>> You'd probably want more than just setuid files as immutable.  On my
>> system, the following are immutable :
>> [list of file]
>Remember to mark immutable the directories too, or the hacxker can
>still mv the file and install a new one.

bzzt!  nope.  mv-ing the file would require a change to the inode,
which ain't allowed.

of course...they could always move the entire directory...

