public inbox for gentoo-hardened@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-hardened] about the recent ELF kernel bug
@ 2005-05-13 14:09 Pedro Venda
  2005-05-13 14:42 ` [gentoo-security] " Miguel Filipe
                   ` (3 more replies)
  0 siblings, 4 replies; 9+ messages in thread
From: Pedro Venda @ 2005-05-13 14:09 UTC (permalink / raw
  To: gentoo-security, gentoo-hardened

[-- Attachment #1: Type: text/plain, Size: 1108 bytes --]

hi everyone,

Has anyone got a clue on how should the proof of concept code behave on 
vulnerable and not vulnerable machines?

On a PaX+grsecurity hardened server, it outputs:

[+] ./elfcd1 argv_start=0xb47b23d4 argv_end=0xb47b23dc  ESP: 0xb47b1890
[+] phase 1
[+] AAAA argv_start=0xb5e0442e argv_end=0xb5e04432  ESP: 0xb5e03930
[+] phase2, <RET> to crash Killed

and doesn't core-dump. Also it doesn't warn about the segmentation violation 
process in the logs...

On my laptop, a test server and 2 other workstations (standard 2.6.11.5-8 
kernels) results are consistent but different from the hardened server:
pjlv@archon test $ ./elfcd1

[+] ./elfcd1 argv_start=0xbfffeff7 argv_end=0xbfffefff  ESP: 0xbfffedb0
[+] phase 1
[+] AAAA argv_start=0xbfff6fee argv_end=0xbfff6ff2  ESP: 0xbfff6e80
[+] phase 2, <RET> to crash Segmentation fault (core dumped)

and core-dumps.

any help? is the hardened server secure? I suppose so, since it didn't core 
dump. 

regards,
pedro venda.
-- 

Pedro João Lopes Venda
email: pjvenda < at > arrakis.dhis.org
http://arrakis.dhis.org

[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2005-05-15 21:28 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-05-13 14:09 [gentoo-hardened] about the recent ELF kernel bug Pedro Venda
2005-05-13 14:42 ` [gentoo-security] " Miguel Filipe
2005-05-13 16:03 ` [gentoo-hardened] Re: [gentoo-security] " antoine
2005-05-13 14:45   ` Robert Paskowitz
2005-05-13 19:49 ` [gentoo-hardened] " Mike Frysinger
2005-05-13 20:25   ` Aleksander Kamil Modzelewski
2005-05-13 20:37     ` Aleksander Kamil Modzelewski
2005-05-15 15:25 ` Kevin F. Quinn
2005-05-15 21:28   ` Pedro Venda

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox