Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1643511
| From | Alan Cox <gnomes@lxorguk.ukuu.org.uk> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN |
| Date | 2017-05-17 18:50 +0200 |
| Message-ID | <tIaj8-5vV-19@gated-at.bofh.it> (permalink) |
| References | (4 earlier) <tHxrr-6b0-9@gated-at.bofh.it> <tHC7L-GS-1@gated-at.bofh.it> <tHGEq-3GY-23@gated-at.bofh.it> <tHJM0-5yL-71@gated-at.bofh.it> <tHLE5-6Kq-7@gated-at.bofh.it> |
| Organization | Intel Corporation |
> If we're adjusting applications, they should be made to avoid TIOSCTI > completely. This looks to me a lot like the symlink restrictions: yes, > userspace should be fixed to the do the right thing, but why not > provide support to userspace to avoid the problem entirely? We do it's called pty/tty. There isn't any other way to do this correctly because TIOCSTI is just one hundreds of things the attacker can do to make your life miserable in the case you create a child process of lower security privilege and give it your tty file handle or worse (like some container crapware) your X11 socket fd. Does it really matter any more or less if I reprogram your enter key, use TIOCSTI, set the baud rate, change all your fonts ? The mainstream tools like sudo get this right (*). Blocking TIOCSTI fixes nothing and breaks apps. If it magically fixed the problem it might make sense but it doesn't. You actually have to get an adult to write the relevant code. Alan (*) Almost. There's an old world trick of sending "+++" "ATE1" "rm -rf *\r\n" to try and attack improperly configured remote modem sessions but the stuff that matters is handled.
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN Matt Brown <matt@nmatt.com> - 2017-05-13 22:00 +0200
Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN Alan Cox <gnomes@lxorguk.ukuu.org.uk> - 2017-05-15 23:00 +0200
Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN Peter Dolding <oiaohm@gmail.com> - 2017-05-16 01:20 +0200
Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN Matt Brown <matt@nmatt.com> - 2017-05-16 06:20 +0200
Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN Peter Dolding <oiaohm@gmail.com> - 2017-05-16 11:10 +0200
Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN Matt Brown <matt@nmatt.com> - 2017-05-16 14:30 +0200
Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN Kees Cook <keescook@chromium.org> - 2017-05-16 16:30 +0200
Re: [kernel-hardening] Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN "Serge E. Hallyn" <serge@hallyn.com> - 2017-05-16 17:50 +0200
Re: [kernel-hardening] Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN Peter Dolding <oiaohm@gmail.com> - 2017-05-17 00:10 +0200
Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN Peter Dolding <oiaohm@gmail.com> - 2017-05-16 23:50 +0200
Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN Matt Brown <matt@nmatt.com> - 2017-05-17 00:00 +0200
Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN Alan Cox <gnomes@lxorguk.ukuu.org.uk> - 2017-05-17 18:50 +0200
Re: [kernel-hardening] Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN Daniel Micay <danielmicay@gmail.com> - 2017-05-17 20:30 +0200
Re: [kernel-hardening] Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN Kees Cook <keescook@chromium.org> - 2017-05-18 05:20 +0200
Re: [kernel-hardening] Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN Peter Dolding <oiaohm@gmail.com> - 2017-05-19 04:50 +0200
Re: [kernel-hardening] Re: [PATCH v6 0/2] security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN "Serge E. Hallyn" <serge@hallyn.com> - 2017-05-19 16:40 +0200
csiph-web