Re: Kernel-loadable Root Kits

From: Alexander Langer (alex@big.endian.de)
Date: 09/08/01


Date: Sat, 8 Sep 2001 20:39:35 +0200
From: Alexander Langer <alex@big.endian.de>
To: D J Hawkey Jr <hawkeyd@visi.com>

Thus spake D J Hawkey Jr (hawkeyd@visi.com):

> Ah. Well then, as I wrote to Kris, the kernel has to deny KLD loading
> altogether, it should be a build-time option, and it should have nothing
> to over-ride this.
> Or am I still being too simplistic? I haven't been using KLD- or LKM-

You'd have to remove the whole kld code then, including all
linker_file stuff.

And, given that, you can still use /dev/mem to manipulate the kernel.

Alex

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Kernel-loadable Root Kits
    ... Well then, as I wrote to Kris, the kernel has to deny KLD loading ... >> altogether, it should be a build-time option, and it should have nothing ... > You'd have to remove the whole kld code then, ... > And, given that, you can still use /dev/mem to manipulate the kernel. ...
    (FreeBSD-Security)
  • Re: [PATCH] Make modules work in Linus tree on ARM
    ... > I suspect we should just remove it altogether. ... > feature" things, but I certainly haven't ever used it myself except for ... and it's historically often been broken after various kernel ... send the line "unsubscribe linux-kernel" in ...
    (Linux-Kernel)
  • Re: [PATCH] Make modules work in Linus tree on ARM
    ... > I suspect we should just remove it altogether. ... > feature" things, but I certainly haven't ever used it myself except for ... and it's historically often been broken after various kernel ... send the line "unsubscribe linux-kernel" in ...
    (Linux-Kernel)
  • Re: Kernel-loadable Root Kits
    ... Well then, as I wrote to Kris, the kernel has to deny KLD loading ... > altogether, it should be a build-time option, and it should have nothing ... But it does raise the bar enough to ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: max_scsi_luns under 2.6 kernel
    ... with a 1), and commented out the 4th line, altogether (my reader only has ... On Sun, 15 Aug 2004, Mike Burger wrote: ... > following line, which worked great with a 2.4 kernel, isn't working so hot ...
    (RedHat)

Quantcast