Firewall Wizards mailing list archives

Re: chroot useful?


From: Claudio Telmon <claudio () link it>
Date: Sun, 09 Nov 1997 19:35:41 +0100

Darren Reed wrote:

Not *BSD anyway.  Procfs (and kernfs) can be excluded from the kernel
when you build them.  Although they can then be modloaded, if you're
allowing modloads in multiuser mode on your firewall, then you're just
asking for trouble.


Yes, you can do the same on linux: compiling the kernel without proc
filesystem
and loadable module support. With the proc filesystem it's just more
simple, but as you and others pointed out, on a typical system the whole
thing is not becoming root, or else everything is possible.

Thanks 

ciao

- Claudio



Current thread: