Re: Binary only module overview

From: richard offer (offerat_private)
Date: Tue Sep 25 2001 - 07:30:38 PDT

  • Next message: richard offer: "Re: Binary only module overview"

    * frm crispinat_private "09/24/01 17:36:11 -0700" | sed '1,$s/^/* /'
    *
    * richard offer wrote:
    * 
    *> Whats technically to stop me writing a device driver that replaces the
    *> exiting capable() code with my own implementation ? Likewise with
    *> intercepting and replacing system calls ?
    *> 
    * It's an obscurity defense: make it difficult, and therefore unprofitable
    * to do so ;-)
    
    Must resist temptation to put forward old comment about obscurity :-)
    
    * 
    * Crispin
    * 
    
    richard.
    
    -----------------------------------------------------------------------
    Richard Offer                     Technical Lead, Trust Technology, SGI
    "Specialization is for insects"
    _______________________________________________________________________
    
    
    _______________________________________________
    linux-security-module mailing list
    linux-security-moduleat_private
    http://mail.wirex.com/mailman/listinfo/linux-security-module
    



    This archive was generated by hypermail 2b30 : Tue Sep 25 2001 - 07:31:28 PDT