These classnotes are depreciated. As of 2005, I no longer teach the classes. Notes will remain online for legacy purposes

UNIX03/Booting Read Only

Classnotes | UNIX03 | RecentChanges | Preferences

As we learned in the previous course, most Linux distributions include media that can be booted read-only as a rescue disc. You also can use live-on-CD distributions like Knoppix to boot into a read-only environment to troubleshoot or repair damage done by a cracker.

Remember that you can chroot into your installation and perform maintenance, however always be aware that when chroot-ing you are using the installed system's programs. Thus, if a Trojan is in place, you may wind up doing more damage than good.

Additionally, you can set boot options in LILO or GRUB that allow you to boot your system read-only. Again, you must be wary of trojans (especially trojanned kernel modules) as the danger from unexpectedly compromised files still exists.



Classnotes | UNIX03 | RecentChanges | Preferences
This page is read-only | View other revisions
Last edited June 28, 2003 5:06 am (diff)
Search:
(C) Copyright 2003 Samuel Hart
Creative Commons License
This work is licensed under a Creative Commons License.