Monitoring and prevention of MBR activity.

Mr Dash Four mr.dash.four at googlemail.com
Tue Sep 6 15:06:35 UTC 2011


> Now if you have a app/admin user process that needs to have full
> access to the system but want to make sure he does not modify the MBR
> you will have a difficult time writing policy for this.
>   
Not to mention that there are some tools - parted being one - which need 
access (rw) to that sector of the hdd, regardless of who runs these tools.



More information about the selinux mailing list