[7972] in bugtraq

home help back first fref pref prev next nref lref last post

Re: FreeBSD VM gremlin

daemon@ATHENA.MIT.EDU (Warner Losh)
Fri Sep 18 22:12:21 1998

Date: 	Fri, 18 Sep 1998 13:29:29 -0600
Reply-To: Warner Losh <imp@VILLAGE.ORG>
From: Warner Losh <imp@VILLAGE.ORG>
X-To:         "Charles M. Hannum" <root@ihack.net>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To:  Your message of "Fri, 18 Sep 1998 07:49:18 EDT." 
              <199809181149.HAA21721@lunacity.ne.mediaone.net>

In message <199809181149.HAA21721@lunacity.ne.mediaone.net> "Charles
M. Hannum" writes:
:
: > You should have md5 checksums of files that you are concerned about,
: > as timestamps are useless in the face of a good attacker.
:
: Rubbish!  A checksum doesn't tell me that someone hadn't temporarily
: replaced the file and has now put the original back.

Ummm, you still can't tell that for a competant attacker.  A good
attacker can set the system time, frob the file, set it back let time
pass and then do the same thing to get the original back.  You'd never
know.

It is a bug in the FreeBSD VM system where a page gets marked as
dirty, but the underlying pages are hardware protected against write,
so the same contents are written out.

Warner

home help back first fref pref prev next nref lref last post