From owner-freebsd-security Sun Sep 9 6:13: 3 2001 Delivered-To: freebsd-security@freebsd.org Received: from gamma.root-servers.ch (gamma.root-servers.ch [195.49.62.126]) by hub.freebsd.org (Postfix) with SMTP id 4FA6E37B401 for ; Sun, 9 Sep 2001 06:13:00 -0700 (PDT) Received: (qmail 61234 invoked from network); 9 Sep 2001 13:12:59 -0000 Received: from dclient217-162-128-224.hispeed.ch (HELO athlon550) (217.162.128.224) by 0 with SMTP; 9 Sep 2001 13:12:59 -0000 Date: Sun, 9 Sep 2001 15:16:42 +0200 From: Gabriel Ambuehl X-Mailer: The Bat! (v1.53bis) Educational Organization: BUZ Internet Services X-Priority: 3 (Normal) Message-ID: <151193622478.20010909151642@buz.ch> To: Giorgos Verigakis Cc: Deepak Jain , Kris Kennaway , D J Hawkey Jr , Alexander Langer , Subject: Re[2]: Kernel-loadable Root Kits In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org -----BEGIN PGP SIGNED MESSAGE----- Hello Giorgos, Sunday, September 09, 2001, 10:07:32 AM, you wrote: >> This user could easily edit the rc.conf file to boot up in >> securelevel=-1 and reboot the machine -- as well as circumvent >> most notifications about the reboot. > Yes, but then you can chflag schg rc.conf rc ... (or maybe the > whole /etc) Would you care to point out how I could lower the securelevel then for legitimate use (i.e. updates or changes to /etc) of the system by the administrators? Best regards, Gabriel -----BEGIN PGP SIGNATURE----- Version: PGP 6.5i iQEVAwUBO5tdrsZa2WpymlDxAQHC5Af+OWFg0iJhixVi5CmlBe4POEc8cQmai97W aa1eCPkkNqwHZBQD3b4CGlvCIJZogH0Nv+GQcvsJECx8GHBSczbjl6E003hVTpSr JiBILeEy2pp67rKRSM4KZjqvnLKWNoHjXfrd62Hr2SqqVZ4rtOkvwviW1QWF/DCO 52erGgJU7Xp2i83JlVWi0lUZsXuwSp6IafccfNVSuWluobJLzcS8Tg9FanPbnovR /1wgY0z0lEVm/ri2rPdUGM6kKSn3h+1ORltc/c9F2WVIqleL3Z4TAZOBrbKR+0Mm 6oD2SPRti6TZ9riB/ayK+Jafhhh7AC/le55exGlSzBNVF9SR5F4AWQ== =4lFV -----END PGP SIGNATURE----- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message