From owner-cvs-all@FreeBSD.ORG Mon Aug 2 12:18:37 2004 Return-Path: Delivered-To: cvs-all@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 11AD116A4CE for ; Mon, 2 Aug 2004 12:18:37 +0000 (GMT) Received: from kaiser.sig11.org (host236-153.pool8250.interbusiness.it [82.50.153.236]) by mx1.FreeBSD.org (Postfix) with ESMTP id 4734E43D64 for ; Mon, 2 Aug 2004 12:18:34 +0000 (GMT) (envelope-from rionda@riondato.com) Received: by kaiser.sig11.org (Postfix, from userid 1000) id 62C35F6; Mon, 2 Aug 2004 14:18:49 +0200 (CEST) From: Matteo Riondato To: Dag-Erling =?ISO-8859-1?Q?Sm=F8rgrav?= In-Reply-To: References: <200408011140.i71BesOt070889@repoman.freebsd.org> <1091447175.2201.48.camel@kaiser.sig11.org> Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="=-dod/U37iRWIQro4t8eXA" Message-Id: <1091449128.2201.50.camel@kaiser.sig11.org> Mime-Version: 1.0 X-Mailer: Ximian Evolution 1.4.6 Date: Mon, 02 Aug 2004 14:18:49 +0200 cc: cvs-all@FreeBSD.org Subject: Re: cvs commit: src/sys/alpha/alpha mem.c src/sys/alpha/confmem.c memdev.h src/sys/conf NOTES files files.alpha files.amd64 ... X-BeenThere: cvs-all@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: CVS commit messages for the entire tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 02 Aug 2004 12:18:37 -0000 --=-dod/U37iRWIQro4t8eXA Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable Il Lun, 2004-08-02 alle 14:14, Dag-Erling Sm=F8rgrav ha scritto: > Matteo Riondato writes: > > Dag-Erling Sm=F8rgrav wrote: > > > The other good news of course is that it is now possible to build a > > > kernel that does not have /dev/mem and /dev/io - that's pretty > > > significant from a security point of view. Thanks! > > Can you please explain why it's signficant? >=20 > /dev/mem and /dev/io are back doors to a system's memory and hardware, > which allow you to bypass all error and credential checks once you've > gained access to them. > [SNIP] Thanks, You were really clear. Best Regards --=20 Rionda aka Matteo Riondato GUFI Staff Member (http://www.gufi.org) BSD-FAQ-it Main Developer (http://www.gufi.org/~rionda) FreeSBIE BugMeister (http://www.freesbie.org) GPG key at: http://www.riondabsd.net/riondagpg.asc Sent from: kaiser.sig11.org running FreeBSD-5.2-CURRENT --=-dod/U37iRWIQro4t8eXA Content-Type: application/pgp-signature; name=signature.asc Content-Description: Questa parte del messaggio =?ISO-8859-1?Q?=E8?= firmata -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (FreeBSD) iD8DBQBBDjEo2Mp4pR7Fa+wRArF1AJ4oLzEBctJ/szz83me1oJe32a8e5wCfev5j aqyNDy0qyVU6J7qEUjKISWQ= =2QGc -----END PGP SIGNATURE----- --=-dod/U37iRWIQro4t8eXA--