Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 03 Feb 2010 13:33:15 +0100
From:      Jordi Espasa Clofent <jespasac@minibofh.org>
To:        freebsd-stable@freebsd.org
Subject:   Inmutable bit in some binaries
Message-ID:  <4B696D0B.3070301@minibofh.org>

next in thread | raw e-mail | index | archive | help
HI all,

I'm hardening one test box and at present I'm planning to do:

# chflags -R schg <file>

where <file> will be some binaries that seems to be common targets for 
rootkits and lammers:

ls
du
ps
find
top
locate
strings
ifconfig
netstat login

I wonder if changing these files permissions as I've shown above will be 
cause some troubles in future upgrade (recompilation, the classic way, 
not the binary upgrade one) process. żIt will?

-- 
I must not fear. Fear is the mind-killer. Fear is the little-death that 
brings total obliteration. I will face my fear. I will permit it to pass 
over me and through me. And when it has gone past I will turn the inner 
eye to see its path. Where the fear has gone there will be nothing. Only 
I will remain.

Bene Gesserit Litany Against Fear.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4B696D0B.3070301>