RE: Kernel exploit in brk() function.
"Stuart Harris - Chief Systems Engineer Intermedia" <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | Intermedia Network Services Pte Ltd. |
| Message-ID | <001001c3bad5$9f7c26e0$a9fb0050@stuartpiii> |
> The team that created the exploit just released the source, > which is an impressive piece of work, and actually works. I > tested it on Debian 3.0: > > bash-2.05a$ gcc -static hatorihanzo.c > bash-2.05a$ ./a.out > sh-2.05a# id > uid=0(root) gid=0(root) > [stuart@olympus stuart]$ ./a.out [-] Unable to unmap stack: Invalid argument [stuart@olympus stuart]$ However, doesn't on a grsec kernel. (woop, I'm glad I use it now ;P) -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page