[114045] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

one shot remote root for linux?

daemon@ATHENA.MIT.EDU (Gadi Evron)
Tue Apr 28 10:12:17 2009

Date: Tue, 28 Apr 2009 17:10:16 +0300
From: Gadi Evron <ge@linuxbox.org>
To: NANOG <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

This is one of them mysterious and rare cases where a non router OS 
vulnerability may affect network operations.

Sometimes news finds us in mysterious yet obvious ways.

HD Moore (respected security researcher) set a status which I noticed on 
my twitter:

@hdmoore reading through sctp_houdini.c - one-shot remote linux kernel
root - http://kernelbof.blogspot.com/

I asked him about it on IM, wondering if it is real:
"looks like that
but requires a sctp app to be running"

Naturally, I retweeted.

Signed,

	@gadievron



home help back first fref pref prev next nref lref last post