mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Peter Read" <peter.read@gmail.com>
To: "Kyle Moffett" <mrmacman_g4@mac.com>
Cc: "Julio Auto" <mindvortex@gmail.com>,
	"Chase Venters" <chase.venters@clientec.com>,
	goodfellas@shellcode.com.ar,
	"Linux kernel" <linux-kernel@vger.kernel.org>,
	endrazine <endrazine@gmail.com>,
	"Stephen Hemminger" <shemminger@osdl.org>,
	Valdis.Kletnieks@vt.edu, "Alan Cox" <alan@lxorguk.ukuu.org.uk>
Subject: Re: Registration Weakness in Linux Kernel's Binary formats
Date: Wed, 4 Oct 2006 08:11:46 +0100	[thread overview]
Message-ID: <73d8d0290610040011v190ea16er8cef746f824819dc@mail.gmail.com> (raw)
In-Reply-To: <1E56E1B6-9C2C-4D84-94D6-42B5A87B5739@mac.com>

I'm thinking of starting a 'security research' firm and pointing out
that if you can physically swap the boot device on a machine and
reboot you can run 'arbitrary code'.

I might also point out the new boot device could have NetBSD on it,
and gloss over the hundreds of other things that would be both
possible and expectedly so...

On 04/10/06, Kyle Moffett <mrmacman_g4@mac.com> wrote:
> On Oct 04, 2006, at 00:08:57, Julio Auto wrote:
> > I sincerely think you're all missing the point here.
>
> No, _you're_ missing the point.
>
> > The observation is in fact something that can be used by rootkit
> > writers or developers of other forms of malware.
>
> This attack relies on being able to load an arbitrary attacker-
> defined kernel module.  Full Stop.  If you can load code into
> privileged mode it's game over regardless of what other designs and
> restrictions are in place.  The "default" security model is that only
> root can load kernel code, but using SELinux or other methods it's
> possible to entirely prevent anything from being loaded after system
> boot or written to the kernel or bootloader images.
>
> If the attacker gains kernel code access, it doesn't matter what
> "simply linked list" or whatever other garbage is being used, they
> can just overwrite the existing ELF loader with their shellcode if
> they want.  Or they could insert a filesystem patch which always
> loads a virus into any ELF binary at load.  Or they could just fork a
> kernel thread and run their shellcode there.  Or they could load a
> copy of Windows from the CD drive and boot into that from Linux.
>
> Kernel-level access implies ultimate trust and security, and
> *nothing* is going to change that.
>
> Cheers,
> Kyle Moffett
>
> -
> To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
> Please read the FAQ at  http://www.tux.org/lkml/
>

  reply	other threads:[~2006-10-04  7:11 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-10-04  4:08 Julio Auto
2006-10-04  4:25 ` Chase Venters
2006-10-04 14:55   ` Alan Cox
2006-10-04 14:34     ` Xavier Bestel
2006-10-04  5:40 ` Kyle Moffett
2006-10-04  7:11   ` Peter Read [this message]
  -- strict thread matches above, loose matches on Subject: below --
2006-10-03 21:25 Fwd: " Bráulio Oliveira
2006-10-03 21:53 ` Kyle Moffett
2006-10-03 21:59   ` Stephen Hemminger
2006-10-03 22:28     ` Valdis.Kletnieks
2006-10-03 19:13 SHELLCODE Security Research
2006-10-03 21:48 ` Chase Venters
2006-10-03 22:54   ` Alan Cox
2006-10-04  3:49 ` Chase Venters

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=73d8d0290610040011v190ea16er8cef746f824819dc@mail.gmail.com \
    --to=peter.read@gmail.com \
    --cc=Valdis.Kletnieks@vt.edu \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=chase.venters@clientec.com \
    --cc=endrazine@gmail.com \
    --cc=goodfellas@shellcode.com.ar \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mindvortex@gmail.com \
    --cc=mrmacman_g4@mac.com \
    --cc=shemminger@osdl.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®