sealingtech / CLIP

SealingTech's Certifiable Linux Integration Platform
9 stars 12 forks source link

Refine etc_t write access #88

Open d3vilbox opened 5 years ago

d3vilbox commented 5 years ago

There are many domains that have write access to etc_t files. Along with modifying a host of configuration files you can also modify things like /etc/bashrc which would then let you run code as an admin user when they logged in.

We need to review who has write access to etc_t and create custom types if the domains only need access to specific files.