From owner-freebsd-current@FreeBSD.ORG Mon Nov 7 22:41:38 2005 Return-Path: X-Original-To: freebsd-current@FreeBSD.org Delivered-To: freebsd-current@FreeBSD.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9E5EC16A422 for ; Mon, 7 Nov 2005 22:41:38 +0000 (GMT) (envelope-from full-disclosure@csilva.org) Received: from jupiter.nswebhost.com (jupiter.nswebhost.com [72.9.236.194]) by mx1.FreeBSD.org (Postfix) with ESMTP id F0D8343D64 for ; Mon, 7 Nov 2005 22:41:31 +0000 (GMT) (envelope-from full-disclosure@csilva.org) Received: from 55-246.dial.nortenet.pt ([212.13.55.246]:34828 helo=[192.168.1.10]) by jupiter.nswebhost.com with esmtpa (Exim 4.52) id 1EZFfz-00028b-Bg for freebsd-current@FreeBSD.org; Mon, 07 Nov 2005 17:41:19 -0500 Message-ID: <436FD822.5000002@csilva.org> Date: Mon, 07 Nov 2005 22:41:38 +0000 From: Carlos Silva aka |Danger_Man| User-Agent: Mozilla Thunderbird 1.0.6 (Windows/20050716) X-Accept-Language: en-us, en MIME-Version: 1.0 To: freebsd-current@FreeBSD.org Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Antivirus-Scanner: Clean mail though you should still use an Antivirus X-AntiAbuse: This header was added to track abuse, please include it with any abuse report X-AntiAbuse: Primary Hostname - jupiter.nswebhost.com X-AntiAbuse: Original Domain - freebsd.org X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12] X-AntiAbuse: Sender Address Domain - csilva.org X-Source: X-Source-Args: X-Source-Dir: Cc: Subject: Security updates without rebooting X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 07 Nov 2005 22:41:38 -0000 Hello all, Can someone explain how to apply security patches on the system without rebooting the machine? I guess that I cant patch the kernel without compiling and rebooting the machine, so the only way is with iptables and keeping the daemons "fresh"? Regards, Carlos Silva, http://osiris.csilva.org/