|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: sperl 5.00503 (and newer ;) exploit
From: Solar Designer (solar
FALSE.COM)Date: Mon Aug 07 2000 - 12:49:26 CDT
- Next message: Paul Szabo: "Re: sperl 5.00503 (and newer ;) exploit"
- Previous message: Francis J. Lacoste: "Re: sperl 5.00503 (and newer ;) exploit"
- In reply to: Paul Rogers: "Re: sperl 5.00503 (and newer ;) exploit"
- Next in thread: Simon Cozens: "Re: sperl 5.00503 (and newer ;) exploit"
- Reply: Solar Designer: "Re: sperl 5.00503 (and newer ;) exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Hi,
> ii) RedHat 6.2 kernel 2.2.16 (P2 266 - 64Mb RAM) with OpenWall patches and
> many other security modifications - now running for over 2 hours and still
> no rootshell - load average of around 10.5 but the system is still usable.
Let me guess: you've placed the exploit script in /tmp? You didn't
have to.
> Or - install the OpenWall patches from www.openwall.com if you're running
> Linux - however please note that this theory requires further testing before
> the i's and t's can be dotted and crossed - no flames please. I shall
> continue to play with it and let the lists know the results.
My patch does nothing to prevent or make it harder to exploit this
kind of vulnerabilities. You should never rely on the "hardening"
features of the patch; they are not meant to be a "solution".
> IMHO, a lesson to be learnt regarding these local exploits is to audit local
> users on a regular basis to ensure where possible that only trusted users
> and/or valid accounts exist on a system.
More importantly, the same policy should apply to SUID/SGID files.
Signed,
Solar Designer
- Next message: Paul Szabo: "Re: sperl 5.00503 (and newer ;) exploit"
- Previous message: Francis J. Lacoste: "Re: sperl 5.00503 (and newer ;) exploit"
- In reply to: Paul Rogers: "Re: sperl 5.00503 (and newer ;) exploit"
- Next in thread: Simon Cozens: "Re: sperl 5.00503 (and newer ;) exploit"
- Reply: Solar Designer: "Re: sperl 5.00503 (and newer ;) exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]