
2
Selecting Programs to Immunize
Novell® AppArmor quarantines programs to protect the rest of the system from being
damaged by a compromised process. You should inspect your ports to see which pro-
grams should be profiled (refer to
Section 2.2, “Inspect Open Ports to Immunize Pro-
grams”
(page 16)) and profile all programs that grant privilege (
Section 2.1, “Immunize
Programs That Grant Privilege”
(page 15)).
2.1 Immunize Programs That Grant
Privilege
Programs that need profiling are those that mediate privilege. The following programs
have access to resources that the person using the program does not have, so they grant
the privilege to the user when used:
cron jobs
Programs that are run periodically by cron. Such programs read input from a variety
of sources and can run with special privileges, sometimes with as much as root
privilege. For example, cron can run
/usr/bin/updatedb
daily to keep the
locate database up to date with sufficient privilege to read the name of every file
in the system. For instructions for finding these types of programs, refer to
Sec-
tion 2.2.1, “Immunizing Cron Jobs”
(page 18).
Web Applications
Programs that can be invoked through a Web browser, including CGI Perl scripts,
PHP pages, and more complex Web applications. For instructions on finding these
Selecting Programs to Immunize
15
Summary of Contents for APPARMOR 1.2
Page 1: ...Novell AppArmor Powered by Immunix Administration Guide www novell com 1 2 09 29 2005...
Page 4: ......
Page 14: ......
Page 116: ......
Page 128: ......