From owner-freebsd-security@FreeBSD.ORG Wed Feb 11 09:55:07 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id B8C9116A4CE for ; Wed, 11 Feb 2004 09:55:07 -0800 (PST) Received: from mail.secureworks.net (mail.secureworks.net [209.101.212.155]) by mx1.FreeBSD.org (Postfix) with SMTP id 560BD43D1D for ; Wed, 11 Feb 2004 09:55:07 -0800 (PST) (envelope-from mdg@secureworks.net) Received: (qmail 4318 invoked from network); 11 Feb 2004 17:51:59 -0000 Received: from unknown (HELO HOST-192-168-8-8.internal.secureworks.net) (63.239.86.253) by mail.secureworks.net with SMTP; 11 Feb 2004 17:51:59 -0000 Date: Wed, 11 Feb 2004 12:55:06 -0500 (EST) From: Matthew George X-X-Sender: mdg@localhost To: twig les In-Reply-To: <20040211172958.8439.qmail@web60407.mail.yahoo.com> Message-ID: <20040211125137.G30841@localhost> References: <20040211172958.8439.qmail@web60407.mail.yahoo.com> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII cc: Liste FreeBSD-security Subject: Re: Question about securelevel X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 11 Feb 2004 17:55:07 -0000 On Wed, 11 Feb 2004, twig les wrote: > circumstances since you can still write to a read-only fs if you > can get to the raw device. If anyone has a link to a drive that securelevel 2 precludes this: 2 Highly secure mode - same as secure mode, plus disks may not be opened for writing (except by mount(2)) whether mounted or not. -- Matthew George SecureWorks Technical Operations