From owner-freebsd-security@FreeBSD.ORG Wed Jul 30 11:36:14 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 4563237B401 for ; Wed, 30 Jul 2003 11:36:14 -0700 (PDT) Received: from cicero0.cybercity.dk (cicero0.cybercity.dk [212.242.40.52]) by mx1.FreeBSD.org (Postfix) with ESMTP id 96F4B43F93 for ; Wed, 30 Jul 2003 11:36:13 -0700 (PDT) (envelope-from db@traceroute.dk) Received: from user1.cybercity.dk (fxp0.user1.ip.cybercity.dk [212.242.41.34]) by cicero0.cybercity.dk (Postfix) with ESMTP id 2602B28ED3 for ; Wed, 30 Jul 2003 20:36:12 +0200 (CEST) Received: from main (port132.ds1-arsy.adsl.cybercity.dk [212.242.239.73]) by user1.cybercity.dk (Postfix) with SMTP id 6A93868B4A for ; Wed, 30 Jul 2003 20:36:11 +0200 (CEST) Date: Wed, 30 Jul 2003 20:45:45 +0200 From: Socketd To: freebsd-security@freebsd.org Message-Id: <20030730204545.0f09adc8.db@traceroute.dk> In-Reply-To: <20030730111512.S16789@fubar.adept.org> References: <20030730015431.4120c648.db@traceroute.dk> <20030730201400.1708d588.db@traceroute.dk> <20030730111512.S16789@fubar.adept.org> X-Mailer: Sylpheed version 0.8.10claws (GTK+ 1.2.10; i386-portbld-freebsd4.8) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Subject: Re: suid bit files + securing FreeBSD (new program: LockDown) X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 30 Jul 2003 18:36:14 -0000 On Wed, 30 Jul 2003 11:18:22 -0700 (PDT) Mike Hoskins wrote: > Just as an aside, this sounds more and more like BastilleBSD. ;) If > that's the direction you're headed, you may want to play with Bastille > on a Linux bax (or vmware session) and see if you get any more > ideas... Something that essentially automates the afore mentioned > checklist would be very similar to Bastille already. (But for BSD, > which I'm sure many would find useful.) > > Good luck, Thanks, I'll look into that :-) br socketd