|
5/27 |
2000/1/27-28 [Computer/SW/OS/FreeBSD, Computer/SW/Security] UID:17349 Activity:high |
1/26 Are the security benefits of mounting /usr partition in read-only mode worth the trouble of rebooting your server whenever you install OS patches or updates? -sysadm \- this isnt worth doing ... at least not on solaris. spend a little more energy on keeping md5 checksums --psb \_ an ounce of prevention is wourth a pound of "AAAa! We've been hacked, FIX IT!" \_ Depends on your needs. Extra security vs convenience. In general, I'd say don't do stuff like this unless you're sure you need to. That you have to ask says you probably don't need it. \_ Most of the time you have to reboot after installing OS patches & updates anyway. \_ Ok I will modify my question. What about simple and yet important updates that DON'T require a reboot. I'd rather restrart a service than reboot. -sysadm \_ what's going to stop some cracker from just remounting /usr r/w, changing stuff, and then having a ball ? I dont see any benefit in the world of mounts with -o remount or -u (bsd) -ERic \_ The only security benfit is to block script kiddies. Crackers with half a clue can get right past it. \_ You NEED TO BE ROOT to remount. the whole point is to make it more difficult for them to get it \_ Eye 0wn3d y00!111 |
5/27 |
|