Re: The disappearing sys_call_table export.

Arjan van de Ven (arjanv@redhat.com)
07 May 2003 17:48:40 +0200


This is a MIME-formatted message. If you see this text it means that your
E-mail software does not support MIME-formatted messages.

--=_courier-32009-1052322576-0001-2
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

On Wed, 2003-05-07 at 17:34, petter wahlman wrote:
> It seems like nobody belives that there are any technically valid
> reasons for hooking system calls, but how should e.g anti virus
> on-access scanners intercept syscalls?
> Preloading libraries, ptracing init, patching g/libc, etc. are
> obviously not the way to go.

those obviously need to be implemented via the security subsystem (eg
LSM). Hooks are obviously the wrong level to do things and I could even
tell you that you cannot implement this right from a module actually.

--=_courier-32009-1052322576-0001-2
Content-Type: application/pgp-signature; name="signature.asc"
Content-Transfer-Encoding: 7bit
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQA+uSrYxULwo51rQBIRAgllAJ4hMqz7dEnYVGGuAeKqn2Al4RX+1ACgnnom
kpCZPte2DWDzNUzKNeNSSp0=
=/jiQ
-----END PGP SIGNATURE-----

--=_courier-32009-1052322576-0001-2--