[syslinux] Don't allow users to append additional kernel cmdline args

Gebhardt Thomas gebhardt at HRZ.Uni-Marburg.DE
Fri Apr 16 00:04:06 PDT 2004


On Thursday 15 April 2004 17:38, Murali Krishnan Ganapathy wrote:

Hi,

> As soon as you allow users to boot off a CD, there is nothing preventing
> them from bringing their own bootable CD, and wreaking havoc. So you
> will not gain any additional security from this feature. The only thing
> you may gain from this feature is to make sure your users will not use
> your CD to hack into your own system.

of course, you are right here. Actually, I am using PXELINUX for booting
Linux on Windows PCs. The BIOS only allows booting by PXE and from
hard disk. So, as far as I can see, allowing the users to append kernel 
cmdline args to the Linux PXE boot image opens a hole.

Cheers, Thomas




More information about the Syslinux mailing list