[comp.os.vms] Implications of setting the TRACEBACK bit on system security

oberman@LLL-ICDC.ARPA ("Oberman, Kevin") (06/29/87)

A recent info-vax message gave details of how to turn traceback on for an
image linked \NOTRACEBACK. I have found it occasionally handy to do this,
but people should be aware of possible security problems implicit in the
action.

With VMS V4.0 install was modified to REQUIRE images to be linked /NOTRACEBACK
before they could be installed. This is because some clever soul realized
that by running a code which had been installed with privs (esp. CMKRNL)
and then hitting CTRL-Y he could invoke DEBUG and find himself with the
ability to execute (successfully) instructions requiring the elevated
privilege.

Modifying the NOTRACEBACK characteristic of an INSTALLed image would open
this door to your system. That doesn't mean it should never be done, just
that it should be done with care.

					R. Kevin Oberman
					Lawrence Livermore National Laboratory
					arpa: oberman@lll-icdc.arpa
   					(415) 422-6955

Disclaimer: Neither my employer nor myself can take resposibility for the
accuracy of this information. I believe it is correct, but if it's not I can
only say "Sorry". I'm a rotten typist and a worse speller, so forgive any silly
errors.
------