<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Linux 2.6 Kernel Backdoor Attempt Thwarted in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/linux-2-6-kernel-backdoor-attempt-thwarted/m-p/3121200#M74943</link>
    <description>Tks Dave too !&lt;BR /&gt;&lt;BR /&gt;Funny thing is that on irc channels this flaw was discribed as far less elegant as any KLM rootkit, as it was so visible that any kernel guru or any linuxw kid would see it on first release... rootkits still have happy days !&lt;BR /&gt;&lt;BR /&gt;J</description>
    <pubDate>Mon, 17 Nov 2003 15:31:17 GMT</pubDate>
    <dc:creator>Jerome Henry</dc:creator>
    <dc:date>2003-11-17T15:31:17Z</dc:date>
    <item>
      <title>Linux 2.6 Kernel Backdoor Attempt Thwarted</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-2-6-kernel-backdoor-attempt-thwarted/m-p/3121198#M74941</link>
      <description>This is an FYI for anyone that does not read securityfocus.com:&lt;BR /&gt;&lt;BR /&gt;An attempt was made by some unscrupulous character to add a code submission to the kernel source that would allow anyone to gain root access using a combination of flags in the wait4() call. &lt;BR /&gt;&lt;BR /&gt;Heres the link to the full story:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.securityfocus.com/news/7388" target="_blank"&gt;http://www.securityfocus.com/news/7388&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Just thought you guys might want to take a look maybe to give you an idea of the next generation of exploits to hit this industry.&lt;BR /&gt;&lt;BR /&gt;Dave</description>
      <pubDate>Mon, 17 Nov 2003 12:43:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-2-6-kernel-backdoor-attempt-thwarted/m-p/3121198#M74941</guid>
      <dc:creator>Dave Falloon</dc:creator>
      <dc:date>2003-11-17T12:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Linux 2.6 Kernel Backdoor Attempt Thwarted</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-2-6-kernel-backdoor-attempt-thwarted/m-p/3121199#M74942</link>
      <description>thank, Dave&lt;BR /&gt;&lt;BR /&gt;for the "for your info" and a good link !&lt;BR /&gt;&lt;BR /&gt;That should keep-us on or toes !&lt;BR /&gt;&lt;BR /&gt;J-P (0 points for this of course)</description>
      <pubDate>Mon, 17 Nov 2003 13:05:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-2-6-kernel-backdoor-attempt-thwarted/m-p/3121199#M74942</guid>
      <dc:creator>Huc_1</dc:creator>
      <dc:date>2003-11-17T13:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: Linux 2.6 Kernel Backdoor Attempt Thwarted</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-2-6-kernel-backdoor-attempt-thwarted/m-p/3121200#M74943</link>
      <description>Tks Dave too !&lt;BR /&gt;&lt;BR /&gt;Funny thing is that on irc channels this flaw was discribed as far less elegant as any KLM rootkit, as it was so visible that any kernel guru or any linuxw kid would see it on first release... rootkits still have happy days !&lt;BR /&gt;&lt;BR /&gt;J</description>
      <pubDate>Mon, 17 Nov 2003 15:31:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-2-6-kernel-backdoor-attempt-thwarted/m-p/3121200#M74943</guid>
      <dc:creator>Jerome Henry</dc:creator>
      <dc:date>2003-11-17T15:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: Linux 2.6 Kernel Backdoor Attempt Thwarted</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-2-6-kernel-backdoor-attempt-thwarted/m-p/3121201#M74944</link>
      <description>The community of free software users' were quick to identify this security breach due to the unfettered access to the source tree.  Can anyone guess-estimate the number of backdoors `embedded' in `non-free' software ?  Security breaches happen and the free software community did not shy away from full disclosure of `incidents' and saying a big `no' to secrecy.  The next line of security breach would be the total erosion of `individual privacy'!  Computer security is a process where one learns and becomes better by correcting mistakes with full disclosure and thru the massive amount of collaboration thru the medium of the Internet to find `fixes'.</description>
      <pubDate>Mon, 17 Nov 2003 18:41:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-2-6-kernel-backdoor-attempt-thwarted/m-p/3121201#M74944</guid>
      <dc:creator>Ragu_1</dc:creator>
      <dc:date>2003-11-17T18:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: Linux 2.6 Kernel Backdoor Attempt Thwarted</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-2-6-kernel-backdoor-attempt-thwarted/m-p/3121202#M74945</link>
      <description>I think the thing that stuck out in my head about this attempt though was its subtle nature.  Using what looks like a typo to make a  root exploit using a combination of little known flags is pretty cunning.  Its almost too bad this person has given in to the dark side.  They could probably make some very nice contributions to OSS instead of just being a code thug.  &lt;BR /&gt;&lt;BR /&gt;I agree Ragu, open peer review by as many people as possible will keep these flaws from being the door for the next blaster or klez or whatever its going to be.  Another thing that helps is public places to voice concerns.&lt;BR /&gt;&lt;BR /&gt;Dave</description>
      <pubDate>Tue, 18 Nov 2003 00:22:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-2-6-kernel-backdoor-attempt-thwarted/m-p/3121202#M74945</guid>
      <dc:creator>Dave Falloon</dc:creator>
      <dc:date>2003-11-18T00:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: Linux 2.6 Kernel Backdoor Attempt Thwarted</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-2-6-kernel-backdoor-attempt-thwarted/m-p/3121203#M74946</link>
      <description>This backdoor code was found before it could do any damage. and never got into the main stream kernel.&lt;BR /&gt;&lt;BR /&gt;the checks seem to be doing their job, that made this into a non event.</description>
      <pubDate>Tue, 18 Nov 2003 02:06:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-2-6-kernel-backdoor-attempt-thwarted/m-p/3121203#M74946</guid>
      <dc:creator>dirk dierickx</dc:creator>
      <dc:date>2003-11-18T02:06:57Z</dc:date>
    </item>
  </channel>
</rss>

