Re: How to get full pathname from an inode?

From: Omen Wild (Omen.Wildat_private)
Date: Fri Jul 25 2003 - 13:40:04 PDT

  • Next message: Jesse Pollard: "Re: How to get full pathname from an inode?"

    Quoting Jesse Pollard <jesse@cats-chateau.net> on Thu, Jul 24 15:56:
    >
    > If the attacker can do that, then he can just replace the search path 
    > environment variable and accomplish the same thing.
    
    I am not trying to protect against every attack, but a specific type of
    attack.  I guess I'm mostly trying to protect against rootkits and
    Trojans.  Those usually modify critical binaries to cover their tracks. 
    
    If the admin is worried about the search path getting changed, then
    they should protect the files that control the search path against
    tampering (with this module).
    
    Omen
    
    -- 
    T-Shirt saying: Nothing is impossible
    if you don't have to do it yourself.
    
    
    

    _______________________________________________ linux-security-module mailing list linux-security-moduleat_private http://mail.wirex.com/mailman/listinfo/linux-security-module



    This archive was generated by hypermail 2b30 : Fri Jul 25 2003 - 13:40:27 PDT