On my laptop, I have REENABLED module loading! (Which is bad for security):
The LOG!:
r00t@debian:~$
(Oh, this is just a bluff, he busting out the console all just saying and playing and such)
r00t@debian:~$ su
(Oh comon now, you know you ain't going to do shit)
Password:
debian:/home/r00t#
(pfft, he's just fronting)
debian:/home/r00t# cat /etc/X11/xdm/Xsetup
#!/bin/sh
#
# $Id$
#
# This script is run as root before showing login widget.
#xsetroot -solid rgb:8/8/8
Esetroot /usr/share/backgrounds/packeterror.png
/bin/echo 419224 > /proc/sys/fs/file-max
/bin/echo 0 > /proc/sys/net/ipv4/tcp_timestamps
/bin/echo 0 >/proc/sys/net/ipv4/tcp_ecn
/bin/echo > /proc/sys/kernel/core_pattern
/sbin/sysctl -w kernel.grsecurity.disable_modules="1"
/sbin/sysctl -w kernel.grsecurity.grsec_lock="1"
LD_PRELOAD=/lib/libsafe.so.2
export LD_PRELOAD
debian:/home/r00t#
(woah woah, dude comon, don't do that, just leave it the fuck alone!)
debian:/home/r00t# jed /etc/X11/xdm/Xsetup
(no dude, STOP.)
debian:/home/r00t# cat /etc/X11/xdm/Xsetup
#!/bin/sh
#
# $Id$
#
# This script is run as root before showing login widget.
#xsetroot -solid rgb:8/8/8
Esetroot /usr/share/backgrounds/packeterror.png
/bin/echo 419224 > /proc/sys/fs/file-max
/bin/echo 0 > /proc/sys/net/ipv4/tcp_timestamps
/bin/echo 0 >/proc/sys/net/ipv4/tcp_ecn
/bin/echo > /proc/sys/kernel/core_pattern
/sbin/sysctl -w kernel.grsecurity.disable_modules="0"
/sbin/sysctl -w kernel.grsecurity.grsec_lock="1"
LD_PRELOAD=/lib/libsafe.so.2
export LD_PRELOAD
debian:/home/r00t#
(You FUCKING SCUMBAG, WHAT THE FUCK! NOW ANYONE WHO GETS ROOT HAS MEGA PWND YOU YOU FUCKING RETARD MOTHER FUCKER!)
I'm sorry, parentheses, I usually have my laptop booted up for weeks, with the modules disabled I can't use alot of my peripherals. I need module support for USB things (usb keys and usb sound devices) and my pcmcia wireless card.
If it is any consolation, I did not compile in firewire support.
Spender and PaXteam and others: what is your opinion of my actions in this instance? On my server modules are disabled still (no problems there).