apparmor and /usr/bin/strings
With the command
/usr/bin/strings /dev/mem | less
I am able to read my WPA-PSK password of my router in cleartext. Strings can only be run as root. There is a security risk here. Immunizing 'strings' with apparmor causes strings not to run as root anymore (have tested it), but how is the correct set-up in the apparmor here? I do not exactly know how to specifically put it on configuration. Maybe it is as simple as the YaST does it, but to be sure.....?
- SuSE Linux 10.0 and SLED10-SP2 on 2 machines. -
Thanks,
sigbj.
|