From: Kero Date: 2005-10-09T05:46:51+09:00 Subject: Re: Save the world from evil code crusade > One major problem when checking code is that checking names is not > sufficient. IMHO you cannot solve this by changing the Ruby interpreter > because you must trap into method calls for certain classes (File and Socket > come to mind) and check which binary method actually gets called. And that > doesn't even deal with user defined C extensions - I gues you would have to > prohibit them altogether. > >> If you do, I guess it would be "do not allow" by default -- so that if >> someone tried to sneak in something bad (by doing some kind of >> scrambling or method renaming or something), it would just be ignored. > > Although I agree from a security perspective that could mean that > extensibility and maybe user defined classes suffer... Could a SeLinux sandbox (or binding) work? I've never used SE Linux, so my suggestion may be dumb. +--- Kero ------------------------- kero@chello@nl ---+ | all the meaningless and empty words I spoke | | Promises -- The Cranberries | +--- M38c --- http://members.chello.nl/k.vangelder ---+