Re: Regarding securelevel startup window

Bryan Drewery <[email protected]>
Newsgroups gmane.os.freebsd.devel.hackers
Message-ID <[email protected]>
On 3/8/26 1:59 PM, Isaac (.ike) Levy wrote:
> Hi All,
>
> I've been re-reading Design and Implementation cover to cover, been a while, this time as part of a project teaching portable shell programming to some wonderful, burgeoning programmers.
>
> I've hit a question regarding, the securelevel startup window:
>
> The system has to boot at securelevel -1 before it can raise. Does anyone know if that window has ever been exploited in the wild?

securelevel is a nice thing but it's like locking your front door. It 
doesn't achieve much against an attacker. The boot issue is a big hole. 
Simply copying a rogue kernel module to /boot/kernel, modifying kld_list 
in rc.conf, rebooting, would load that module before securelevel is set. 
You'd probably never see the file if that happened as it would hide 
itself after boot. Or just replacing some file in there and 
rebooting. Or any other rogue script thrown into /etc/rc.d.  If an 
attacker has root access securelevel does not matter much.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.