> > Or set the machine up to come back in single user mode after a reboot,
> > which would definitely make it noticeable. You probably only want to do this
> > if you have reliable back-up power though.
>
> That wouldn't work, because the attacker would be able to modify the
> initdefault. Unless of course / is mounted ro, and it's REAL ro (Either
> hardware or with proc modifications suggested earlier).
Didn't think of that. You need to make inittab immutable.
-- Ah, but you're forgetting Rimmer directive 273 which states just as clearly, "No chance you metal bastard!"- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/