Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 12 Jul 2001 15:08:56 -0400
From:      Peter Radcliffe <pir@pir.net>
To:        "'security@FreeBSD.ORG'" <security@FreeBSD.ORG>
Subject:   Re: FreeBSD 4.3 local root PREVENTIONS
Message-ID:  <20010712150856.B22961@pir.net>
In-Reply-To: <6381A6A8826BD31199500090279CAFBA2BD50E@exchange.strategicit.net>; from JPortwood@strategicit.net on Thu, Jul 12, 2001 at 03:08:31PM -0400
References:  <6381A6A8826BD31199500090279CAFBA2BD50E@exchange.strategicit.net>

next in thread | previous in thread | raw e-mail | index | archive | help
"Portwood, Jason" <JPortwood@strategicit.net> probably said:
> Wouldn't it be a better practice to just mount all the partitions that don't
> need suid as nosuid?  Just off the top of my head those candidates would
> be  
> 
> /tmp
> /home
> /var
> 
> Is there a good reason for not doing this?

I've been doing this for some time. I also mount everything but /
nodev.  Doesn't seem to hurt anything I use.

P.

-- 
pir                  pir@pir.net                    pir@net.tufts.edu


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20010712150856.B22961>