There is a security risk here. Immunizing 'strings' with apparmor causes strings not to run as root anymore (have tested it), but how is the correct set-up in the apparmor here? I do not exactly know how to specifically put it on configuration. Maybe it is as simple as the YaST does it, but to be sure.....?

- SuSE Linux 10.0 and SLED10-SP2 on 2 machines. -

Thanks,
sigbj.
Reply With Quote
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -6. The time now is 08:43 AM.


© 2007 Novell, Inc. All Rights Reserved.

Search Engine Friendly URLs by vBSEO 3.3.0 RC2