I would not feel safe
Posted Apr 16, 2009 22:20 UTC (Thu) by
proski (subscriber, #104)
Parent article:
The details on loading rootkits via /dev/mem
Users of RHEL and other distributions have been safe for some time now.
I would not feel safe if somebody has root access to my system but cannot use /dev/mem to install a rootkit. /dev/mem protections are beyond the last line of defense. To continue the military analogy, it's an officer's pistol. If it has to be used against enemies, things are very bad already.
That's not to say that strict /dev/mem is not worth the trouble. It protects against other things as well, such as buggy local software.
(
Log in to post comments)