Re: [patch] Add basic sanity checks to the syscall execution patch

From: Ingo Molnar
Date: Sat Sep 06 2008 - 11:46:26 EST



* Willy Tarreau <w@xxxxxx> wrote:

> Then they will simply proceed like this :
> - patch /boot/vmlinuz
> - sync
> - crash system
>
> => user says "oh crap" and presses the reset button. Patched kernel boots.
> Game over. Patching vmlinuz for known targetted distros is even easier
> because the attacker just has to embed binary changes for the most
> common distro kernels.

a reboot often raises attention. But yes, in terms of end user boxes,
probably not. Anyway, my points were about transparent rootkits
installed on a running system without anyone noticing - obviously if the
attacker can modify the kernel image and the user does not mind a reboot
it's game over.

Ingo
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/