mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* Why Sysrq+k does not offer a trusted path
@ 2003-09-29  6:53 Oliver Tennert
  2003-09-29  7:20 ` Bernd Eckenfels
  2003-09-29  7:21 ` viro
  0 siblings, 2 replies; 3+ messages in thread
From: Oliver Tennert @ 2003-09-29  6:53 UTC (permalink / raw)
  To: linux-kernel


Hello,

the Sysrq documentation states that the sequence Sysrq + k is not supposed
to constitute a SAK as specified for a C2 system.

Although I do not quite know what excatly in the author's view is missing
for Sysrq + k to really offer a C2 compliant trusted path for logging in,
at least I know of one thing which in a trivial way constitutes a security
leak:

As "/proc/sys/kernel/sysrq" is writable for any privileged process,
writing a "0" into it leads to switching off sys requests altogether. A
malicious program can then do just that and otherwise simulate the
functionality of sys requests its own way. Forging a secure login path is
then a trivial task.

My question is: why not eliminate "/proc/sys/kernel/sysrq" altogether, and
decide at boot time if sysrq functionality is wished or not?

Setting the variable sysrq_enabled at a very early stage of the kernel
setup based on a command line parameter "sysrq" would be a very convenient
way to decide if sys requests are to be enabled, and moreover this
procedure cannot be overridden once the kernel has booted.

Thus it is a more secure way to offer a real SAK.

Or am I missing a very important point?

Best regards

Oliver Tennert

--
________________________________________creating IT solutions

Dr. Oliver Tennert			science + computing ag
phone   +49(0)7071 9457-598		Hagellocher Weg 71-75
fax     +49(0)7071 9457-411		D-72070 Tuebingen, Germany
O.Tennert@science-computing.de		www.science-computing.de




^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2003-09-29  7:23 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2003-09-29  6:53 Why Sysrq+k does not offer a trusted path Oliver Tennert
2003-09-29  7:20 ` Bernd Eckenfels
2003-09-29  7:21 ` viro

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®