Re: Kernel exploit in brk() function.
Ricardo Barberis <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | Dattatec.com |
| Message-ID | <[email protected]> |
Christophe Devine wrote: > Sam Halliday <[email protected]> wrote: > >> > bash-2.05a$ gcc -static hatorihanzo.c >> > bash-2.05a$ ./a.out >> > sh-2.05a# id >> > uid=0(root) gid=0(root) > >> hmm... strangely it fails for me on a 2.4.22 kernel; i thought it was >> still vulnerable? >> >> gcc -static hatorihanzo.c >> ./a.out >> [-] Unable to unmap stack: Invalid argument >> >> but, it did work on a Redhat 7.2 2.4.20-19.7 kernel. > > Yeah, some friend of mine noticed that too. It looks like on most > distros like Debian the exploit works; but it appears to fail when > compiled with recent versions of gcc/binutils. Just a heads up, the Slackware 9.1 with 2.4.22 I have in my office PC is vulnerable. However, in our servers we have a RH 7.2 with 2.4.18-27.7, a RH 7.3 with 2.4.20-18.7 and another with 2.4.18-27.7.xsmp which are NOT, and we have a RH with a vanilla 2.4.22 compiled by one of our guys and also is NOT vulnerable (I can keep posting about our servers if you want). Now a question, does RH's gcc-2.96 have anything to do about this? Cheers, -- Ricardo Barberis Usuario Linux Nº 250625: http://counter.li.org Usuario LFS Nº 5121: http://www.linuxfromscratch.org LFS en castellano: http://www.lfs-es.org -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page