Gentoo Archives: gentoo-security

From: Miguel Angel Tormo Alfaro <matormo@××××××.es>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] mount noexec and ro
Date: Mon, 06 Nov 2006 06:05:41
Message-Id: 200611060658.03887.matormo@edicom.es
In Reply to: Re: [gentoo-security] mount noexec and ro by Paul de Vrieze
1 But normally only root can make devices, right?
2
3 El Sábado 04 Noviembre 2006 20:03, Paul de Vrieze escribió:
4 > On Saturday 04 November 2006 17:27, Joe Knall wrote:
5 > > correct, it's atually like this
6 > > /srv/www type ext3 (ro,nosuid,nodev,acl,user_xattr)
7 > > /srv/www/data type ext3 (rw,noexec,nosuid,acl,user_xattr)
8 > >
9 > > but I need a /dev, currently data/dev with null and urandom there,
10 > > writeable and not nodev (could as well be a separate partition).
11 > > Do you think this turns all the rest in vain?
12 >
13 > Nodev is mainly for those situations where you may not have full control over
14 > the disk (like usb sticks). But the ability to have devices will mean that
15 > those who can make devices can abuse them.
16 >
17 > Paul
18 >
19
20 --
21 gentoo-security@g.o mailing list