Can the output to a terminal be monitored?

Peter da Silva peter at ficc.ferranti.com
Tue Jun 12 23:31:29 AEST 1990


In article <509 at al.ele.tue.nl> raymond at ele.tue.nl (Raymond Nijssen) writes:
> Then, you can run a program acting as a spy. These programs
> are used by crackers, and it's quite easy for them, since /dev/kmem is
> world readable on most unix systems,

I hope not. It's never been on any system I've used.

> for this is necessary for commands
> like ps, which examines lots of kernels buffers also.

cr--r-----   1 sys      sys         2,  1 Feb  6  1989 /dev/kmem
-r-xr-sr-x   1 root     sys         21494 Feb  6  1989 /bin/ps

> Nevertheless, it should still be considered as a security hole, and I 
> wonder if it has been fixed in rel. 4.

It's been fixed in Rel 3, Rel 2, Rel 0, System III, and V7. I'd check on
our Suns, too, but they seem to be making trouble for TCP/IP.
-- 
`-_-' Peter da Silva. +1 713 274 5180.  <peter at ficc.ferranti.com>
 'U`  Have you hugged your wolf today?  <peter at sugar.hackercorp.com>
@FIN  Dirty words: Zhghnyyl erphefvir vayvar shapgvbaf.



More information about the Comp.unix.questions mailing list