[KLUG Members] Cool security feature.

Bruce Smith members@kalamazoolinux.org
14 Oct 2003 14:34:51 -0400


Looking at the new Fedora beta release notes 
http://fedora.redhat.com/docs/release-notes/
I see the following:

  The Fedora Core 0.94 kernel now makes it possible to prevent 
  the loading of kernel modules. This can be useful for system 
  administrators wanting to ensure that only a strictly-controlled
  set of modules are loaded. To disable kernel module loading, 
  issue the following command:

    echo off > /proc/modules

  Once this command has been issued, all further attempts to load 
  kernel modules will fail.

  NOTE: Once kernel module loading has been disabled, a reboot is 
  required to re-enable it.

Does anyone know how to make this happen on other systems?
Is a kernel patch required?  (if so, where?)

It doesn't work on the latest Redhat 9 kernel, nor does it work
on a stock 2.4.22 kernel.

--------------------------------------------
Bruce Smith                bruce@armintl.com
System Administrator / Network Administrator
Armstrong International, Inc.
Three Rivers, Michigan  49093  USA
http://www.armstrong-intl.com/
--------------------------------------------