[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[stalk:00344] アーガス社のハッキング・コンテストでハッカーが初勝利(上)





  アーガス社のハッキング・コンテストでハッカーが初勝利(上)

<http://www.hotwired.co.jp/news/news/technology/story/20010425301.html>

  だそうです。アーガス社自身も web page で説明しています。

<http://www.argus-systems.com/events/infosec/>

  で、

---- http://www.argus-systems.com/events/infosec/
> The LSD hack was not an exploit of the PitBull software. LSD
> became aware of a vulnerability in Intel x86 operating
> systems through a posting to the NetBSD advisory (that
> vulnerability was not discovered by LSD). LSD was able to use
> that vulnerability to create a kernel level vulnerability in
> the base Solaris x86 operating system that was running on the
> system that Argus had deployed for the hacking challenge. The
> vulnerability exploited by LSD relates specifically to
> operating system implementations supporting the Intel x86
> architecture. In addition to Solaris for x86, the vulnerability
> may affect other operating systems that support the
> Intel x86 architecture. 

  だそうなんですが、これって NetBSD Security Advisory 2001-002
  Vulnerability in x86 USER_LDT validation のことなんですかねえ。
  他にそれっぽいものを思い付かないのですが。

---- http://mail-index.netbsd.org/netbsd-announce/2001/02/16/0000.html
> The problem affects other Operating Systems also:
……
> * Sun Solaris/x86 has the same bug, in a different
>   implementation of a similar mechanism.

----
// 木下是雄「理科系の作文技術」中公新書 624 を読もう!!

小島 肇 - KOJIMA Hajime
[Office] kjm@xxxxxxxxxxxxxxxxxx, http://www.st.ryukoku.ac.jp/~kjm/
         Phone: 077-543-7414  Fax: 077-543-0706
--
- このメイリングリストに関する質問・問い合せ等は
- <security-talk@xxxxxxxxxx>までお知らせください
--
------------------------------------------------------------------------
◆ 「パワーアップ!検索エンジン30万馬力キャンペーン」開催中!(5/2マデ)
        http://www.infoseek.co.jp/ISCamp?svx=971122