[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-disclosure] [Dailydave] What RedHat doesn't want you toknow about ExecShield (without NX)
- To: full-disclosure@xxxxxxxxxxxxxxxxx
- Subject: Re: [Full-disclosure] [Dailydave] What RedHat doesn't want you toknow about ExecShield (without NX)
- From: "gary sweet" <gary.sweet.11@xxxxxxxxx>
- Date: Tue, 15 May 2007 11:36:11 +1000
Brad Spengler wrote:
>>> The problem is there's nothing you can do about my attack,
>> There are likely similar attacks to the NULL ptr issue. Its just a
>> well known/predictable invalid pointer dereference.
> The attack I was referring to was the SELinux disabling, not the kernel
> exploit which allowed
> me to disable SELinux, although it is also since it's highly unlikely that
> PaX's UDEREF will be
> implemented in Fedora/RHEL there will be nothing you can do about the class
> of bugs you
> mention either.
This coming from someone who spends his time 'hunting for Linux kernel
vulnerabilities' .. bravo Brad :rolleyes:
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/