From: Xiaotian Feng <xtfeng@gmail.com>
To: wzt wzt <wzt.wzt@gmail.com>
Cc: linux-kernel@vger.kernel.org, mingo@redhat.com, hpa@zytor.com,
x86@kernel.org, zippel@linux-m68k.org
Subject: Re: [PATCH] Kconfig: Make config Filter access to /dev/mem default y
Date: Thu, 15 Apr 2010 14:28:30 +0800 [thread overview]
Message-ID: <q2m7b6bb4a51004142328jf5a16efei859d5cd90f2911d@mail.gmail.com> (raw)
In-Reply-To: <o2w628d1651004142317n438d21e4t359c9661c2c00926@mail.gmail.com>
On Thu, Apr 15, 2010 at 2:17 PM, wzt wzt <wzt.wzt@gmail.com> wrote:
> On Thu, Apr 15, 2010 at 2:12 PM, Xiaotian Feng <xtfeng@gmail.com> wrote:
>> On Tue, Apr 13, 2010 at 10:52 AM, <wzt.wzt@gmail.com> wrote:
>>> Recently, most company start use >=2.6.31 kernels to replace redhat kernels.
>>> But the config "Filter access to /dev/mem" is "default n", that allows kernel
>>> rootkit using /dev/mem again. it could access all kernel memory default. Most
>>> administrator don't known the "Filter access to /dev/mem" is "defult N", when
>>> he compiles the kernel, it's easily to be attacked by rootkit.
>>
>> Have you ever successfully attack by this way?
>
> [root@localhost zealot]# ./zealot
so you're running rootkit as a root user?
> [+] Found HISTSIZE. [SAFE]
> [+] Check md5 values. [SAFE]
> [+] eth0 was not set promsic. [SAFE]
> [+] Not found raw socket. [SAFE]
> system_call addr changed to 0xc04028a0,sys_call_table addr changed to
> 0xc0675130,Found dr rootkit!,system call sys_execve addr changed to
> 0xc0401582,system call sys_olduname addr changed to 0xc0405989,system
> call sys_fork addr changed to 0xc0407bbb
>
> It's a host ids i wrote, it could search all kernel memory using /dev/mem. ok?
>
> some of the code here:
> static void *kmap(unsigned long off, unsigned long count)
> {
> int fd;
> void *p;
>
> fd = open(DEV_MEM, O_RDWR);
> if (fd < 3) {
> DbgPrint("open %s failed.\n", DEV_MEM);
> dup2(fd, 3);
> close(fd);
> fd = 3;
> }
>
> p = mmap(NULL, ALIGNUP(count + 4097), PROT_READ | PROT_WRITE,
> MAP_SHARED, fd, ALIGNDOWN(off) & 0x0fffffff);
> if (p == MAP_FAILED)
> {
> mem_support_flag = 1;
> fprintf(stdout, "[-] /dev/mem cannot be read or write.\n");
>
> DbgPrint("mmap failture, errno %d\n", errno);
> close(fd);
> return NULL;
> }
>
> close(fd);
> return p;
> }
>
>>If CONFIG_STRICT_DEVMEM
>> is not set, the /dev/mem access is filtered in pat code.
> please point it, thanks.
>
Years ago, someone sent the same patch.
check http://lkml.org/lkml/2008/11/7/361
>>>
>>> Signed-off-by: Zhitong Wang <zhitong.wangzt@alibaba-inc.com>
>>>
>>> ---
>>> arch/x86/Kconfig.debug | 3 ++-
>>> arch/x86/configs/i386_defconfig | 2 +-
>>> arch/x86/configs/x86_64_defconfig | 2 +-
>>> 3 files changed, 4 insertions(+), 3 deletions(-)
>>>
>>> diff --git a/arch/x86/Kconfig.debug b/arch/x86/Kconfig.debug
>>> index bc01e3e..733aea6 100644
>>> --- a/arch/x86/Kconfig.debug
>>> +++ b/arch/x86/Kconfig.debug
>>> @@ -7,6 +7,7 @@ source "lib/Kconfig.debug"
>>>
>>> config STRICT_DEVMEM
>>> bool "Filter access to /dev/mem"
>>> + default y
>>> ---help---
>>> If this option is disabled, you allow userspace (root) access to all
>>> of memory, including kernel and userspace memory. Accidental
>>> @@ -20,7 +21,7 @@ config STRICT_DEVMEM
>>> This is sufficient for dosemu and X and all common users of
>>> /dev/mem.
>>>
>>> - If in doubt, say Y.
>>> + If in doubt, say N.
>>>
>>> config X86_VERBOSE_BOOTUP
>>> bool "Enable verbose x86 bootup info messages"
>>> diff --git a/arch/x86/configs/i386_defconfig b/arch/x86/configs/i386_defconfig
>>> index d28fad1..95c85a8 100644
>>> --- a/arch/x86/configs/i386_defconfig
>>> +++ b/arch/x86/configs/i386_defconfig
>>> @@ -2386,7 +2386,7 @@ CONFIG_PROVIDE_OHCI1394_DMA_INIT=y
>>> # CONFIG_SAMPLES is not set
>>> CONFIG_HAVE_ARCH_KGDB=y
>>> # CONFIG_KGDB is not set
>>> -# CONFIG_STRICT_DEVMEM is not set
>>> +CONFIG_STRICT_DEVMEM=y
>>> CONFIG_X86_VERBOSE_BOOTUP=y
>>> CONFIG_EARLY_PRINTK=y
>>> CONFIG_EARLY_PRINTK_DBGP=y
>>> diff --git a/arch/x86/configs/x86_64_defconfig b/arch/x86/configs/x86_64_defconfig
>>> index 6c86acd..659bfe7 100644
>>> --- a/arch/x86/configs/x86_64_defconfig
>>> +++ b/arch/x86/configs/x86_64_defconfig
>>> @@ -2360,7 +2360,7 @@ CONFIG_PROVIDE_OHCI1394_DMA_INIT=y
>>> # CONFIG_SAMPLES is not set
>>> CONFIG_HAVE_ARCH_KGDB=y
>>> # CONFIG_KGDB is not set
>>> -# CONFIG_STRICT_DEVMEM is not set
>>> +CONFIG_STRICT_DEVMEM=y
>>> CONFIG_X86_VERBOSE_BOOTUP=y
>>> CONFIG_EARLY_PRINTK=y
>>> CONFIG_EARLY_PRINTK_DBGP=y
>>> --
>>> 1.6.5.3
>>>
>>> --
>>> To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
>>> the body of a message to majordomo@vger.kernel.org
>>> More majordomo info at http://vger.kernel.org/majordomo-info.html
>>> Please read the FAQ at http://www.tux.org/lkml/
>>>
>>
>
next prev parent reply other threads:[~2010-04-15 6:28 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-04-13 2:52 wzt.wzt
2010-04-15 6:12 ` Xiaotian Feng
2010-04-15 6:17 ` wzt wzt
2010-04-15 6:28 ` Xiaotian Feng [this message]
2010-04-15 6:39 ` wzt wzt
2010-04-15 7:12 ` Xiaotian Feng
2010-04-15 7:37 ` wzt wzt
2010-04-15 6:36 ` Michal Svoboda
2010-04-15 10:43 ` Jiri Kosina
2010-04-15 13:41 ` Michal Svoboda
2010-04-15 13:59 ` Alan Cox
2010-04-15 11:00 ` Alan Cox
2010-04-15 18:03 ` Pavel Machek
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=q2m7b6bb4a51004142328jf5a16efei859d5cd90f2911d@mail.gmail.com \
--to=xtfeng@gmail.com \
--cc=hpa@zytor.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=wzt.wzt@gmail.com \
--cc=x86@kernel.org \
--cc=zippel@linux-m68k.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®