Ineffective as a DRM / other checking component
Posted Mar 29, 2007 11:48 UTC (Thu) by
hummassa (subscriber, #307)
Parent article:
Integrity management in the kernel
Take the following path:
1. inject some code into kernelspace, via known vulnerability;
2. this code makes the kernel present to the TPM (*) the original file to
generate the signature (that will be sent to the network), but execute
another file altogether;
3. ...
4. Profit!!!
:-)
Sorry for the /.-ism, but that's it. This should be kept out of the
kernel, not because of its immorality, but because of its ineffectivity.
(*) funny thing is, in Portuguese, this is the acronym to PMS :-)
(
Log in to post comments)