Re: switching from linux to freebsd



On 01/08/06, Erik Nørgaard <norgaard@xxxxxxxxxxxx> wrote:

If you configure your server using LDAP or NIS for user management then
you only need to mount the root file system rw when updating the base
system or changing root password. Add the MAC and you will likely be
able to protect further against the attack you mention.



Or when you want to patch or install other software, unless you put
/usr/local on its own partition. And put /usr/ports somewhere else. And
don't tinker with anything in /etc/mail. I think we're just going to
disagree on this.

I have never yet seen a situation where mounting the OS disk ro proved to be
useful. I have seen it hinder perfectly normal sysadmin work.

I have seen one instance in 10 years where it would have stopped a silly
mistake (someone moved libc on Solaris). But as that person was doing
something they were supposed to be doing and just made a mistake, they would
have made the same mistake after mounting the disk rw if it had been mounted
ro.

Cheers, Erik


Cheers,
Frem.
_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Sodding Word
    ... Not everyone has it - that's a mistake to assume. ... that it's only available for Macs and Windoze, for starters, and the Mac ... And you get hostile - all because I have trouble understanding some ... paragraph break to convey that useful piece of information. ...
    (uk.comp.sys.mac)
  • Re: How can I recover a (large) file that I have started to COPY over (rather than delete) ?
    ... And thus copying data from disk to disk remains a very dangerous ... "Save" means - in Unix, Linux, OS X, and Windows. ... I made a mistake. ... That doesnt help. ...
    (microsoft.public.windowsxp.general)
  • Re: Sodding Word
    ... shudder). ... Not everyone has it - that's a mistake to assume. ... that it's only available for Macs and Windoze, for starters, and the Mac ... paragraph break to convey that useful piece of information. ...
    (uk.comp.sys.mac)
  • Re: Mac Swap List
    ... isn't that what makes them criminals? ... postings about any Apple product, ... mac things, ... could of just said, "You posted to the group by mistake, try not to ...
    (comp.sys.apple2)
  • Re: iMac plus Virtual PC...?
    ... I made a mistake on the ... I am receiving all my mail in BOTH my PC ... >> and my Mac. ... > clients behaves, so that it doesn't delete the messages on the server. ...
    (comp.sys.mac.advocacy)