Subject: Re: Fork bomb protection patch
To: Dave Sainty <>
From: Andrew Brown <>
List: tech-kern
Date: 12/06/2002 09:48:00
>Heh, I was pondering this the other day after the realisation that
>ptrace() could prevent SIGKILL from killing a process.
>I've been thinking that a:
>options NOPTRACE
>... would be a useful option for hardening boxes...

hmm...since ptrace() is for "process tracing and debugging", there
can't be any legitimate uses for it on a...firewall machine, can

|-----< "CODE WARRIOR" >-----|             * "ah!  i see you have the internet (Andrew Brown)                that goes *ping*!"       * "information is power -- share the wealth."