From owner-freebsd-questions@FreeBSD.ORG Sun Apr 16 21:51:58 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5447916A400; Sun, 16 Apr 2006 21:51:58 +0000 (UTC) (envelope-from kstewart@owt.com) Received: from smtp.owt.com (smtp.owt.com [204.118.6.19]) by mx1.FreeBSD.org (Postfix) with ESMTP id 048E543D48; Sun, 16 Apr 2006 21:51:57 +0000 (GMT) (envelope-from kstewart@owt.com) Received: from topaz-out (owt-207-41-94-233.owt.com [207.41.94.233]) by smtp.owt.com (8.12.8/8.12.8) with ESMTP id k3GLppXK018277; Sun, 16 Apr 2006 14:51:52 -0700 From: Kent Stewart To: freebsd-questions@freebsd.org Date: Sun, 16 Apr 2006 14:51:55 -0700 User-Agent: KMail/1.9.1 References: <20060416205147.6544228454@porsche.brendan.id.au> <4442B4C8.40602@freebsd.org> In-Reply-To: <4442B4C8.40602@freebsd.org> MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200604161451.55744.kstewart@owt.com> Cc: Brendan Grossman , Colin Percival Subject: Re: /boot at beginning of drive X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 16 Apr 2006 21:51:58 -0000 On Sunday 16 April 2006 14:19, Colin Percival wrote: > Brendan Grossman wrote: > > Here is my reason for separating /tmp and mounting it > > noexec,nosuid: > > > > http://www.sagonet.com/forums/showthread.php?t=2852 > > Quoth mount(8): > noexec Do not allow execution of any binaries on the > mounted file system. This option is useful for a server that has > file systems containing binaries for architectures other than its > own. Note: This option was not designed as a security feature and no > guarantee is made that it will prevent malicious code execution; for > example, it is still possible to execute scripts which reside on a > noexec mounted partition. > > Mounting /tmp as noexec causes perfectly good code to gratuitously > fail, while providing no real security improvement. Including weird system or port update failures. Kent -- Kent Stewart Richland, WA http://www.soyandina.com/ "I am Andean project". http://users.owt.com/kstewart/index.html