Re: Things to remove from /rescue

From: John-Mark Gurney (gurney_j_at_efn.org)
Date: 07/17/03

  • Next message: Ceri Davies: "Re: Things to remove from /rescue"
    Date: Thu, 17 Jul 2003 01:43:33 -0700
    To: freebsd-arch@freebsd.org
    
    

    David O'Brien wrote this message on Thu, Jul 17, 2003 at 01:08 -0700:
    > - ipfw & natd & ipf & ipfs & ipfstat & ipmon & ipnan, why would one needs
    > these? /rescue is to fix a borked /, not replace PicoBSD.

    ipfw I can see as useful. If you have a kernel that defaults to closed,
    and you need to access the network, then this is a problem. If we had
    a loader tunable to make a closed firewall open, then this wouldn't be
    needed, but then we introduce the fun security hole of /boot/loader.conf
    munging, which is minor... if someone can modify /boot/loader.conf, you
    have bigger fish to fry..

    -- 
      John-Mark Gurney				Voice: +1 415 225 5579
         "All that I will do, has been done, All that I have, has not."
    _______________________________________________
    freebsd-arch@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-arch
    To unsubscribe, send any mail to "freebsd-arch-unsubscribe@freebsd.org"
    

  • Next message: Ceri Davies: "Re: Things to remove from /rescue"

    Relevant Pages

    • Re: Things to remove from /rescue
      ... > ipfw I can see as useful. ... If you have a kernel that defaults to closed, ... > and you need to access the network, ... To unsubscribe, ...
      (freebsd-arch)
    • RE: internet gateway
      ... Your using the ppp nat function which is ok, ... complied the ipfw divert option into your kernel. ... My gateway machine has two network cards, ...
      (freebsd-questions)
    • Re: Things to remove from /rescue
      ... If you have a kernel that defaults to closed, ... > and you need to access the network, ... Just having the rights to issue the ipfw ...
      (freebsd-arch)
    • Re: update 5.0 -> 5.1 problems
      ... > configured and recompiled kernel. ... And after reboot i ... > receive many errors especially connected with network. ... > May it be the problem that binaries like ipfw try to read 'old kernel ...
      (comp.unix.bsd.freebsd.misc)
    • Re: Problems w. Promise SATA300 TX2plus PDC40775
      ... I have a Debian Sarge system with 2.6.8-K7 linux kernel (original kernel from ... Raw IP | Low Level Network Programming ... # ACPI Support ...
      (Debian-User)