Re: New release of Solaris secuirity module Papillon
Dave Aitel <[email protected]>
| Newsgroups | gmane.comp.security.sun |
|---|---|
| Organization | Immunity, Inc. |
| Message-ID | <[email protected]> |
Good work, once again. In fact, there are probably many really cool projects that could benefit from being built on your work - for example, a kernel rootkit detection tool... It didn't really detect my 0day local root - or not in a way that it can distinguish between it, and lots of valid popen()s and execves() and other normal activity. You should only warn if the current %PC is on a non .text page, maybe? -dave On 20 Apr 2003 15:26:29 +0200 Konrad Rieck <[email protected]> wrote: > Hello, > > I am sending this mail again to the "Focus Sun" list, because it > returned after one week pending without being accepted or rejected > and I feel that it actually fits the focus of this mailing list. > > With this mail I'd like to announce a new release of my open source > Solaris security module named Papillon. Source and binary packages are > available at > > http://www.roqe.org/papillon >