From owner-freebsd-security Thu Dec 21 13:48:28 2000 From owner-freebsd-security@FreeBSD.ORG Thu Dec 21 13:48:25 2000 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from odin.ac.hmc.edu (Odin.AC.HMC.Edu [134.173.32.75]) by hub.freebsd.org (Postfix) with ESMTP id 8C56A37B400 for ; Thu, 21 Dec 2000 13:48:25 -0800 (PST) Received: (from brdavis@localhost) by odin.ac.hmc.edu (8.11.0/8.11.0) id eBLLmOd30045; Thu, 21 Dec 2000 13:48:24 -0800 Date: Thu, 21 Dec 2000 13:48:24 -0800 From: Brooks Davis To: kj@indifference.org Cc: freebsd-security@FreeBSD.ORG Subject: Re: Read-Only Filesystems Message-ID: <20001221134824.A29237@Odin.AC.HMC.Edu> References: <20001219114936.A23819@rfx-64-6-211-149.users.reflexco> <20001219120953.S19572@fw.wintelcom.net> <20001219211642.D13474@citusc.usc.edu> <3A40BED3.1070909@2cactus.com> <20001220174056.C22288@citusc.usc.edu> <20001220174129.F19572@fw.wintelcom.net> <20001220175931.E22288@citusc.usc.edu> <20001220231205.W96105@149.211.6.64.reflexcom.com> <20001221060108.B26775@citusc.usc.edu> <20001221140435.F25684@indifference.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2i In-Reply-To: <20001221140435.F25684@indifference.org>; from kj@indifference.org on Thu, Dec 21, 2000 at 02:04:35PM -0800 Sender: brdavis@odin.ac.hmc.edu Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org On Thu, Dec 21, 2000 at 02:04:35PM -0800, kj@indifference.org wrote: > To be truly, anal. Couldn't one just put a bios boot password on every > server reboot (really how often do we need to reboot). And have a serial > console hooked up to the server. > > That way if the attacker drops the security level and reboots, he can't > modify anything as the server never boots up. It's major downtime, but > better then a comprimise. Unless the next boot is a CD or floppy which does an integrity test of the entire system that don't do much because as soon as the system boots the security level bypassing compromise occures. Unless you're sure you protected everything related to the loader, modules, and kernel this could even happen if you just boot to single user mode. The password would mean things took longer but they wouldn't actually stop you from being back doored. Isn't paranoia fun. ;-) -- Brooks -- Any statement of the form "X is the one, true Y" is FALSE. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message