Skip to Content
Linux Administration Cookbook
book

Linux Administration Cookbook

by Adam K. Dean
December 2018
Beginner
826 pages
22h 54m
English
Packt Publishing
Content preview from Linux Administration Cookbook

There's more...

While AppArmor is nice and it definitely does what it advertises, there are some caveats:

  • It relies on developers to write and supply profiles (or others who contribute the time) 
  • Profiles have to be bulletproof before they can be included in the default installation, which could be the reason there are so few even after a decade
  • It's fairly unknown and most people don't even bother with it outside of the defaults

It also goes off path, rather than inode, meaning you can do things such as create a hardlink to bypass restrictions:

$ sudo ln /usr/sbin/tcpdump /usr/sbin/tcpdump-clone

Admittedly, if you're on a box and have sudo, it's pretty much game over at that point anyway:

$ sudo tcpdump -i enp0s3tcpdump: enp0s3: You don't ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Practical Linux Security Cookbook - Second Edition

Practical Linux Security Cookbook - Second Edition

Tajinder Kalsi
Mastering Linux Administration

Mastering Linux Administration

Alexandru Calcatinge, Julian Balog

Publisher Resources

ISBN: 9781789342529Supplemental Content