[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[no subject]



> Or, you may be hacked. A clever intruder can insert modules
> into the kernel (which is why a public server shouldn't have
> module load/unload enabled), and can also hide the fact that
> he's done so. A malicious module that simply allocated
> pages as fast as it could would cause the behavior you're
> seeing.

Common misperception, but it actually makes no difference. Even if you
disable module loading / unloading, attackers can still insert LKMs. 
Modern linux rootkits do exactly this....

later,
chris


</pre>
<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->
<hr>
<ul><li><strong>Follow-Ups</strong>:
<ul>
<li><strong><a name="00390" href="msg00390.html">[ale] Memory leak (hacked?)</a></strong>
<ul><li><em>From:</em> dcorbin at machturtle.com (David Corbin)</li></ul></li>
</ul></li></ul>
<!--X-Follow-Ups-End-->
<!--X-References-->
<ul><li><strong>References</strong>:
<ul>
<li><strong><a name="00206" href="msg00206.html">[ale] Memory leak (hacked?)</a></strong>
<ul><li><em>From:</em> dcorbin at machturtle.com (David Corbin)</li></ul></li>
<li><strong><a name="00210" href="msg00210.html">[ale] Memory leak (hacked?)</a></strong>
<ul><li><em>From:</em> esoteric at 3times25.net (Geoffrey)</li></ul></li>
<li><strong><a name="00213" href="msg00213.html">[ale] Memory leak (hacked?)</a></strong>
<ul><li><em>From:</em> dcorbin at machturtle.com (David Corbin)</li></ul></li>
<li><strong><a name="00216" href="msg00216.html">[ale] Memory leak (hacked?)</a></strong>
<ul><li><em>From:</em> esoteric at 3times25.net (Geoffrey)</li></ul></li>
<li><strong><a name="00217" href="msg00217.html">[ale] Memory leak (hacked?)</a></strong>
<ul><li><em>From:</em> dcorbin at machturtle.com (David Corbin)</li></ul></li>
<li><strong><a name="00219" href="msg00219.html">[ale] Memory leak (hacked?)</a></strong>
<ul><li><em>From:</em> jknapka at kneuro.net (Joe Knapka)</li></ul></li>
</ul></li></ul>
<!--X-References-End-->
<!--X-BotPNI-->
<ul>
<li>Prev by Date:
<strong><a href="msg00368.html">[ale] email aliases and wildcards</a></strong>
</li>
<li>Next by Date:
<strong><a href="msg00370.html">[ale] email aliases and wildcards</a></strong>
</li>
<li>Previous by thread:
<strong><a href="msg00219.html">[ale] Memory leak (hacked?)</a></strong>
</li>
<li>Next by thread:
<strong><a href="msg00390.html">[ale] Memory leak (hacked?)</a></strong>
</li>
<li>Index(es):
<ul>
<li><a href="maillist.html#00369"><strong>Date</strong></a></li>
<li><a href="threads.html#00369"><strong>Thread</strong></a></li>
</ul>
</li>
</ul>

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->
</body>
</html>