Re: Kernel exploit in brk() function.

Sam Halliday <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
Christophe Devine wrote:
> Sam Halliday wrote:
> > > bash-2.05a$ gcc -static hatorihanzo.c
> > > bash-2.05a$ ./a.out
> > > sh-2.05a# id
> > > uid=0(root) gid=0(root)
> > hmm... strangely it fails for me on a 2.4.22 kernel; i thought it was still
> > vulnerable?
> > 
> >   gcc -static hatorihanzo.c
> >   ./a.out
> >   [-] Unable to unmap stack: Invalid argument
> > 
> > but, it did work on a Redhat 7.2 2.4.20-19.7 kernel.
> Yeah, some friend of mine noticed that too. It looks like on most
> distros like Debian the exploit works; but it appears to fail when
> compiled with recent versions of gcc/binutils.

aah... ok, it works if i use gcc-2.95.3 (the compiler used to build the kernel).

unfortunately i need to wait for my modem drivers to be updated for 2.4.23
before i can upgrade... :-(

cheers,
Sam
-- 
To win just once against the odds
And once be smiled on by the Gods
To race with speed along the track
Break the tape and not look back
To never have considered losing
As if to win is by your choosing
Bare you soul for all to find
An honest heart and an open mind
   -- Saw Doctors, "To Win Just Once"

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQE/0JYhh5Q4qVL9G8kRAn2bAJ98hzwiRNUPxeskZmc47OHkoYpt6wCcCCWE
C3/pTLV9SDZBwUdohQ/smWw=
=JHk8
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.