Re: Kernel modules
Matt Harris <[email protected]>
| Newsgroups | gmane.comp.security.sun |
|---|---|
| Organization | Smithsonian Institution - UNIX Engineering |
| Message-ID | <[email protected]> |
WatchGuard (www.watchguard.com) makes a product (which is an lkm itself) called ServerLock which prevents this sort of thing (touching the kernel at all in a potentially-hazardous way, really) as well as placing additional restrictions on filesystem write accesses. I've used it a bit and it seems to be pretty decent, althought it does not co-exist with Veritas filesystem at all without causing *Major* problems. Hal Flynn wrote: > So, my question is, what are you doing to prevent the loading of kernel > modules? Any clever tricks? Hacks? > > Cheers, > Hal Flynn > Symantec Corp. -- /* * * Matt Harris - Senior UNIX Systems Engineer * Smithsonian Institution, OCIO * */