Module security [Was: Re: Bootscreen]

Horst von Brand (brand@jupiter.cs.uni-dortmund.de)
Wed, 29 Jan 2003 10:57:52 +0100


Jos Hulzink <josh@stack.nl> said:

[...]

> Oh, and using modules is a (minor) security issue. I have all my drivers
> compiled in the kernel. I like it and it is secure.

There are ways of installing rogue "modules" even without module support.
Google and ye shall find... [One of the online cracker mags had an
extensive article on module/kernel based rootkits some 6-10 months
ago]. And if "someone" gets root, they can leave behind a doctored kernel
any time they want. You'll never notice...

-- 
Dr. Horst H. von Brand                   User #22616 counter.li.org
Departamento de Informatica                     Fono: +56 32 654431
Universidad Tecnica Federico Santa Maria              +56 32 654239
Casilla 110-V, Valparaiso, Chile                Fax:  +56 32 797513
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/