Re: Kernel exploit in brk() function.
"Mihai (Cop) Moldovanu" <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | Tfm Group |
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Friday 05 December 2003 19:31, Billy O'Connor wrote: > >> Looks like gcc-3.3.1 is somehow stopping the exploit???? > > > > Same here for gcc 3.2.2 and linux 2.4.21. > > Maybe, I can't get the exploit to work even with Sebian Sid. Try with a statically linked executable compiled with another gcc .... here: Linux tfm 2.4.21-xfs #2 SMP Mon Nov 17 12:27:05 EET 2003 i686 unknown and bash-2.05a# gcc -v Reading specs from /usr/lib/gcc-lib/i386-linux/3.2.1/specs Configured with: ../gcc-3.2.1/configure --prefix=/usr - --enable-languages=c,c++,java --enable-shared --host=i386-linux - --enable-threads=posix Thread model: posix gcc version 3.2.1 And the test results : su-2.05a$ gcc -o a.out hatorihanzo.c --static su-2.05a$ ./a.out sh-2.05a# id uid=0(root) gid=0(root) sh-2.05a# exit su-2.05a$ - ---- TFM Group Romania , Linux division Mihai Moldovanu ( [email protected]). PGP ID: 0x3A8B616A on pgp.mit.edu -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQE/0MNw4LnCdzqLYWoRAoUdAJ94ddgPFpHM9OM0GgHvQdRQcs3arACfSgie 3+0ZswRvjF//pWrI9WqTXK8= =a1sg -----END PGP SIGNATURE----- -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page