|
From: Tim <t....@co...> - 2004-04-27 20:01:36
|
Roland Pabel wrote: >On Tuesday 27 April 2004 06:14, Tim Tait wrote: >[...] > > >>While I'm on the topic, I think another pontential hole is the linuxrc >>script that discovers the etc.tar.bz2 file on boot... since multiple >>locations are checked, if an unpriveleged user can introduce an >>etc.tar.bz2 file onto a drive that is checked before the real one, then >>they can control the machine on the next reboot. We should check the >>file for "root" ownership and that it is not writeable by anyone else >>before loading it. Of course not being a bash master I'm not sure how to >>write that... >> >> >if you have several users on a system, the most dangerous part is rebooting. >it's the only time a false config could be injected, but even worse: just >pass init=/bin/bash and you have a root shell. So either: don't reboot, or: >always attend your reboots and make sure the right config is loaded. >If you want to disable command line passing, you have to change isolinux.cfg. >When doing that, you can also add a "config=/dev/whatever" and if you protect >that device properly, everything should be fine. >of course, make sure no one swaps CD's and boots a rescue system... >so, IMHO, root ownership may be an additional security check, but it's >inferior to gpg signing (but maybe we should make that part easier...) >Roland > DL supports passing the etc.tar.bz2 file location from boot program? Cool! And is it just isolinux or does Grub and Lilo work too parameter passing from hard disk boots? This would solve a major headache for me - I don't want DL scanning all 7 or 8 disk partitions and floppies, usb etc. I just want to tell it load the one on hda1, or the floppy. I can make grub menu picks for those. Can/does this parameter also get read by save-config? My 2nd big concern is a config be written back to somewhere other than it came from. As Bruce pointed out, the floppy FAT doesn't support ownership attributes, so that may not help. But if I can force the etc.tar.bz2 location from the boot string, which already has a config file that is root only access, then a non priveleged user can not overwrite it so thats even better. Tim |