Re: How to login user automatically? (for IP Filter firewall)

From: Martin (nospam_at_example.org)
Date: 09/09/04


Date: Thu, 09 Sep 2004 01:04:51 +0100

Lee Harr wrote:

>> I'm too inexperienced to know more than that I should wonder if I run
>> IP Filter (see http://www.obfuscation.org/ipf/ipf-howto.html ) via
>> rc.local then is it running with root permissions?

The hard-core solution is: set the box up to be dedicated to the task. Set
most of the files on the disk to be Immutable. Run at SecureLevel 3. Very
secure, as you need to take the box into single-user to change anything
(unless you think you can find new exploitable kernel bugs). But all that
makes day-to-day maintenance a bit impractical.

If you start with moderate security and keep learning, you can gradually
reach a compromise where you have good security combined with ease of use.
How you set it up is an engineering compromise between security and
convenience.



Relevant Pages

  • Re: KLD detectors
    ... > of tools out there to bypass the securelevel restriction. ... provides yet another layer of security, use it in tandem with freebsd's ... Most of my machines are remote, ... looking would be /usr/ports/security and around the internet. ...
    (FreeBSD-Security)
  • Re: X & securelevel=3
    ... >> granted access after security is switched on. ... >> one way of doing it seems to be to start it before setting the securelevel, ... the system a bit more with out losing functionality for the users. ...
    (FreeBSD-Security)
  • Re: Kernel-loadable Root Kits < securelevel >
    ... >> securelevel. ... >> process can raise the security level, but no process can lower it. ... If ddb support is compiled into the kernel, then it could be as easy ...
    (FreeBSD-Security)
  • Re: Unable to open /dev/io
    ... > Do you really need to set the secure level to 2? ... the way to securelevel 0; and that is a steep fall. ... I may not run the Pentagon, but I maintain certain security standards. ... that I do not lower the entire server to "Insecure mode" ...
    (freebsd-questions)