Re: Question about /dev/mem and /dev/kmem

From: Alan Cox
Date: Mon Nov 29 2004 - 07:56:39 EST


On Llu, 2004-11-29 at 10:47, Jim Nelson wrote:
> And what stops an attacker who's already gained root from doing a "cat "0" >
> /proc/sys/kernel/cap-bound" ?

If they already had root you've already lost.

An SELinux policy would probably be a lot more useful because you also
want to block ioperm/iopl

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/