just a FYI

From: Jeffrey Bouquet <jbtakk_at_iherebuywisely.com>
Date: Wed, 19 Sep 2018 06:28:22 -0700 (PDT)
 /usr/ports/security/lockdown [ sorry if this is a PR or for ports- ]
altered fstab, login.conf and ttys locking me out of my main machine, probably due
to the password hash, but only a daily backup helped me login again and fix the 
damages, with a few files "hardened" maybe but at a cost of uncertainty 
as to whether the net benefit was good/bad once the system is back up, as
it is now.
  It fortunately only took me about an hour.  This would have been much more 
problematic if I had not had 14 years experience in FreeBSD.
  Can someone alter the port to log its actions, create backups, ask permission for
each block of edits it is about to undertake, etc, so someone with critical server data
or less of a backup doesn't suffer the same? Something like a mergemaster would... 
Received on Wed Sep 19 2018 - 11:28:30 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:41:18 UTC