Subject: Re: Bugtraq: procfs hole
To: None <tech-security@NetBSD.ORG>
From: Matthias Scheler <tron@lyssa.owl.de>
List: tech-security
Date: 08/15/1997 01:29:09
In article <Pine.NEB.3.96.970814185607.517D-100000@rickb>,
	Rick Byers <rickb@iaw.on.ca> writes:
> So the obvious intermediate fix is to take procfs out of your kernel.

Why? Unmounting "/proc" and removing it from "/etc/ftab" ought to be
enough.

> Obviously, removing mount_procfs won't help much.

To use "mount_procfs" you need root privileges. But if you have root
privileges you don't need any security hole to get them.
-- 
Matthias Scheler                                http://home.owl.de/~tron/