1 |
On Sat, 2006-07-15 at 17:45 +0100, Daniel Drake wrote: |
2 |
> Hi, |
3 |
> |
4 |
> The local root exploit-of-the-week would have been unable to run if our |
5 |
> users systems had /proc mounted with nosuid and/or noexec |
6 |
> |
7 |
> It would be worthwhile considering making this a default. What are |
8 |
> people's thoughts? |
9 |
|
10 |
I mailed Mike about this very thing a month ago. Pretty sure it should |
11 |
be showing up in an upcoming baselayout. But yeah it's a good idea for |
12 |
the nosuid part anyway. Not 100% sure about the noexec part as that |
13 |
might break upx which calls /proc/self/exe as part of it's decompresser |
14 |
routines. |
15 |
|
16 |
-- |
17 |
Ned Ludd <solar@g.o> |
18 |
Gentoo Linux |
19 |
|
20 |
-- |
21 |
gentoo-dev@g.o mailing list |