Timothy Bolz wrote:

> I have a question about Demo Linux and possible could be used for
> other distros.  If Demo Linux is runs from CD, it almost makes it
> hack proof is what I'm thinking.

Not necessarily.  If your CD-based distro is running an insecure
version of sendmail, then an attacker can break in.  Once in, they're
in until you reboot.  When you do reboot, the attacker will have to
break in again, but since the system is exactly like it was, it will
be easy to repeat the breakin.  A clever weasel could even automate
the process.

Once in, the attacker can disable or spoof the checksumming mechanism.

Also, be sure you aren't using a CD-R drive! (-:

> I know it would be slow as CD.

Not necessarily.  You can use the CD to initialize and load a disk
based filesystem or even a RAM based filesystem.  The CD would only be
needed at boot time.

-- 
Bob Miller                              K<bob>
kbobsoft software consulting
http://kbobsoft.com                     [EMAIL PROTECTED]

Reply via email to