Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: latest ptrace hole patch?

From: Jeremy Gaddis <jeremy(at)gaddis.org>
Date: Mon Mar 24 2003 - 20:15:45 EST


> -----Original Message-----
> From: SB CH [mailto:chulmin2@hotmail.com]
> Sent: Thursday, March 20, 2003 9:32 PM
> To: focus-linux@securityfocus.com
> Cc: ch@debian.org
> Subject: Re: latest ptrace hole patch?
>
> Hello, list.

I tested the exploited previously posted to bugtraq (km3.c) by anszom@v-lo.krakow.pl against a variety of Linux machines (Slackware 8.0, Red Hat Linux 7.0, multiple Debian 3.0) and each one was exploitable when using the stock kernels.

I applied this same patch to two of my Debian 3.0 machines and recompiled their kernels. Neither appear vulnerable to this exploit now. With the patched kernels, running the above-mentioned exploit simply results in it repeatedly forking.

Unpatched Red Hat Linux 7.0 with stock kernel:

[jeremy@venus:pts/1:~/security]$ ./km3
Linux kmod + ptrace local root exploit by <anszom@v-lo.krakow.pl>

=> Simple mode, executing /usr/bin/id > /dev/tty sizeof(shellcode)=95
=> Child process started.+ 27934
uid=0(root) gid=0(root) groups=1002(jeremy) - 27934 ok!
[jeremy@venus:pts/1:~/security]$

Patched (using above patch) Debian Linux 3.0:

[jeremy@MERCURY:pts/0:~/security]$ ./km3 Linux kmod + ptrace local root exploit by <anszom@v-lo.krakow.pl>

Do you need help?X

=> Simple mode, executing /usr/bin/id > /dev/tty sizeof(shellcode)=95

=> Child process started..........
=> Child process started..........
=> Child process started..........
=> Child process started..........
=> Child process started..........
=> Child process started..........
=> Child process started..........
=> Child process started.          (^C issued at this point)
[jeremy@MERCURY:pts/0:~/security]$

I didn't test any exploit available at www.hack.co.za as I wasn't able to connect to that webserver for an unknown reason.

j.

--
Jeremy L. Gaddis   <
jeremy(at)gaddis.org>   <
http://www.gaddis.org>
Received on Tue Mar 25 14:15:12 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:20 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library