se linux for everyday sysadmins

22
SELinux for Everyday SysAdmins Jeronimo Zucco [email protected] Ulisses Castro [email protected] 10º Forum Internacional de Software Livre – FISL 2009

Upload: ulisses-castro

Post on 25-Dec-2014

771 views

Category:

Technology


5 download

DESCRIPTION

Palestra realizada 10° Fórum Internacional Software Livre(http://fisl.softwarelivre.org/10/papers/pub/programacao?print=1)

TRANSCRIPT

Page 1: SE Linux For Everyday SysAdmins

SELinux forEveryday SysAdmins

Jeronimo Zucco [email protected]

Ulisses [email protected]

10º Forum Internacional de Software Livre – FISL 2009

Page 2: SE Linux For Everyday SysAdmins

Quem Somos ?

● Jeronimo Zucco: Bacharel em Ciência da Computação e Pós-Graduado em Gerência e Segurança de Redes. 11 anos de experiência com GNU/Linux.

● Ulisses Castro: Consultor, Instrutor e Pentester com ênfase em Software Livre, Hardening em Sistemas Operacionais e Banco de Dados, Mantenedor Debian (selinux-basics), OWASP: ASDR, Top Ten, CEH (Certified Ethical Hacker), LPIC-2, Desenvolvedor Python

Page 3: SE Linux For Everyday SysAdmins

Incidentes de Segurança

Page 4: SE Linux For Everyday SysAdmins
Page 5: SE Linux For Everyday SysAdmins
Page 6: SE Linux For Everyday SysAdmins
Page 7: SE Linux For Everyday SysAdmins

Contextos de Segurança

● ls -Z-rw-r--r--. root root system_u:object_r:net_conf_t:s0 /etc/resolv.conf

drwxr-xr-x. jczucco jczucco unconfined_u:object_r:user_home_t:s0 Documents

Page 8: SE Linux For Everyday SysAdmins

Firefox poderia ler a chave privada?

ronaldo 5949 3.6 12.8 130792 32188 ? Sl23:43 0:06 firefox-bin

-rw------- 1 ronaldo admins 1671 Aug 11 23:48 id_rsa

Page 9: SE Linux For Everyday SysAdmins

DAC x MAC

Page 10: SE Linux For Everyday SysAdmins
Page 11: SE Linux For Everyday SysAdmins

Security-Enhanced Linux

Page 12: SE Linux For Everyday SysAdmins
Page 13: SE Linux For Everyday SysAdmins

SELinux - Arquitetura

Page 14: SE Linux For Everyday SysAdmins

SELinux - Elementos

Page 15: SE Linux For Everyday SysAdmins

Usabilidade

“...life is too short for SELinux.” (Theodore Ts’o)”

Page 16: SE Linux For Everyday SysAdmins

SELinux – Política Targeted

Page 17: SE Linux For Everyday SysAdmins

SELinux Management

Page 18: SE Linux For Everyday SysAdmins

SeTroubleshoot

Page 19: SE Linux For Everyday SysAdmins

SELinux: Possibilidades de Uso● Labeled networking● Quiosque● Svirt● Sandbox● RBAC● Android● Sepgsql

● MLS● MCS● mod_selinux

Page 20: SE Linux For Everyday SysAdmins

man -k selinux

Page 21: SE Linux For Everyday SysAdmins

demo

Page 22: SE Linux For Everyday SysAdmins

OBRIGADO!Ulisses Castro

[email protected]

Jeronimo [email protected]

jczucco.blogspot.com