Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfaceforon access scanning

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Arjan van de Ven <arjan@...>
Cc: Press, Jonathan <Jonathan.Press@...>, Peter Dolding <oiaohm@...>, Rik van Riel <riel@...>, Greg KH <greg@...>, <linux-kernel@...>, <linux-security-module@...>
Date: Wednesday, August 6, 2008 - 9:55 am

On Wed, 2008-08-06 at 06:49 -0700, Arjan van de Ven wrote:

Other options involved overwriting LSM function pointers.  I was told
that recently moving SELinux to be statically compiled in apparently
messed them up on that method, at least for RH products.  The other
method I've heard is hunting down all of the filesystem_operations
structs and overwriting those functions.  I was also told that until
recently pages marked RO could just be marked RW and then remarked RO,
although it was recently fixed to RO pages stayed RO.  So yeah, I'd have
to call them all ugly rootkit like hacks.

they just keep finding uglier and uglier ways to infiltrate the kernel
which is why I was ask to try to help get a clean solution.

-Eric

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Sidebar to [malware-list] [RFC 0/5] [TALPA] Intro to a linux..., David Collier-Brown, (Wed Aug 6, 7:40 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfa..., David Collier-Brown, (Mon Aug 11, 12:11 pm)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfa..., Arjan van de Ven, (Wed Aug 13, 10:28 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interf..., David Collier-Brown, (Wed Aug 6, 7:31 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfa..., Eric Paris, (Wed Aug 6, 9:55 am)