Re: udev exploit

Javier J. Martínez Cabezón <[email protected]>
Newsgroups gmane.linux.rsbac
Message-ID <[email protected]>
And filtering LD variables with rsbac¿? :-)

2009/4/27 Jens Kasten <[email protected]>:
> hi list,
>
> last time the udev exploit was published.
> So of course i was looking for, what is the use of rsbac and pax for
> such exploits.
> i follow the this link:
>
> http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2009-04/msg00204.html
>
> then  i call /tmp/udev  ``and given value``
> i get:
> Mon Apr 27 19:43:37 2009 :<6>0000000164|rsbac_adf_request(): request
> CHANGE_OWNER, pid 8796, ppid 8556, prog_name suid, prog_file /tmp/suid,
> uid 1000, target_type PROCESS, tid 8796, attr owner, value 0, result
> NOT_GRANTED by AUTH
>
> Conclusion:
> Auth Module is easy to use with strong protection, should everywhere as
> default. :D
>
> grüsse
> jens
>
>
>
> _______________________________________________
> rsbac mailing list
> [email protected]
> http://www.rsbac.org/mailman/listinfo/rsbac
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.