$B $B?7$7$$%+!<%M%k$GN)$A>e$2$k(B
$B>e$X(B: LIDS$B$N%$%s%9%H!<%k(B
$BLa$k(B: kernel$B$N%3%s%Q%$%k(B
$B0J2<$N:n6H$O!"(Broot$B$G9T$$$^$9!#(B
$B$^$:!"(B/etc/lids/lids.conf$B$r:n@.$7$F$"$2$^$9!#(B
touch /etc/lids/lids.conf
$B$^$?!":F5/F0;~$K:GDc8BI,MW$J%k!<%k$r@_Dj$7$F$"$2$^$9!#0J2<$N%k!<%k$O(B
http://www.lids/org/lids-faq/LIDS-FAQ.html
$B$r;29M$K!"(BRedHat Linux9$BMQ$K%Q%9$rJQ99$7$?$b$N$G$9!#(B
/sbin/lidsconf -A -o /sbin -j READONLY
/sbin/lidsconf -A -o /bin -j READONLY
/sbin/lidsconf -A -o /usr -j READONLY
/sbin/lidsconf -A -o /lib -j READONLY
/sbin/lidsconf -A -o /etc -j READONLY
/sbin/lidsconf -A -o /usr/local/etc -j READONLY
/sbin/lidsconf -A -o /etc/shadow -j DENY
/sbin/lidsconf -A -o /etc/grub.conf -j DENY
/sbin/lidsconf -A -o /boot/grub/grub.conf -j DENY
/sbin/lidsconf -A -s /bin/login -o /etc/shadow -j READONLY
/sbin/lidsconf -A -s /usr/bin/vlock -o /etc/shadow -j READONLY
/sbin/lidsconf -A -s /bin/su -o /etc/shadow -j READONLY
/sbin/lidsconf -A -s /bin/su -o CAP_SETUID -j GRANT
/sbin/lidsconf -A -s /bin/su -o CAP_SETGID -j GRANT
/sbin/lidsconf -A -o /boot -j READONLY
/sbin/lidsconf -A -o /root -j READONLY
/sbin/lidsconf -A -o /bin/bash -o /root/.bash_history -j READONLY
/sbin/lidsconf -A -o /var/log -j APPEND
/sbin/lidsconf -A -s /bin/login -o /var/log/wtmp -j WRITE
/sbin/lidsconf -A -s /bin/login -o /var/log/lastlog -j WRITE
/sbin/lidsconf -A -s /bin/init -o /var/log/wtmp -j WRITE
/sbin/lidsconf -A -s /bin/init -o /var/log/lastlog -j WRITE
/sbin/lidsconf -A -s /bin/halt -o /var/log/wtmp -j WRITE
/sbin/lidsconf -A -s /bin/halt -o /var/log/lastlog -j WRITE
/sbin/lidsconf -A -s /etc/rc.d/rc.sysint -o /var/log/wtmp -i 1 -j WRITE
/sbin/lidsconf -A -s /etc/rc.d/rc.sysint -o /var/log/lastlog -i 1 -j WRITE
/sbin/lidsconf -A -s /sbin/hwlock -o /etc/adjtime -j WRITE
/sbin/lidsconf -A -s /sbin/init -o CAP_INIT_KILL -j GRANT
/sbin/lidsconf -A -s /sbin/init -o CAP_KILL -j GRANT
/sbin/lidsconf -A -s /etc/rc.d/init.d/halt -o CAP_INIT_KILL -i 1 -j GRANT
/sbin/lidsconf -A -s /etc/rc.d/init.d/halt -o CAP_KILL -i 1 -j GRANT
/sbin/lidsconf -A -s /etc/rc.d/init.d/halt -o CAP_NET_ADMIN -i 1 -j GRANT
/sbin/lidsconf -A -s /etc/rc.d/init.d/halt -o CAP_SYS_ADMIN -i 1 -j GRANT
/sbin/lidsconf -A -s /sbin/update -o CAP_SYS_ADMIN -j GRANT
/sbin/lidsconf -A -o /etc/lids -j DENY
/sbin/lidsconf -A -o /home/omok -j READONLY
/sbin/lidsconf -A -s /bin/init -o /etc/initrunlvl -j APPEND
$B:G8e$K!"@_Dj%U%!%$%k$r99?7$7$F!"H?1G$5$;$^$9!#(B
lidsconf -U
Kazuki Omo
$BJ?@.(B15$BG/(B5$B7n(B16$BF|(B