Re: Kernel exploit in brk() function.

Sam Halliday <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
Christophe Devine wrote:
> The team that created the exploit just released the source, which is an
> impressive piece of work, and actually works. I tested it on Debian 3.0:
> 
> bash-2.05a$ gcc -static hatorihanzo.c
> bash-2.05a$ ./a.out
> sh-2.05a# id
> uid=0(root) gid=0(root)

hmm... strangely it fails for me on a 2.4.22 kernel; i thought it was still
vulnerable?

  gcc -static hatorihanzo.c
  ./a.out
  [-] Unable to unmap stack: Invalid argument

but, it did work on a Redhat 7.2 2.4.20-19.7 kernel.

i haven't done anything special to my kernel... its a straight vanilla release.

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQE/z+9gh5Q4qVL9G8kRAuNrAJ9q5+8xh35tmb9j/oAZq98gwGXoXQCfWtjk
LkS2e3jnTl4lScOGeRMwFWI=
=7vG9
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.