Re: read-only file systems

From: Vladimir Ivanov (VIvanov@tee.toshiba.de)
Date: 09/11/01


Message-ID: <3B9DC8A4.80AE73AF@tee.toshiba.de>
Date: Tue, 11 Sep 2001 10:17:40 +0200
From: Vladimir Ivanov <VIvanov@tee.toshiba.de>
To: focus-sun@securityfocus.com
Subject: Re: read-only file systems


> > I know /usr can be comfortably turned in to a read-only file system
> for
> > particularly hardened systems - or at least I can't think of any
> reason
> why
> > not. Can the same be done with / on Solaris 8?
>
> Sure. unless you need to change passwords. or have log files locally.
> or
> create tmp files or lock files. or maybe write to /etc/mtab (or
> whatever it
> is in solaris). I would reccomend something like argus pitbull rather
> then
> going through the insane hassle of trying to make / read only. plus
> once the
> attacker has root they can remount it.

I'm afraid you are mistaken.

How can you mount / RO, if you have no
/dev and /devices as separate partition? This is not Linux where you
can have devfs.

Am I wrong?

-- 
Vladimir Ivanov                      
System Administrator                 E-Mail:  VIvanov@tee.toshiba.de
Toshiba Electronics Europe GmbH      Tel/Fax: +49-211-5296-297/386



Relevant Pages

  • Re: read-only file systems
    ... Subject: read-only file systems ... On Mon, 10 Sep 2001, Heather Flanagan wrote: ... > particularly hardened systems - or at least I can't think of any reason why ...
    (Focus-SUN)
  • Re: read-only file systems
    ... Subject: read-only file systems ... >particularly hardened systems - or at least I can't think of any reason why ... Sinc eyou can't downgrade a r/w root to a ro root, ... Casper ...
    (Focus-SUN)
  • read-only file systems
    ... Subject: read-only file systems ... particularly hardened systems - or at least I can't think of any reason why ... Can the same be done with / on Solaris 8? ...
    (Focus-SUN)
  • RE: read-only file systems
    ... Subject: read-only file systems ... else in the same partition as root, ... encapsulate the root disk or not. ... (It has to have to consecutive partitions ...
    (Focus-SUN)
  • Re: read-only file systems
    ... Subject: read-only file systems ... > particularly hardened systems - or at least I can't think of any reason ... Can the same be done with / on Solaris 8? ... going through the insane hassle of trying to make / read only. ...
    (Focus-SUN)