LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-20-2009, 07:13 PM   #1
justmehere
Member
 
Registered: Jul 2005
Distribution: Mandrake 6.1
Posts: 59

Rep: Reputation: 15
How safe and secure is running Linux from a CD


Does anyone know if running Knoppix from a CD is safe in protecting against clickjacking *malicious* scripts ? Any comments would be appreciated.
 
Old 08-20-2009, 07:19 PM   #2
MS3FGX
LQ Guru
 
Registered: Jan 2004
Location: NJ, USA
Distribution: Slackware, Debian
Posts: 5,852

Rep: Reputation: 361Reputation: 361Reputation: 361Reputation: 361
Not particularly, no. When running a live CD, you have a fully functional operating system, albeit one running in temporary space. Anything that could effect an installed Linux distribution could effect a live-variant.

Furthermore, since a live environment can mount your hard disk and get access to your permanent storage, theoretically it would be possible to craft a script that installs itself to your resident OS from the live environment; or at the very least trash your files.

It is also worth mentioning that, by their nature, live CDs are often limited to older software releases. Without the benefit of constant updates that you would have on an installed OS, the risk is actually higher that you would be running exploitable software.
 
Old 08-20-2009, 07:23 PM   #3
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by justmehere View Post
Does anyone know if running Knoppix from a CD is safe in protecting against clickjacking *malicious* scripts ? Any comments would be appreciated.
I concur with MS3FGX. I would just add that something like NoScript will help protect you against clickjacking (among an array of other nasties) on both live and installed systems.

Last edited by win32sux; 08-20-2009 at 07:30 PM.
 
Old 08-21-2009, 10:02 AM   #4
justmehere
Member
 
Registered: Jul 2005
Distribution: Mandrake 6.1
Posts: 59

Original Poster
Rep: Reputation: 15
Thank you both for the replies.
 
Old 08-27-2009, 06:30 PM   #5
mazinoz
Member
 
Registered: Mar 2003
Location: Mansfield Queensland Australia
Distribution: Linux Mint - Tara
Posts: 497

Rep: Reputation: 35
I agree with the above comments and also want to add that as far as I know, Knoppix doesn't even have a firewall preinstalled.

1. You could try making your own more secure live CD
2. Use Knoppix for mounting your hard drive and to do analysis.
3. Don't use it on the internet. I have had the experience of having a hard drive ravaged
when I did this, because I did not realise they can mount a hard drive.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows running Firefox more secure than linux running it? moxieman99 General 14 04-04-2009 10:12 AM
Secure while running Damn Small Linux from within XP?? Adamski960 Linux - Security 4 08-02-2008 02:51 PM
LXer: Is Open Source software safe and secure? LXer Syndicated Linux News 0 05-24-2008 01:00 AM
how safe (secure) is Linux? lumiwa Linux - Security 5 12-04-2007 07:59 AM
setting up a safe and secure server/router Ciccio Linux - Security 3 04-25-2003 10:46 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:55 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration