[114045] in North American Network Operators' Group
one shot remote root for linux?
daemon@ATHENA.MIT.EDU (Gadi Evron)
Tue Apr 28 10:12:17 2009
Date: Tue, 28 Apr 2009 17:10:16 +0300
From: Gadi Evron <ge@linuxbox.org>
To: NANOG <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
This is one of them mysterious and rare cases where a non router OS
vulnerability may affect network operations.
Sometimes news finds us in mysterious yet obvious ways.
HD Moore (respected security researcher) set a status which I noticed on
my twitter:
@hdmoore reading through sctp_houdini.c - one-shot remote linux kernel
root - http://kernelbof.blogspot.com/
I asked him about it on IM, wondering if it is real:
"looks like that
but requires a sctp app to be running"
Naturally, I retweeted.
Signed,
@gadievron