From: KOSAKI Motohiro <kosaki.motohiro@jp.fujitsu.com>
To: Steve Grubb <sgrubb@redhat.com>
Cc: kosaki.motohiro@jp.fujitsu.com,
Stefani Seibold <stefani@seibold.net>,
Kees Cook <kees.cook@canonical.com>,
linux-kernel@vger.kernel.org,
"Greg Kroah-Hartman" <gregkh@suse.de>,
Andrew Morton <akpm@linux-foundation.org>,
Tejun Heo <tj@kernel.org>, Veaceslav Falico <vfalico@redhat.com>,
Alexander Viro <viro@zeniv.linux.org.uk>,
Oleg Nesterov <oleg@redhat.com>,
Neil Horman <nhorman@tuxdriver.com>,
Roland McGrath <roland@redhat.com>, Ingo Molnar <mingo@elte.hu>,
Peter Zijlstra <a.p.zijlstra@chello.nl>,
Hidetoshi Seto <seto.hidetoshi@jp.fujitsu.com>,
Thomas Gleixner <tglx@linutronix.de>,
Eric Paris <eparis@redhat.com>, James Morris <jmorris@namei.org>,
"Andrew G. Morgan" <morgan@kernel.org>,
Dhaval Giani <dhaval.giani@gmail.com>,
"Serge E. Hallyn" <serue@us.ibm.com>,
Christoph Hellwig <hch@lst.de>,
linux-fsdevel@vger.kernel.org
Subject: Re: [PATCH v2] sanitize task->comm to avoid leaking escape codes
Date: Wed, 30 Jun 2010 09:16:08 +0900 (JST) [thread overview]
Message-ID: <20100630084217.38F2.A69D9226@jp.fujitsu.com> (raw)
In-Reply-To: <201006290858.50387.sgrubb@redhat.com>
> On Monday, June 28, 2010 11:05:56 pm KOSAKI Motohiro wrote:
> > > Am Freitag, den 25.06.2010, 08:56 +0900 schrieb KOSAKI Motohiro:
> > > > > Through get_task_comm() and many direct uses of task->comm in the
> > > > > kernel, it is possible for escape codes and other non-printables to
> > > > > leak into dmesg, syslog, etc. In the worst case, these strings
> > > > > could be used to attack administrators using vulnerable terminal
> > > > > emulators, and at least cause confusion through the injection of \r
> > > > > characters.
> > > > >
> > > > > This patch sanitizes task->comm to only contain printable characters
> > > > > when it is set. Additionally, it redefines get_task_comm so that it
> > > > > is more obvious when misused by callers (presently nothing was
> > > > > incorrectly calling get_task_comm's unsafe use of strncpy).
>
> For the audit system, we want the real, unsanitized task->comm. We record it
> in a special format to the audit logs such that unprintable characters are
> included. We want it exactly this way for certification purposes as well as
> forensic evidence if someone was playing games. If you do sanitize it for
> other areas of the kernel, please give us a way to get the unsanitized text.
Probably this mail is offtopic. I think audit is unrelated with this discusstion. because when
forensic, admins shouldn't believe task->comm at all. because 1) no path information,
perhaps "ls" might mean "/home/attackers-dir/evil-script/ls" 2) easily obscured by
prctl(PR_SET_NAME).
That said, audit have to logged following two point if task name is necessary.
1) exec
2) prctl(PRT_SET_NAME)
Thought ?
next prev parent reply other threads:[~2010-06-30 0:16 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-06-24 19:05 [PATCH v2] sanitize task->comm to avoid leaking escape codes Kees Cook
2010-06-24 23:56 ` KOSAKI Motohiro
2010-06-28 17:48 ` Stefani Seibold
2010-06-28 18:04 ` Kees Cook
2010-06-29 3:05 ` KOSAKI Motohiro
2010-06-29 12:58 ` Steve Grubb
2010-06-30 0:16 ` KOSAKI Motohiro [this message]
2010-06-30 0:22 ` Steve Grubb
2010-06-30 0:28 ` KOSAKI Motohiro
2010-06-29 9:36 ` Alan Cox
2010-06-29 14:51 ` Kees Cook
2010-06-30 9:13 ` Alan Cox
2010-06-30 0:31 ` KOSAKI Motohiro
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20100630084217.38F2.A69D9226@jp.fujitsu.com \
--to=kosaki.motohiro@jp.fujitsu.com \
--cc=a.p.zijlstra@chello.nl \
--cc=akpm@linux-foundation.org \
--cc=dhaval.giani@gmail.com \
--cc=eparis@redhat.com \
--cc=gregkh@suse.de \
--cc=hch@lst.de \
--cc=jmorris@namei.org \
--cc=kees.cook@canonical.com \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@elte.hu \
--cc=morgan@kernel.org \
--cc=nhorman@tuxdriver.com \
--cc=oleg@redhat.com \
--cc=roland@redhat.com \
--cc=serue@us.ibm.com \
--cc=seto.hidetoshi@jp.fujitsu.com \
--cc=sgrubb@redhat.com \
--cc=stefani@seibold.net \
--cc=tglx@linutronix.de \
--cc=tj@kernel.org \
--cc=vfalico@redhat.com \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox