Re: Disabling module loading with a module?

Matthew Wilcox (Matthew.Wilcox@genedata.com)
Tue, 17 Aug 1999 17:19:12 +0200


On Tue, Aug 17, 1999 at 03:58:19PM +0200, fvw wrote:
> On Tue, 17 Aug 1999, Matthew Kirkwood wrote:
> > It's even easier than that. 2.2.11 and 2.3.12 onwards have a(n almost)
> > monotonic bounding set for many privileged operations which the kernel
^^^^^^^^^
> > kernel restricts to root (specifically, the new capability stuff).
> I was talking about an already crack box, and echo 0 is as easy as echo 1 :-)

That means that you _can't_ decrease the security, only increase it.

-- 
Matthew Wilcox <willy@bofh.ai>
"Windows and MacOS are products, contrived by engineers in the service of
specific companies. Unix, by contrast, is not so much a product as it is a
painstakingly compiled oral history of the hacker subculture." - N Stephenson

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/