OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Peter.HavensLevel3.com
Date: Fri Oct 12 2001 - 14:51:13 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    // -----Original Message-----
    // From: Peter L. Ashford [mailto:ashfordSDSC.EDU]
    // Subject: Announcing Solaris Security Paper
    //
    // Comments and/or suggestions are appreciated.

    Hi,

    At first glance, you're web page looks very useful. However, I noticed one
    thing in skimming through it. Under the section
    http://www.accs.com/p_and_p/SolSec/#Network, the paper states:

            Disk Layout

            This subject has no bearing on security...

    I would disagree with this statement. First of all, you can make a file
    system read-only and/or nosuid, and secondly you can contain file growth
    (perhaps DOS issues are minor). Therefore, your disk layout does have a
    bearing on security. Comments? Did I miss something by just skimming?

    Peter Havens
    Level 3 Communications