官术网_书友最值得收藏!

Introduction

Web applications are a prime example of where SELinux can prove its effectiveness. They are often facing the (untrusted) Internet and are a popular target to exploit. Securing the web server and web applications is just one of the basic mitigating strategies though—by confining the web server, we are reducing the results of a successful exploit even further.

A well-confined web server will only allow operations towards the operating system that are acceptable behavior for the service. But considering the wide area of services that can be provided through a web server, we must be careful not to open up too many privileges.

Policy developers have foreseen the situation that the web server domain might be too broad in its privileges and have made the web server domain (httpd_t) not only very versatile, but also very configurable. In this chapter, we will look into the domain in more detail.

主站蜘蛛池模板: 泾川县| 慈溪市| 通化市| 连江县| 大渡口区| 日土县| 平谷区| 陵川县| 湘西| 高邑县| 清徐县| 孟连| 耒阳市| 阿勒泰市| 宁蒗| 三亚市| 玛沁县| 嘉峪关市| 开远市| 常熟市| 陵川县| 花垣县| 寿宁县| 孟连| 新昌县| 六枝特区| 密山市| 垦利县| 含山县| 元谋县| 和龙市| 务川| 长宁区| 荔波县| 正安县| 苍山县| 连平县| 丹东市| 栾川县| 汉源县| 新巴尔虎右旗|