From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (qmail 355 invoked by alias); 4 Dec 2003 02:36:37 -0000 Mailing-List: contact overseers-help@sources.redhat.com; run by ezmlm Precedence: bulk List-Archive: List-Post: List-Help: , Sender: overseers-owner@sources.redhat.com Received: (qmail 336 invoked from network); 4 Dec 2003 02:36:37 -0000 Received: from unknown (HELO mx1.redhat.com) (66.187.233.31) by sources.redhat.com with SMTP; 4 Dec 2003 02:36:37 -0000 Received: from int-mx1.corp.redhat.com (int-mx1.corp.redhat.com [172.16.52.254]) by mx1.redhat.com (8.11.6/8.11.6) with ESMTP id hB42ab224640 for ; Wed, 3 Dec 2003 21:36:37 -0500 Received: from lacrosse.corp.redhat.com (lacrosse.corp.redhat.com [172.16.52.154]) by int-mx1.corp.redhat.com (8.11.6/8.11.6) with ESMTP id hB42ab229434; Wed, 3 Dec 2003 21:36:37 -0500 Received: from localhost (mgalgoci@localhost) by lacrosse.corp.redhat.com (8.11.6/8.11.6) with ESMTP id hB42aaT09146; Wed, 3 Dec 2003 21:36:36 -0500 X-Authentication-Warning: lacrosse.corp.redhat.com: mgalgoci owned process doing -bs Date: Thu, 04 Dec 2003 02:36:00 -0000 From: Matthew Galgoci X-X-Sender: mgalgoci@lacrosse.corp.redhat.com To: Christopher Faylor cc: overseers@sources.redhat.com Subject: Re: have we been sucked by suckit? In-Reply-To: Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII X-SW-Source: 2003-q4/txt/msg00197.txt.bz2 Ok, I am en route as soon as I send this mail. ETA of 45 minutes barring me actually finding anything wrong with sources. On Wed, 3 Dec 2003, Matthew Galgoci wrote: > > Btw I am running late unfortunately :\ > > I will be at the colo some time this evening (soon I hope) and get > the checking done as soon as possible. > > On Wed, 3 Dec 2003, Christopher Faylor wrote: > > > On Wed, Dec 03, 2003 at 08:29:16PM -0500, Matthew Galgoci wrote: > > >I am going to check it by hand this evening, booted from rescue media. > > > > > >I also have a hardened kernel to install on it that raises the bar on > > >exports through /dev/mem, which is how sukkit is installed. > > > > And, eventually I'll turn off module support in the kernel, which is > > another potential hole. > > > > Long term plans are to use SElinux. That would be cool even for the > > non-security aspects. > > > > cgf > > > > -- Matthew Galgoci System Administrator Red Hat, Inc 919.754.3700 x44155