Re: eavesdrop in dbus policy

Thiago Macieira <[email protected]>
Newsgroups gmane.comp.freedesktop.dbus
Message-ID <1762358.hlS12u8rbm@tjmaciei-mobl4>
On Friday 27 March 2015 09:20:32 Aubert Malek wrote:
> What is different with Become Monitor? I mean, this method will be used by a
> root user too. How does this way avoid security vulnerability?

The security issue was in "root user". If the caller is already root, they can 
ptrace or kill the dbus-daemon. Or any other process, for that matter...
-- 
Thiago Macieira - thiago (AT) macieira.info - thiago (AT) kde.org
   Software Architect - Intel Open Source Technology Center
      PGP/GPG: 0x6EF45358; fingerprint:
      E067 918B B660 DBD1 105C  966C 33F5 F005 6EF4 5358

_______________________________________________
dbus mailing list
[email protected]
http://lists.freedesktop.org/mailman/listinfo/dbus
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.