Results 1 to 3 of 3

Thread: Security Upgraded Knoppix

  1. #1
    Junior Member
    Join Date
    Sep 2004
    Location
    Beaverton, Oregon, USA
    Posts
    2

    Security Upgraded Knoppix

    There are a number of critical security holes in any pre-September linux code that handles JPEGs and BMPs. That includes Mozilla, gtk+2.0 , gdk-pixbuf , kdelibs , and libpng.
    See http://secunia.com/advisories/12526/ , 12586, 12564, 12311, 12221. These holes have not been exploited as of 28 Sep 2004, but similar holes are being exploited in windoze now, and will certainly be a problem for Linux/Knoppix before Knoppix 3.8 is available.

    I pass out hundreds of Knoppix disks per year, and don't want to pass out exploitable versions of Mozilla and others. I would like to remaster a Knoppix "version 3.6A". I can manage the Mozilla 1.7.3 upgrade, but I am not sure I can get all the libraries right, and if any recompiles are needed, I'm not sure I can find all the applications that are affected.

    Is there anyone skilled and willing to work with me to remaster a more secure version of 3.6?

    Keith Lofstrom (keithl at keithl dot com)

  2. #2
    Member registered user
    Join Date
    Aug 2004
    Location
    Tempe AZ
    Posts
    31
    You bring up a question: why worry about it if the OS is running off a bootable CD? The OS itself can not be corrupted by an external attack.

    For a third party to attack from the internet via this avenue, he would have to guess which version of Knoppix is being run, then how the particular user is storing his or her data on which kind of nonvolatile memory. It seems like an awful lot of work, for what?

  3. #3
    Junior Member
    Join Date
    Sep 2004
    Location
    Beaverton, Oregon, USA
    Posts
    2
    Assume that there will be JPEG exploits for Mozilla 1.7.2 . Thus, by running the browser and inavertently looking at an infected site, you will get rooted, and the remote zombie the exploit talks to can read all necessary configuration information. exec( uname -a ) > mail > zombie , for example. The zombie can then select the appropriate rootkit for that version of Linux, and load quite a lot of executable scripts into whatever is writeable - ramdisk, mountable hard disk, operating kernel, whatever. Your hard disk can be scribbled on, your machine can be zombied, passwords and credit cards sent out, all sorts of mischief can be done.

    Yes, you can return to status quo with a flick of the power switch - but how does the typical windoze user know when to do that? And it is not quite status quo; your information is on the zombie, and the zombie has put information on your hard disk. If it ever gets control again, it has a running start.

    All this can be automated, and there is no protection beyond the read-only nature of the CD, since there is no root password. After the rooting, the CD can be ignored until the next reboot.

    The typical Knoppix user is a Linux newbie, straight from windoze. I am giving them a Knoppix CD so they have an alternative to windoze, and most of them will actually use it a long time from now, when their windoze has become unusable, probably by enemy action. I don't want to compound their problems with something that can allow as much damage as windoze itself.

Similar Threads

  1. upgraded knoppix (on hd) and wireless eth0 turned to wlan0
    By tofergregg in forum General Support
    Replies: 1
    Last Post: 01-09-2005, 06:08 AM
  2. Upgraded Kernel Won't Compile
    By Max in forum Hdd Install / Debian / Apt
    Replies: 1
    Last Post: 03-10-2004, 06:56 PM
  3. upgraded to 2.6.2....now no sound or network
    By theoldmanschild in forum Hdd Install / Debian / Apt
    Replies: 22
    Last Post: 02-24-2004, 10:32 PM
  4. Replies: 2
    Last Post: 01-01-2004, 11:43 PM
  5. Can Ext2 be upgraded after the Knoppix/Debian install?
    By audioaficionado in forum Hdd Install / Debian / Apt
    Replies: 1
    Last Post: 01-26-2003, 08:38 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


Cisco Catalyst C9300-24UX-A 24 Port 10G/mGig Copper UPOE Network Switch picture

Cisco Catalyst C9300-24UX-A 24 Port 10G/mGig Copper UPOE Network Switch

$475.00



Cisco WS-C3560CX-12PC-S 12 Port GbE PoE IP Base Catalyst Managed Switch, TESTED picture

Cisco WS-C3560CX-12PC-S 12 Port GbE PoE IP Base Catalyst Managed Switch, TESTED

$174.00



Cisco Nexus N9K-C92160YC-X 48P 25GbE SFP28 6P QSFP+/QSFP28 PE Switch picture

Cisco Nexus N9K-C92160YC-X 48P 25GbE SFP28 6P QSFP+/QSFP28 PE Switch

$499.00



Cisco Catalyst WS-C2960X-24PD-L GigE PoE 370W, 2 x 10G SFP+, LAN Base H22 picture

Cisco Catalyst WS-C2960X-24PD-L GigE PoE 370W, 2 x 10G SFP+, LAN Base H22

$94.00



🔥🔥🔥 CISCO SFP-10G-SR V03 10-2415-03 850nm 10GBASE-SR SFP+ Multi Module 🔥🔥🔥 picture

🔥🔥🔥 CISCO SFP-10G-SR V03 10-2415-03 850nm 10GBASE-SR SFP+ Multi Module 🔥🔥🔥

$6.80



GENUINE Cisco SFP-10G-SR V03 SFP+ GBIC Transceiver Module 10-2415-03 picture

GENUINE Cisco SFP-10G-SR V03 SFP+ GBIC Transceiver Module 10-2415-03

$6.80



Cisco C3850-NM-2-10G 2 Port Network Exp.Module for 3850 picture

Cisco C3850-NM-2-10G 2 Port Network Exp.Module for 3850

$30.99



Cisco Nexus N3K-C3172PQ-10GE 48P 10GbE 6P QSFP+ Switch N3K-C3172PQ-10GE picture

Cisco Nexus N3K-C3172PQ-10GE 48P 10GbE 6P QSFP+ Switch N3K-C3172PQ-10GE

$189.00



Cisco 2900 Series CISCO2901/K9 v06 Integrated Services Router picture

Cisco 2900 Series CISCO2901/K9 v06 Integrated Services Router

$39.99



Cisco WS-C2960X-48FPD-L 48 V07 POE+ GE+2 10G SFP+, LAN BASE 740W w/ C2960X-Stack picture

Cisco WS-C2960X-48FPD-L 48 V07 POE+ GE+2 10G SFP+, LAN BASE 740W w/ C2960X-Stack

$110.00