From owner-freebsd-hackers Fri Feb 9 21:39: 6 2001 Delivered-To: freebsd-hackers@freebsd.org Received: from mta6.snfc21.pbi.net (mta6.snfc21.pbi.net [206.13.28.240]) by hub.freebsd.org (Postfix) with ESMTP id 923D137B401 for ; Fri, 9 Feb 2001 21:38:46 -0800 (PST) Received: from xor.obsecurity.org ([63.207.60.67]) by mta6.snfc21.pbi.net (Sun Internet Mail Server sims.3.5.2000.01.05.12.18.p9) with ESMTP id <0G8J00HIE0O6IL@mta6.snfc21.pbi.net> for freebsd-hackers@freebsd.org; Fri, 9 Feb 2001 21:31:19 -0800 (PST) Received: by xor.obsecurity.org (Postfix, from userid 1000) id 4643C66B62; Fri, 09 Feb 2001 21:34:04 -0800 (PST) Date: Fri, 09 Feb 2001 21:34:04 -0800 From: Kris Kennaway Subject: Re: /etc/security: add md5 to suid change notification? In-reply-to: <3A84D3F7.1CCE62A3@softweyr.com>; from wes@softweyr.com on Fri, Feb 09, 2001 at 10:39:03PM -0700 To: Wes Peters Cc: freebsd-hackers@freebsd.org Message-id: <20010209213404.A85235@mollari.cthul.hu> MIME-version: 1.0 Content-type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="G4iJoqBmSsgzjUCe" Content-disposition: inline User-Agent: Mutt/1.2.5i References: <200102082355.f18NtfF89134@medusa.kfu.com> <3A84582E.3000702@quack.kfu.com> <3A84D3F7.1CCE62A3@softweyr.com> Sender: owner-freebsd-hackers@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.ORG --G4iJoqBmSsgzjUCe Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Fri, Feb 09, 2001 at 10:39:03PM -0700, Wes Peters wrote: > Add a list of executables and their MD5's to the kernel, to be loaded at > boot time via the loader. Modify the kernel loader to refuse to exec > any executable whose MD5 is known but doesn't match. Ditto for shared > libraries and ld.so. There you have it, a system that cannot be=20 > upgraded except in single-user mode. Be sure not to allow any scripting languages to be executed. Getting away without /bin/sh might be tough, you can probably do a lot with builtins if you're creative. Kris --G4iJoqBmSsgzjUCe Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.4 (FreeBSD) Comment: For info see http://www.gnupg.org iD8DBQE6hNLLWry0BWjoQKURAoGkAKCarhDAbKEOdnl7544mrJVaE4k/AACgv2e1 FG3SqJ3NrEylPm16Pa/ibok= =KzPG -----END PGP SIGNATURE----- --G4iJoqBmSsgzjUCe-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-hackers" in the body of the message