Re: Kernel exploit in brk() function.

"Mihai (Cop) Moldovanu" <[email protected]>
Newsgroups gmane.linux.lfs.security
Organization Tfm Group
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Friday 05 December 2003 19:31, Billy O'Connor wrote:

> >> Looks like gcc-3.3.1 is somehow stopping the exploit????
> >
> > Same here for gcc 3.2.2 and linux 2.4.21.
>
> Maybe, I can't get the exploit to work even with Sebian Sid.

Try with a statically linked executable compiled with another gcc ....
here:

Linux tfm 2.4.21-xfs #2 SMP Mon Nov 17 12:27:05 EET 2003 i686 unknown
and
bash-2.05a# gcc -v
Reading specs from /usr/lib/gcc-lib/i386-linux/3.2.1/specs
Configured with: ../gcc-3.2.1/configure --prefix=/usr 
- --enable-languages=c,c++,java --enable-shared --host=i386-linux 
- --enable-threads=posix
Thread model: posix
gcc version 3.2.1

And the test results :

su-2.05a$ gcc -o a.out hatorihanzo.c --static
su-2.05a$ ./a.out
sh-2.05a# id
uid=0(root) gid=0(root)
sh-2.05a# exit
su-2.05a$


- ----
TFM Group Romania , Linux division
Mihai Moldovanu ( [email protected]). 
PGP ID: 0x3A8B616A on pgp.mit.edu
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE/0MNw4LnCdzqLYWoRAoUdAJ94ddgPFpHM9OM0GgHvQdRQcs3arACfSgie
3+0ZswRvjF//pWrI9WqTXK8=
=a1sg
-----END PGP SIGNATURE-----

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.