diff options
author | Silvio Rhatto <rhatto@riseup.net> | 2017-10-01 17:21:16 -0300 |
---|---|---|
committer | Silvio Rhatto <rhatto@riseup.net> | 2017-10-01 17:21:16 -0300 |
commit | 07d75df75ada34ef4b7de9cb07770b19251520f1 (patch) | |
tree | a3b814eda00e61afbaf9f778edee4ccaba92741d /firewire.mdwn | |
parent | ef09f1fdae32c8d46b464bb50a85bb69097c211a (diff) | |
download | padrao-07d75df75ada34ef4b7de9cb07770b19251520f1.tar.gz padrao-07d75df75ada34ef4b7de9cb07770b19251520f1.tar.bz2 |
Change markdown extension to .md
Diffstat (limited to 'firewire.mdwn')
-rw-r--r-- | firewire.mdwn | 23 |
1 files changed, 0 insertions, 23 deletions
diff --git a/firewire.mdwn b/firewire.mdwn deleted file mode 100644 index 63ac7f4..0000000 --- a/firewire.mdwn +++ /dev/null @@ -1,23 +0,0 @@ -[[!toc levels=4]] - -Firewire -======== - -Para evitar [dumps de memória via firewire](http://links.sarava.org/tags/firewire), [este artigo](http://www.hermann-uwe.de/blog/physical-memory-attacks-via-firewire-dma-part-1-overview-and-mitigation) oferece a mitigação ideal via `/etc/modprobe.d/blacklist`: - - # Physical memory attacks via Firewire/DMA Mitigation - # Prevent automatic loading of the ohci1394 module. - blacklist ohci1394 - # Prevent manual loading of the ohci1394 module. - install ohci1394 false - # Iff we should ever load the ohci1394 module, force the use of the 'phys_dma=0' option. - options ohci1394 phys_dma=0 - -Depois dessa configuração, é preciso atualizar a `initrd` de cada sistema, através do comando - - update-initramfs -v -u - -Feito isso, o firewire pode ser desabilitado nos sistemas que estão rodando simplesmente com um - - rmmod ohci1394 - |