官术网_书友最值得收藏!

Introduction

Web applications are a prime example of where SELinux can prove its effectiveness. They are often facing the (untrusted) Internet and are a popular target to exploit. Securing the web server and web applications is just one of the basic mitigating strategies though—by confining the web server, we are reducing the results of a successful exploit even further.

A well-confined web server will only allow operations towards the operating system that are acceptable behavior for the service. But considering the wide area of services that can be provided through a web server, we must be careful not to open up too many privileges.

Policy developers have foreseen the situation that the web server domain might be too broad in its privileges and have made the web server domain (httpd_t) not only very versatile, but also very configurable. In this chapter, we will look into the domain in more detail.

主站蜘蛛池模板: 茶陵县| 邹平县| 叶城县| 略阳县| 乳源| 奎屯市| 上蔡县| 克山县| 尖扎县| 逊克县| 四平市| 宜川县| 舒城县| 葵青区| 惠来县| 汉沽区| 邵东县| 和田市| 繁峙县| 平江县| 拉萨市| 白朗县| 新闻| 长子县| 济宁市| 武胜县| 错那县| 呼伦贝尔市| 株洲市| 修武县| 张家界市| 四川省| 安阳县| 嘉祥县| 娱乐| 始兴县| 淳安县| 马山县| 尤溪县| 怀仁县| 老河口市|