Securing the FreeBSD Console by removing OS Version

Gil Agno Virtucio gihl at nesic.com.ph
Mon Sep 15 15:29:05 PDT 2003


Maybe you can edit your /etc/gettytab

default:\
         :cb:ce:ck:lc:fd#1000:im=\r\n\Some Text Here 
\r\n\r\n:sp#1200:\
         :if=/etc/issue:

then you can maybe also use figlet to generate some fancy 
text to your /etc/issue.

You can also disallow users from accessing uname.

hope this helps.


On Mon, 2003-09-15 at 13:48, Kris Kennaway wrote:
> You realise that if someone can log in to the system they can
> trivially discover the OS and OS version by querying the kernel?  As a
> "security measure" this change has zero benefit.
> 

Yes, uname -a will do the trick.  Here is what I wanted. 
 I did not want the version to pop up on the console after 
boot.

So I added the clear command to the /etc/issue.  So, I 
want the console to look like this after the system is up 
and booted:

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

security mumbo jumbo

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

Login:


Ray Seals <rseals at vdsi.net>

____________________________________________________________________
** Get your free E-Mail account at WWW.DIGITELONE.COM **


More information about the freebsd-questions mailing list