OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: limited functionality accounts (was: Re: History Files)
From: Seth R Arnold (sarnoldWILLAMETTE.EDU)
Date: Sun Apr 16 2000 - 13:10:51 CDT


* Marc Slemko <marcsZNEP.COM> [000416 08:45]:
> Also be wary of special filesystems such as /proc inside the chrooted
> environment. On some systems, /proc may let you escape a chrooted
> environment. On some OSes (don't think Linux lets you, but I don't know
> about that for sure...) /proc lets the user edit memory in programs they
> are running. I don't know if any OS/architecture combinations let you

I believe the answers to this is, "Yes, Linux lets users edit memory" --
the /dev/kmem and /dev/mem devices allow mucking around in memory, and
several linux distributions were shipping with world-writable
permissions on those things. Check bugtraq archives for the exaxt
details.

:)

--
Seth Arnold | http://www.willamette.edu/~sarnold/
Hate spam? See http://maps.vix.com/rbl/ for help