From 44cc4d5dbc6551d4e0c1204fe971ec48ed6c84b7 Mon Sep 17 00:00:00 2001 From: James Ross-Gowan Date: Sun, 21 May 2017 23:04:17 +1000 Subject: [PATCH] Disable virtual serial port by default It seems dangerous to leave this on. If an unprivileged process can write to serial ports, it could send privileged input (like magic SysRq sequences on Linux or a UAC bypass on Windows) or it could act as a keylogger. --- Output/pjrcUSB/capabilities.kll | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Output/pjrcUSB/capabilities.kll b/Output/pjrcUSB/capabilities.kll index ce3504d97..aef93e80d 100644 --- a/Output/pjrcUSB/capabilities.kll +++ b/Output/pjrcUSB/capabilities.kll @@ -92,7 +92,7 @@ enableKeyboard = 1; # CDC / Serial Port Endpoint enableVirtualSerialPort => enableVirtualSerialPort_define; -enableVirtualSerialPort = 1; +enableVirtualSerialPort = 0; # Raw I/O Endpoint # *Currently Unused*