Great Circle Associates Firewalls
(December 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Linux as a Firewall Platform
From: Ken Hardy <ken @ bridge . com>
Date: Tue, 17 Dec 1996 09:24:31 -0600 (CST)
To: tlewis @ mindspring . com
Cc: firewalls @ greatcircle . com

Todd Graham Lewis <lists @
 reflections .
 mindspring .
 com> wrote:
>If a hacker gains root on your firewall, haven't you, uhh, already lost?

Maybe .. but the fact that even then he cannot modify your logs or run
totally free through the system means:

 1. The damage he can do is not unlimited.  In fact, if he lands root
    (in a chroot'ed jail, especially) in an environment that is really
    restricted with immutable, append-only, no-suid, nodev, &c. types
    of restrictions, he could be very limited in what he could do.
    Especially after your next reboot if he *cannot* change your
    configurations while in multi-user mode.

 2. Assuming he can get root, you'd probably like to know about it.
    Tamper-proof log could mean the difference between a one-time
    incident and an ongoing penetration about which you remain
    blissfully unaware.

--
KH

Indexed By Date Previous: Re: Linux as a Firewall Platform
From: Edwin Kremer <Edwin . Kremer @ cs . ruu . nl>
Next: Re: Linux as a Firewall Platform
From: peter @ baileynm . com (Peter da Silva)
Indexed By Thread Previous: Re: Linux as a Firewall Platform
From: lists @ lina . inka . de (Bernd Eckenfels)
Next: Re: Linux as a Firewall Platform
From: "Jamie Thain" <jthain @ cat . bbsr . edu>

Google
 
Search Internet Search www.greatcircle.com