|
|
|||
Vulnerability
I found this on an OSX site and, since OpenBSD is mentioned I thought it may be of interest here.
http://invisiblethingslab.com/resour..._cache_fun.pdf |
|
||||
The PDF refers to (but does not cite) Loic Duflot's SMM abuse analysis from 2006. There was some discussion on misc@ at the time. This from Jonathan Thornburg nets out the consensus: (ref http://marc.info/?l=openbsd-misc&m=114658731227097&w=2)
Quote:
My cursory interpretation -- I could be wrong -- is that the biggest area for concern, or at least awareness, for *nix users on this architecture is the use of XFree86 or X.Org, which exploit SMM. See xf86(4). Last edited by jggimi; 20th March 2009 at 04:55 PM. |
|
|||
This is an SMM related flaw, it isn't OpenBSD specific.. I read a paper recently documenting a use of the xf86(4) aperture driver to do malicious things.
People must realize that they only used OpenBSD as an example, it's due to the way Xorg was designed.. as a user land program, it needs a way of accessing special areas of physical memory. This isn't isn't a problem if machdep.allowaperture is 0, like on a server... or if machdep.allowaperture > 0 and Xorg is running, /dev/xf86 can only be opened once. As I said, this is an x86 architectural problem.. OpenBSD developers have been concerned about SMM for a very long time. Don't run untrusted binaries.. and don't do so as root. |
|
||||
I found an old interview with Duflot whic may be helpful, describing SMM and the X11-based weakness for *nix systems in more detail.
I did not recall the issue clearly, when I wrote above that X uses SMM. It doesn't. SMM uses legacy video RAM memory, and that is where the weakness lies. But I had read this interview 3 years ago, as I remembered the title: http://www.securityfocus.com/columnists/402 BSDfan's Wiki reference has a link in the footnotes to an article describing a demonstration SMM-based rootkit shown at the Black Hat '08 conference. The key to such things is that OS's and their applications do not have access to SMM datablocks, and would be blind to code hidden therein. |
|
|||
I posted the link with academic interest in mind rather than a supposition of an actual concern about vulnerability. Involvement in the BSDs suggests at least a little technical expertise. I actually found it through a Mac OSX forum.
|
Thread Tools | |
Display Modes | |
|
|
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
cannot port upgrade php5-posix, complains about vulnerability | robklg | FreeBSD Installation and Upgrading | 5 | 15th July 2008 09:05 AM |
Swfdec read-only file access vulnerability | corey_james | FreeBSD Ports and Packages | 0 | 14th May 2008 11:31 PM |
WARNING: Vulnerability database out of date, checking anyway | mfaridi | FreeBSD Security | 9 | 8th May 2008 06:13 AM |