Great Circle Associates Firewalls
(January 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Rom based os/web server?
From: Sameer R Manek <manek @ challenger . atc . fhda . edu>
Date: Fri, 10 Jan 1997 13:18:32 -0800 (PST)
To: Alexey Zilber <alex @ usanetworks . com>
Cc: firewalls @ GreatCircle . COM
In-reply-to: <2 . 2 . 32 . 19970109161037 . 00bf5620 @ icarus . usanetworks . com>

True a rom based os is a nice thing, but can you ever
change configuration files? upgrade the kernel? or what about
security patches? 

All these will require new card or rom upgrade from the vender
unless they give you some way to do it, possibly a flash rom
in which case someone could hack the box and possibly remotely
burn a backdoor.

IMHO a better way to do things is have the webserver nfs mount
the files from another box, which exports them read only. Then 
have the nfs server locked down, even they penitrate your web server
the files are intact, which means one less thing you have to do
for damage control.

Sameer
--
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Sameer Manek                        manek @
 challenger .
 atc .
 fhda .
 edu
    "A mind once streched by a new idea 
                   never regains its original dimentions"
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-


On Thu, 9 Jan 1997, Alexey Zilber wrote:

> I recieved the previous months copy of The Linux Journal (yes, yes, I know..
> :-) ).  And it talks about a rom based stripped down version of Linux that's
> been created, for systems that cannot use components that could be damaged
> from stress (like hardrives).  This thing is stored, compressed in rom, then
> gets booted and uncompressed into ram.
>         This thing might be good for a hard-coded webserver.  While it could
> get hacked, a reboot and a password change should be all that's needed to
> repair it.
> Alex
> 
> 



References:
Indexed By Date Previous: Newbie Q's & Class 3 Firewalls?
From: John Cross <jcross @ grtk . com>
Next: Re: Rom based os/web server?
From: Scott Averbach <scott @ shell . flinet . com>
Indexed By Thread Previous: Rom based os/web server?
From: Alexey Zilber <alex @ usanetworks . com>
Next: Re: Rom based os/web server?
From: Scott Averbach <scott @ shell . flinet . com>

Google
 
Search Internet Search www.greatcircle.com