RE: Kernel exploit in brk() function.
"Stuart Harris - Chief Systems Engineer Intermedia" <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | Intermedia Network Services Pte Ltd. |
| Message-ID | <001a01c3bad9$7be34f70$a9fb0050@stuartpiii> |
Guess it wasn't just grsec then ;) > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of IvanK. > Sent: 05 December 2003 02:39 > To: LFS Security Discussion List; Christophe Devine > Subject: Re: Kernel exploit in brk() function. > > > On a plain kernel straight out of kernel.org: > > $ ./a.out > [-] Unable to unmap stack: Invalid argument > $ > > IvanK. > > > On Thursday 04 December 2003 09:01 pm, Christophe Devine wrote: > > Ian Molton <[email protected]> wrote: > > > > Seems this is how the debian servers got rooted last > week. Fixed > > > > in 2.4.23. > > > > > > Impressive. fixed before release of a broken version, then > > > discovered ;-) > > > > The team that created the exploit just released the source, > which is > > an impressive piece of work, and actually works. I tested > it on Debian > > 3.0: > > > > bash-2.05a$ gcc -static hatorihanzo.c > > bash-2.05a$ ./a.out > > sh-2.05a# id > > uid=0(root) gid=0(root) > > > > You can download the code at > > http://www.cr0.net:8040/misc/hatorihanzo.c > > -- > http://linuxfromscratch.org/mailman/listinfo/lfs-security > FAQ: http://www.linuxfromscratch.org/faq/ > Unsubscribe: See the above information page > > -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page