Story thread · 2 reports / 2 sources

Research into file-notification attacks on Linux

lwn.net · 18h · first report

Sudheendra Raghav Neela, a member of a group of researchers from Graz University of Technology , has announced the release of research into file-notification attacks that would allow spying on user activity on Android, Linux, macOS, and Windows. The group has published a paper with details on the research as well as a web site with demonstrations of the vulnerabilities. On Linux, an attacker can use inotifywatch to monitor a directory to conduct an inter-keystroke timing attack—even if they do not have read access to the files within a directory. The group also discovered a method to conduct a UI-redress attack (or " clickjacking " attack) on KDE 5 and KDE 6 by monitoring /usr/bin/pkexec to detect when Polkit spawns an authentication prompt. An attacker could draw a fake password window on top of the real window to collect a user's credentials. Both of these flaws are still present today, though the Linux kernel did partially mitigate the issue with a fix that was included in the 5.10.

The coverage

  1. Windows, Linux, Android File Notification Systems Leak User Activity

    securityweek.com · 1h

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.