Re[2]: gpart destroy, zpool destroy, zfs destroy under securelev

看板FB_current作者時間11年前 (2014/05/29 17:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/2 (看更多)
Hello, > if you have root privileges you can just write some random bytes in some > places and this will be enough to break your system. So, restricting > some gpart's or zpool's actions depending from securelevel looks like > protection from kids. Having root under securelevel 3 confirmed disallows you to: 1) Direct write to the block devices such as (a)da 2) Change rules and/or shutdown pf 3) Remove system flags such as schg, sunlnk I think your statement true in case of securelevel -1, we're talking about the highest one - 3, which shown in logs. _______________________________________________ freebsd-current@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-current To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
文章代碼(AID): #1JXlTEGq (FB_current)
文章代碼(AID): #1JXlTEGq (FB_current)