Re: Kernel exploit in brk() function.
Sam Halliday <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
Christophe Devine wrote: > The team that created the exploit just released the source, which is an > impressive piece of work, and actually works. I tested it on Debian 3.0: > > bash-2.05a$ gcc -static hatorihanzo.c > bash-2.05a$ ./a.out > sh-2.05a# id > uid=0(root) gid=0(root) hmm... strangely it fails for me on a 2.4.22 kernel; i thought it was still vulnerable? gcc -static hatorihanzo.c ./a.out [-] Unable to unmap stack: Invalid argument but, it did work on a Redhat 7.2 2.4.20-19.7 kernel. i haven't done anything special to my kernel... its a straight vanilla release. -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iD8DBQE/z+9gh5Q4qVL9G8kRAuNrAJ9q5+8xh35tmb9j/oAZq98gwGXoXQCfWtjk LkS2e3jnTl4lScOGeRMwFWI= =7vG9 -----END PGP SIGNATURE-----