Re: preventing tampering with tripwire

From: Maxlor (mail@maxlor.com)
Date: 06/19/02


Date: Wed, 19 Jun 2002 02:12:33 +0200
From: Maxlor <mail@maxlor.com>
To: Baldur Gislason <baldur@foo.is>

As I read that, I thought "Doh". Thats really pretty much the ideal
solution...

And if an attacker has physical access to my machine, well, he can do
pretty much anything he wants anyway.

Thanks!

--On Dienstag, 18. Juni 2002 23:40 +0000 Baldur Gislason <baldur@foo.is>
wrote:

> use kern.securelevel 1 or higher and man chflags, set the tripwire binary
> schg so it cannot be tampered with. Of course there's no such thing as
> absolute security, but this moves you just a step closer. Unless the
> intruder performs a reboot and makes his changes before the kernel
> securelevel is raised on boot.
>
> Baldur

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: boot -s - can i detect intruder
    ... I know that if someone have physical access to my servers can penetrade into ... > attacker is at all sophisticated, but if the attacker is really clueless, ... the user could select a shell of his own. ...
    (FreeBSD-Security)
  • Re: Do I have to set another password in the CMOS setting to enhance the security of OS?
    ... one of the "ten immutable laws" is that physical access beats ... Even using encryption is a kind of a gamble, ... useless to me as an attacker. ... Software Design Engineer, Internet Information Server ...
    (microsoft.public.security)
  • Re: Win2k3 Web Edition - Usage of EFS
    ... with physical access an administrator. ... And the data will be unreadable even to an attacker ... If you use EFS, *please* back up those users' encryption certificates (and ...
    (microsoft.public.security)
  • Re: Protection from Hackers
    ... physical access to the system. ... You protect against this sort of attack by ... The bottom line is that once your attacker has physical access, ... > Administrator account, but this program showed ALL accounts and you ...
    (microsoft.public.win2000.security)
  • Re: Wierd one
    ... doh - good point! ... PHP - so thats not a bad idea at all. ... Els wrote: ...
    (alt.html)