[Secure-testing-team] Re: kernel allows loadkeys to be used by any user, allowing for local root compromise

Krzysztof Halasa khc at pm.waw.pl
Thu Oct 20 15:05:33 UTC 2005


Rudolf Polzer <debian-ne at durchnull.de> writes:

> We use a PS/2 port, so without a reboot, this would not work. IIRC 2.6
> kernels
> with keyboard support compiled into the kernel cannot be forced to re-detect
> the keyboard when the line was interrupted (which is a big problem with
> old KVM
> switches).

Must have been a different problem, just tried and the keyboard works fine.

But of course one can connect the "dongle" before rebooting. Dead keyboard
can force reboot as well, can't it?

> Of course, with USB keyboards this approach would work.

Would be less trivial.
-- 
Krzysztof Halasa




More information about the Secure-testing-team mailing list