Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S261716AbUK2Mkv (ORCPT ); Mon, 29 Nov 2004 07:40:51 -0500 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S261701AbUK2MjG (ORCPT ); Mon, 29 Nov 2004 07:39:06 -0500 Received: from levante.wiggy.net ([195.85.225.139]:24534 "EHLO mx1.wiggy.net") by vger.kernel.org with ESMTP id S261704AbUK2Mgd (ORCPT ); Mon, 29 Nov 2004 07:36:33 -0500 Date: Mon, 29 Nov 2004 13:36:29 +0100 From: Wichert Akkerman To: Jim Nelson Cc: linux-kernel@vger.kernel.org Subject: Re: Question about /dev/mem and /dev/kmem Message-ID: <20041129123629.GP31995@wiggy.net> Mail-Followup-To: Jim Nelson , linux-kernel@vger.kernel.org References: <41AA9E26.4070105@verizon.net> <20041129093937.GN31995@wiggy.net> <41AAFE4E.7010308@verizon.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <41AAFE4E.7010308@verizon.net> User-Agent: Mutt/1.5.6+20040722i X-SA-Exim-Connect-IP: Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 695 Lines: 21 Previously Jim Nelson wrote: > Isn't that /proc/sys/kernel/cap-bound? yes, it is. > And what stops an attacker who's already gained root from doing a "cat "0" > > /proc/sys/kernel/cap-bound" ? The fact that you are not allowed to change the cap-bound settings with that specific bitmask. Wichert. -- Wichert Akkerman It is simple to make things. http://www.wiggy.net/ It is hard to make things simple. - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/