[7972] in bugtraq
Re: FreeBSD VM gremlin
daemon@ATHENA.MIT.EDU (Warner Losh)
Fri Sep 18 22:12:21 1998
Date: Fri, 18 Sep 1998 13:29:29 -0600
Reply-To: Warner Losh <imp@VILLAGE.ORG>
From: Warner Losh <imp@VILLAGE.ORG>
X-To: "Charles M. Hannum" <root@ihack.net>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To: Your message of "Fri, 18 Sep 1998 07:49:18 EDT."
<199809181149.HAA21721@lunacity.ne.mediaone.net>
In message <199809181149.HAA21721@lunacity.ne.mediaone.net> "Charles
M. Hannum" writes:
:
: > You should have md5 checksums of files that you are concerned about,
: > as timestamps are useless in the face of a good attacker.
:
: Rubbish! A checksum doesn't tell me that someone hadn't temporarily
: replaced the file and has now put the original back.
Ummm, you still can't tell that for a competant attacker. A good
attacker can set the system time, frob the file, set it back let time
pass and then do the same thing to get the original back. You'd never
know.
It is a bug in the FreeBSD VM system where a page gets marked as
dirty, but the underlying pages are hardware protected against write,
so the same contents are written out.
Warner