[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Protecting root security



On Tue, 18 May 1999, Koyote wrote:

> You can setup a computer that is not bootable from cdrom, and remove
> the floppy drive (install it when you need to do a full
> install.)...(and no, I have no idea how to make the cdrom unbootable
> on a linux pc. I'll learn sooner or later.)

For newer PCs, you can specify in the bios the order devices should be
booted from. So, you could just tell it to always look at
(drive C|hda|primary master) first, and only check the floppy/cdrom if that's
unbootable. Also, you can set a password on bios access (and on
boot sometimes) to keep random people from changing these settings.

Of course, if the little battery fails, or the cracker opens up the case
and removes it for 10 minutes or triggers the proper jumper, or he knows
the manufacturer's bios password, all this is still useless. Although, if
he can get inside the case, he could just as easily walk off with your hd
as reset the bios.


Reply to: