LWN.net Logo

Making distribution files readable only by root is pointless

Making distribution files readable only by root is pointless

Posted Mar 28, 2013 0:04 UTC (Thu) by nix (subscriber, #2304)
In reply to: Making distribution files readable only by root is pointless by arjan
Parent article: KASLR: An Exercise in Cargo Cult Security (grsecurity blog)

It's zero difference in effort. Effective exploit authors will either be writing attack tools, in which case they *have* to download various distros to customize their attacks for those distros -- they're not going to be looking at files on the target system at all except under automation -- or they'll be targetting it at a particular target, in which case the 'extra' effort spent to customize for the distro the target is used is required anyway, and is drowned in the effort spent on the rest of the targetted attack.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds