From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752575Ab3LMJXH (ORCPT ); Fri, 13 Dec 2013 04:23:07 -0500 Received: from aserp1040.oracle.com ([141.146.126.69]:23826 "EHLO aserp1040.oracle.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751943Ab3LMJXA (ORCPT ); Fri, 13 Dec 2013 04:23:00 -0500 Message-ID: <52AAD178.6020607@oracle.com> Date: Fri, 13 Dec 2013 10:20:56 +0100 From: Vegard Nossum User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.0 MIME-Version: 1.0 To: Ryan Mallon , Kees Cook , "Theodore Ts'o" , LKML , Tommi Rantala , Ingo Molnar , "Eric W. Biederman" , Andy Lutomirski , Daniel Vetter , Alan Cox , Greg Kroah-Hartman , Jason Wang , "David S. Miller" , Dan Carpenter , James Morris Subject: Re: [PATCH 1/9] Known exploit detection References: <1386867152-24072-1-git-send-email-vegard.nossum@oracle.com> <20131212190659.GG13547@thunk.org> <52AA4BC8.1080207@gmail.com> In-Reply-To: <52AA4BC8.1080207@gmail.com> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Source-IP: acsinet21.oracle.com [141.146.126.237] Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 12/13/2013 12:50 AM, Ryan Mallon wrote: > On 13/12/13 08:13, Kees Cook wrote: >> On Thu, Dec 12, 2013 at 11:06 AM, Theodore Ts'o wrote: >>> On Thu, Dec 12, 2013 at 05:52:24PM +0100, vegard.nossum@oracle.com wrote: >>>> The idea is simple -- since different kernel versions are vulnerable to >>>> different root exploits, hackers most likely try multiple exploits before >>>> they actually succeed. > > The _exploit() notifications could also be used to spam the syslogs. > Although they are individually ratelimited, if there are enough > _exploit() markers in the kernel then an annoying person can cycle > through them all to generate large amounts of useless syslog. They are rate limited collectively, not individually, so this should not be an issue. Vegard