4 ms·
Honest question: is a strcmp really the best way there is to test for specific kernel modules?
by copper 15y ago
Honest question: is a strcmp really the best way there is to test for specific kernel modules?
- joelthelion 15y agoWhat's wrong with it?
- xentronium 15y agostrcmp (and many other string routines like strlen, strcpy) relies on strings being null terminated. Safe versions (strncmp, strnlen, strncpy) have a parameter for maximum string length. I am pretty sure that in this particular case it is not passed any user input, so it's kinda safe.
- antihero 15y agoWould be a pretty neat exploit to buffer overflow someone's actual kernel via a carefully constructed module name, though.
- 1amzave 15y agoA neat hack, yes...but probably not worthwhile from the perspective of an actual attacker (if you've got permissions to load a kernel module, you could just load one of your own crafting to do whatever nefarious things you wanted directly).
- ori_b 15y agoIf you haven't validated or ensured that your string is a string you've already lost.
- Locke1689 15y agoIn this case it should be fine because the second argument is a string literal (guaranteed to be null-terminated) and the function doesn't continue past the end of the first null-terminated string.
- tadfisher 15y agoSeems reasonable to use strcmp to compare two strings.
- cbs 15y agoGood as any for their use. Follow that the thread on lkml (there is a gmane link in the comments here somewhere) for more discussion on identifying taint-introducing modules.