Found, a new rootkit

jdow jdow at earthlink.net
Sat Apr 8 10:07:35 UTC 2006


From: "Tim" <ignored_mailbox at yahoo.com.au>

> On Fri, 2006-04-07 at 14:56 -0500, Mike McCarty wrote:
>> If my MSDOS machine were connected, and someone bombarded the serial
>> port, all that would happen is that the bits would fall on the floor,
>> and the overrun error bit would get set in the UART. With Linux,
>> interrupts would be generated, and the driver would accept the bytes,
>> buffer them, and eventually dump the input. (Unless something has
>> changed since the last time I looked at the Linux serial drivers.)
> 
> Are you saying that unexpected data coming through your COM port
> wouldn't generate IRQ messages (COM ports have an IRQ), which would be
> kicking the CPU quite hard?  That's not exactly a trivial thing to
> ignore.

If you get close enough to my machines to feed high rate data into the
unused serial ports on my machines that is the least of my worries,
Kemo Sabe. You have physical access to my machines. At that point the
only thing that can protect them from a crude level of physical attack
is divine intervention.

{^_^}




More information about the fedora-list mailing list