Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 12 May 1999 16:51:27 +1000 (EST)
From:      Darren Reed <avalon@coombs.anu.edu.au>
To:        shadows@whitefang.com (Thamer Al-Herbish)
Cc:        freebsd-security@FreeBSD.ORG
Subject:   Re: Wrapping syscalls
Message-ID:  <199905120651.QAA05838@cheops.anu.edu.au>
In-Reply-To: <Pine.BSF.4.05.9905111427460.253-100000@rage.whitefang.com> from "Thamer Al-Herbish" at May 11, 99 02:29:02 pm

next in thread | previous in thread | raw e-mail | index | archive | help
In some mail from Thamer Al-Herbish, sie said:
> 
> On Wed, 12 May 1999, Darren Reed wrote:
> 
> > Logging would be interesting, as would write'ing data to be sent
> > back to the client :-)  Lets hope they're not interested in using
> > CGI either :-)
> 
> You would need some granulity I suppose. Just looked at the TIS
> post, it's been done and done well it seems.

TIS post ?

> > This isn't a capability based solution in the traditional sense of
> > that term, more of a means being able to deny yourself use of certain
> > system calls.
> 
> Absolutely not.

What you described is somewhat like a product from Axent.

Capabilities are not tied to system calls, system calls just provide a
user interface to them.

Darern


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199905120651.QAA05838>