Vulnerability Development mailing list archives

The use of immunix


From: Renee Teunissen <Renee () wittenburg10c nl>
Date: Mon, 26 Mar 2001 11:17:06 +0200

Dick Visser wrote:

On Mon, 26 Mar 2001, Renee Teunissen wrote:

The thing I read from booting of a CDROM is also a good choice, I think,
this will prevent people from booting from unwanted kernels.

Or adding that old SCSI disk with a kernel to boot from, that is jumpered
readonly. Also possible with IDE but you have to cut one (which one?) of
the 40/80 wires of the IDE-cable.....

Ofcourse, you are compleetly right. tftp booting is also an option, if one can
prevent the localnetwork to be compromised. Anyway I would go for the CDROM
for the ease of use, sinds its lots easier to replace a CDROM in case of an
kernel upgrade. On the otherhand, a lot of BIOSes can prevent the bootsector
to be upgraded. We all know if one does this, it will make the system stop,
and therefore getting a DOS, if anyone tries to upgrade the kernel.

Btw what kind of hacks do you guys apply to your kernel / distribution and
what distribution do you use? I'm using the sources of redhat which I rebuild,
but am thinking about using the sources supplied bij immunix, any comments on
this?
Especially the stackguard compiler thingies look very nice - but haven't used
it for primal systems.

Cheers,
Renee.
------------------------------------

Renee A. Teunissen
Technical Consultant Embedded and Internet Solutions
PTS Software bv,
Soerenseweg 61,
7314JE Apeldoorn,
The Netherlands.
phone +31-55-5363200
web: www.pts.nl, www.wittenburg10c.nl (home)
email: renee () pts nl, renee () wittenburg10c nl (home)


Current thread: