Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Rule updates next #293

Merged
merged 90 commits into from
Oct 25, 2017
Merged

Rule updates next #293

merged 90 commits into from
Oct 25, 2017

Conversation

mstemm
Copy link
Contributor

@mstemm mstemm commented Oct 25, 2017

Syncing the next batch of rule updates to dev.

mstemm added 30 commits October 19, 2017 16:17
Add support for db management programs that tend to spawn
shells. Starting with two lists
mysql_mgmt_binaries/postgres_mgmt_binaries which are combined into
db_mgmt_binaries. db_mgmt_binaries is added to both shell spawning rules
and the individual programs are removed.
Allow dovecot to setuid by adding to mail_binaries.

Allow the program auth, when run by dovecot, to spawn shells.
Create a list plesk_binaries and allow them to run shells.

Also let them write to files below /etc/sw/keys.
Specifically the program starter. Using the full command line to be more
specific.
The program is "my_init", which is fairly generic, so capture it by the
full command line.
It might perform dns lookups as a part of resolving ip addresses.
truncated version of docker-runc-current.
New rule Launch Disallowed Container triggers when a container is
started that does not match the macro allowed_containers. In the main
falco rules file, this macro never matches, so it never
triggers. However, in a second rules file the macro allowed_containers
could be filled in with the specific images that match.
Used by Red Hat Sattelite.
Appears as java program, so look for the classpath.
In some cases, the container image might not be known/is NULL, so the
comparison aganst "dummy-not-allowed-container-image" doesn't work.

Replace this with proc.vpid=1, which is in the main rule Launch
Disallowed Continer. Ensures it will only trigger when the
allowed_containers macro is overridden.
It's java so you need to look at the classpath.
Should be testing proc.name, not proc.cmdline.
S99qualys-cloud is the init script, cfn-signal is cloudformation.
It can run scripts like sed to modify files before writing the final
file.
mstemm added 26 commits October 23, 2017 11:05
A legitimate case is k8s mounting /etc/kubernetes/ssl, which was
matching /etc*. The glob matcher we have isn't a full regex so you can't
exclude strings, only characters.
Generalize jenkins_script_sh to jenkins_scripts and add additional
cases.
Better than globally letting php spawn shells.
rhsmcertd-worke(r), red hat subscription manager
device mapper event daemon.
New macro user_sensitive_mount_containers allows a second rules file to
specify containers/images that can perform sensitive mounts.
It has -g/-u args to change gid/uid.

Also move some other single setuid programs to the list
known_setuid_binaries.
Reorganize the unknown_user_in_container macro to get it working again
in containers. Previously, it was being skipped entirely due to a
problem with handling of unknown users, which get returned as NULL.

The new macro is known_user_in_container, which tests the user.name
against "N/A". It happens that if user.name is NULL, the comparison
fails, so it has the same effect as if the string "N/A" were being
returned. Any valid user name won't match the string "N/A", so known
users will cause the macro to return true.

The setuid rule needs an additional check for not container, so add that.
Add lists of files/directories that are acceptable to write.
@mstemm mstemm force-pushed the rule-updates-next branch from b449244 to 71a386f Compare October 25, 2017 20:52
@mstemm mstemm merged commit ccea09b into dev Oct 25, 2017
@mstemm mstemm deleted the rule-updates-next branch October 25, 2017 21:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants