Re: ? Unsafe terminal escape sequences and ANSI codes from decryption

Grant Taylor <[email protected]> Mon, 6 Mar 2023 17:21:33 -0700
Newsgroups sci.crypt,alt.security.pgp,alt.bbs,comp.terminals,alt.computer.security
Organization TNet Consulting
Message-ID <[email protected]>
On 3/6/23 3:29 PM, Dennis Boone wrote:
> Actually, one might be able to program an answerback sequence that e.g. 
> contained a hostile command, then triggered the terminal to send 
> said command.  Depending on how the particular model implements screen 
> content send, it might be possible to inject malicious commands via 
> that path too.

Please walk me through this hypothetical scenario.

My main holdup is that I thought configuring the answerback was purely 
client side.  Is there some terminal (emulator) that can be caused to 
alter it's answerback setting via control codes sent to it by the remote 
system?

I would have thought that a local user would maliciously configure their 
terminal (emulator) to send a suspicious answerback if / when prompted.

> There are other forms of objectionable behavior.  In some environments, 
> causing the terminal to make a lot of noise, for example, could be 
> an issue.  Send your real VT100 the sequence "ESC [ 1 4 5 q" in such 
> a place, and the enjoy the panic of figuring out how to stop it.

Especially with buffer on one end and / or the other end.



-- 
Grant. . . .
unix || die