3 ms·
> Once the system reaches normal security level, even root cannot tamper with these logs without rebooting into single-user mode What stops the attacker from j
by comex 1y ago
> Once the system reaches normal security level, even root cannot tamper with these logs without rebooting into single-user mode
What stops the attacker from just editing /etc/rc.securelevel and then doing a normal reboot?
- TacticalCoder 1y ago> What stops the attacker from just editing /etc/rc.securelevel and then doing a normal reboot? Certainly a full reboot leaves more tracks than no full reboot? So it's harder to hide?
- kstrauser 1y agoMake that file immutable so that you can only edit it in single-user mode. This is definitely one of those “security vs convenience” situations where you can easily shoot yourself in the foot, but it’s great to have the option when you need it.
- dgl 1y agoExcept it is sourced from /etc/rc, and that’s a shell script which obviously depends on the shell and some other pieces. If you want an immutable base you kind of need to make the whole (base) system immutable (and that is possibly best designed as such to start with). I don’t think this is “security vs convenience”, I’d more argue it’s possible to think you’ve made this secure but you’ve missed something and haven’t configured it to be as secure as you think. An approach like others have suggested with remote logging is at least easier to reason about.