Gentoo Archives: gentoo-security

From: Daniel Heemann <daniel.heemann@×××.de>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Built in integrity?
Date: Tue, 10 Feb 2004 17:40:28
Message-Id: 200402101840.08548.daniel.heemann@gmx.de
In Reply to: Re: [gentoo-security] Built in integrity? by Daniel Brandt
1 On Tuesday 10 February 2004 16:36, Daniel Brandt wrote:
2 > > Hmm, let's say the attacker gains access to the machine, the firewall
3 > > blocks all binary transfer (I know uuencode/decode, but lets think the
4 > > attacker is not in the position to transfer executables onto the
5 > > compromised system, perhaps he can't transfer any files) and the
6 > > attacker only needs 10 lines of c-code to exploit the kernel or
7 > > whatever - don't worry about if he can compile the 10 lines or not?
8 > > Perhaps also the system runs on alpha hardware but the attacker only
9 > > has x86 binaries etc..
10 >
11 > Too hypothetic, transfer of a binary file will be possible if there is
12 > two-way communication.
13 Not really, e.g. a lot of dedicated systems' serial consoles are connected
14 to a central server to provide a login possibilty if login via network is
15 not possible. Using such a console does not provide the possibility to
16 transfer binary data, I think.
17
18 > Non x86 hardware is not a problem because of cross compiling.
19 ACK (for Linux - other Unixes may still run on hardware the attacker has no
20 crosscompiler for or the ABI is different).
21
22 Regards
23 Daniel
24
25 --
26 "Those who would give up essential liberty, to purchase a little temporary
27 safety, deserve neither liberty nor safety." - Benjamin Franklin
28
29
30 --
31 gentoo-security@g.o mailing list