Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id ; Thu, 24 Oct 2002 05:41:27 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id ; Thu, 24 Oct 2002 05:41:27 -0400 Received: from mail.hometree.net ([212.34.181.120]:38595 "EHLO mail.hometree.net") by vger.kernel.org with ESMTP id ; Thu, 24 Oct 2002 05:41:26 -0400 To: linux-kernel@vger.kernel.org Path: forge.intermeta.de!not-for-mail From: "Henning P. Schmiedehausen" Newsgroups: hometree.linux.kernel Subject: Re: One for the Security Guru's Date: Thu, 24 Oct 2002 09:47:38 +0000 (UTC) Organization: INTERMETA - Gesellschaft fuer Mehrwertdienste mbH Message-ID: References: <20021023130251.GF25422@rdlg.net> <1035411315.5377.8.camel@god.stev.org> Reply-To: hps@intermeta.de NNTP-Posting-Host: forge.intermeta.de X-Trace: tangens.hometree.net 1035452858 15272 212.34.181.4 (24 Oct 2002 09:47:38 GMT) X-Complaints-To: news@intermeta.de NNTP-Posting-Date: Thu, 24 Oct 2002 09:47:38 +0000 (UTC) X-Copyright: (C) 1996-2002 Henning Schmiedehausen X-No-Archive: yes X-Newsreader: NN version 6.5.1 (NOV) Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1323 Lines: 30 James Stevenson writes: >can read / write disks. Thus you could recompile your own kernel Don't put a compiler on the box. The point is not, to make it impossible to root your box. The point is, to make it a) hard(er) and b) time intensive. a) keeps out the kiddies with the r00t hAx0r kits b) gives a security aware staff (or an IDS or a security watcher) a reaction window. One of the most sucking decisions of mainstream distributions is that they offer to install a development kit on server installs. It seems that people working @ linux vendors either have no clue or simply don't understand the needs of their customers. Sheesh, some even install a full desktop with "[gnome|kde]-games" on a server. What is this? Microsoft Windows " ? Regards Henning -- Dipl.-Inf. (Univ.) Henning P. Schmiedehausen -- Geschaeftsfuehrer INTERMETA - Gesellschaft fuer Mehrwertdienste mbH hps@intermeta.de Am Schwabachgrund 22 Fon.: 09131 / 50654-0 info@intermeta.de D-91054 Buckenhof Fax.: 09131 / 50654-20 - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/