vlock + magic SysRQ key

From: Luis M. Cruz (lcruzvaat_private)
Date: Wed Aug 04 1999 - 09:16:32 PDT

  • Next message: Henrik Nordstrom: "Re: SGID man"

    --8P1HSweYDcXXzwPJ
    Content-Type: text/plain; charset=iso-8859-1
    Content-Transfer-Encoding: quoted-printable
    
    
      Hi!
    
      Sorry if somebody has noticed this before or is only a stupid remark, but
    a few days ago I found that you can kill vlock (and similar programs that
    lock all linux consoles) with the alt+sysrq+k key combination on LiNUX 2.2.X
    and 2.3.X (if you enabled magic keys when you compiled the kernel) so
    someone could bypass the console locking and althought he cannot access the
    session where vlock was ejecuted (because it has been killed), he can access
    the other posibly opened sessions on other consoles. So, if you have enabled
    the magic keys, using "vlock -a" is not secure!.
    
    --
    Saludos del General...
     _______ _ .-.-. .-. .-.---.---.     ---------  Coordinador de LiMA  ------=
    ---
    (  ____ ) \| | | | | | |    ) _ )    Asociaci=F3n de usuarios de LiNUX de M=
    =E1laga
    | |_   / _ \ | |_| \_/ |   \  _)           http://iaeste.cie.uma.es/lima
    |  _ )/_/ \_\|___)\___/|_|\_\___)    --------------------------------------=
    ---
    | |Correo-E: <luismcat_private>                  LiNUX Reg. User #58=
    539
    |_|Web: http://moon.inf.uji.es/~luismc                  failure en IRC-Hisp=
    ano
       PGP keyID's: 0x6848D470 (DSS) / 0x255E9505 (RSA)
    
    --8P1HSweYDcXXzwPJ
    Content-Type: application/pgp-signature
    
    -----BEGIN PGP SIGNATURE-----
    Version: PGPfreeware 5.0i for non-commercial use
    MessageID: dRNWOCSh5g5loUr07nM8+3/7kofZkPPW
    
    iQA/AwUBN6hnX8ENB1VoSNRwEQJYxACffx+WhNNEaHUsyQIRIE84Ew1rGhEAnAkK
    xdNrqkjepNLN9h2k5Iq1kDp/
    =ApSX
    -----END PGP SIGNATURE-----
    
    --8P1HSweYDcXXzwPJ--
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:55:11 PDT