mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Krzysztof Halasa <khc@pm.waw.pl>
To: <linux-kernel@vger.kernel.org>
Subject: Re: Linux-2.4.20 modem control
Date: 20 Mar 2003 19:51:56 +0100	[thread overview]
Message-ID: <m3fzphswfn.fsf@defiant.pm.waw.pl> (raw)
In-Reply-To: <Pine.LNX.4.53.0303181404270.27869@chaos>

"Richard B. Johnson" <root@chaos.analogic.com> writes:

> The problem is when you log out! With a terminal connected,
> you get the login prompt again. This is no good if you are
> connected to a modem.

How would that happen? Even assuming the modem doesn't see DTR line
being lowered (for a short time - say, too short) while closing the
device, getty should initialize the modem correctly, i.e. lowering DTR
first for ~1 s.

> The modem will not be disconnected
> and you have to forcably disconnect at the remote end by
> disconnecting the phone line or lowering DTR with your remote
> terminal program. Then the modem will not be ready to
> answer another call. It will remain in a off-line condition
> forever.

Why? Does your modem report on/off-line status using DCD (carrier detect)
line correctly?

The shell should get HUP/disconnect after DCD drops.


BTW: there is (and always was) another issue, security-related.
Normally the user can issue "stty clocal" command which disables DCD
level detection. Thus, the /dev/ttyS* device will be owned by the user
((s)he will have an open file descriptor to the device) after the line
is disconnected. The shell will not be terminated and no getty will be
spawn.

It allows making a script simulating getty/login and ie. collecting
passwords/sessions etc.

This isn't a kernel issue - the kernel has "LOCK TERMIOS" ioctl in place,
and it's probably enough to stop this attack. The problem is no getty
uses that ioctl (it might have changed from the last time I checked,
though - but I would rather check it again if I had untrusted users).
-- 
Krzysztof Halasa
Network Administrator

  parent reply	other threads:[~2003-03-23 22:50 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-03-17 23:07 Ed Vance
2003-03-18  0:33 ` Richard B. Johnson
2003-03-18 18:34   ` Steve Lee
2003-03-18 19:17     ` Richard B. Johnson
2003-03-18 19:34       ` Steve Lee
2003-03-18 20:03         ` Richard B. Johnson
2003-03-20 18:51       ` Krzysztof Halasa [this message]
  -- strict thread matches above, loose matches on Subject: below --
2003-03-21  0:45 Ed Vance
2003-03-21 12:24 ` Richard B. Johnson
2003-03-19 23:50 Ed Vance
2003-03-20  1:18 ` Richard B. Johnson
2003-03-20 22:13   ` Richard B. Johnson
2003-03-19 16:51 Ed Vance
2003-03-19 17:03 ` Richard B. Johnson
2003-03-19 22:32 ` Richard B. Johnson
2003-03-18  0:34 Ed Vance
2003-03-17 20:07 Ed Vance
2003-03-17 21:33 ` Richard B. Johnson
2003-03-17 16:19 Richard B. Johnson
2003-03-17 19:56 ` Jamie Lokier
2003-03-17 21:12   ` Richard B. Johnson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=m3fzphswfn.fsf@defiant.pm.waw.pl \
    --to=khc@pm.waw.pl \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®