Re: Kernel exploit in brk() function.

Alberto Ferrer <[email protected]>
Newsgroups gmane.linux.lfs.security
Organization Barra Home
Message-ID <[email protected]>
Hello, this is a report from Redhat servers (Hosting)

[[email protected]:~]$ ssh full.dattafull.com
[email protected]'s password: 
Last login: Thu Dec  4 07:58:33 2003 from host11.200-82-112.telecom.net.ar
adduser albert
root@full [~]# adduser albert
mv debroot@full [~]# mv debian-hatorihanzo.c /home/albert/
croot@full [~]# su - albert
albert@full [~]# ls
./  ../  .bash_logout  .bash_profile  .bashrc  debian-hatorihanzo.c  .emacs  public_ftp/  public_html/
albert@full [~]# gcc -static -o debian-hatorihanzo debian-hatorihanzo.c
albert@full [~]# ls
./  ../  .bash_logout  .bash_profile  .bashrc  debian-hatorihanzo*  debian-hatorihanzo.c  .emacs  public_ftp/  public_html/
albert@full [~]# ./debian-hatorihanzo 
[-] Unable to change page protection: Cannot allocate memory
[-] Unable to exit, entering neverending loop.
                                
[1]+  Stopped                 ./debian-hatorihanzo
albert@full [~]# uname -a       
Linux full.dattafull.com 2.4.20-20.9 #1 Mon Aug 18 11:45:58 EDT 2003 i686 i686 i386 GNU/Linux
albert@full [~]# gcc -v         
Reading specs from /usr/lib/gcc-lib/i386-redhat-linux/3.2.2/specs
Configured with: ../configure --prefix=/usr --mandir=/usr/share/man --infodir=/usr/share/info --enable-shared --enable-threads=posix --disable-checking --with-system-zlib --enable-__cxa_atexit --host=i386-redhat-linux                        
Thread model: posix             
gcc version 3.2.2 20030222 (Red Hat Linux 3.2.2-5)
albert@full [~]# gcc --version  
gcc (GCC) 3.2.2 20030222 (Red Hat Linux 3.2.2-5)
Copyright (C) 2002 Free Software Foundation, Inc.
This is free software; see the source for copying conditions.  There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
                                
albert@full [~]# cat /proc/version 
Linux version 2.4.20-20.9 ([email protected]) (gcc version 3.2.2 20030222 (Red Hat Linux 3.2.2-5)) #1 Mon Aug 18 11:45:58 EDT 2003
albert@full [~]# 

--------------------------
     Alberto Ferrer
  [email protected]
 http://www.barrahome.org
JID: [email protected]
--------------------------
SNMP = Security? Not My Problem!

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.