OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Here's another glibc env. var.
From: Alan Cox (alanlxorguk.ukuu.org.uk)
Date: Fri May 26 2000 - 17:53:00 CDT


> Let me explain an idea I had recently: whenever execve() is called on a
> s[ug]id binary, the kernel would load and run a specified "wrapper"

Keep the kernel out of it. If you want to do this add yourself an
ld-sanitize.so and make that your elf loader for such apps. No kernel help
needed