From owner-freebsd-hackers@FreeBSD.ORG Mon Jun 23 06:48:55 2003 Return-Path: Delivered-To: freebsd-hackers@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 0F3C437B404 for ; Mon, 23 Jun 2003 06:48:55 -0700 (PDT) Received: from cicero0.cybercity.dk (cicero0.cybercity.dk [212.242.40.52]) by mx1.FreeBSD.org (Postfix) with ESMTP id 7D8E143FEC for ; Mon, 23 Jun 2003 06:48:54 -0700 (PDT) (envelope-from db@traceroute.dk) Received: from user5.cybercity.dk (fxp0.user5.ip.cybercity.dk [212.242.41.51]) by cicero0.cybercity.dk (Postfix) with ESMTP id 03D2D102B99 for ; Mon, 23 Jun 2003 15:48:53 +0200 (CEST) Received: from main (port132.ds1-arsy.adsl.cybercity.dk [212.242.239.73]) by user5.cybercity.dk (Postfix) with SMTP id 50B7F2866BA for ; Mon, 23 Jun 2003 15:48:52 +0200 (CEST) Date: Mon, 23 Jun 2003 15:56:27 +0200 From: Socketd To: hackers@freebsd.org Message-Id: <20030623155627.5d0a0ad3.db@traceroute.dk> X-Mailer: Sylpheed version 0.8.10claws (GTK+ 1.2.10; i386-portbld-freebsd4.8) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Subject: Mounting X-BeenThere: freebsd-hackers@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Technical Discussions relating to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 23 Jun 2003 13:48:55 -0000 Hi again Would it be possible to have this configuration and not having the system fail (because of lacking rights or something): /tmp and /var/tmp noexec (I know /tmp has to be execuable to make world) /var nosuid (what about even noexec?) /var/mail noexec /home nosuid (again what about noexec if I don't have shell users, but only websites and backup's on /home?) Can nodev also be added to all above + /usr? br socketd