[114057] in North American Network Operators' Group
Re: one shot remote root for linux?
daemon@ATHENA.MIT.EDU (andrew.wallace)
Tue Apr 28 18:31:16 2009
In-Reply-To: <49F70E48.7020702@linuxbox.org>
Date: Tue, 28 Apr 2009 23:31:04 +0100
From: "andrew.wallace" <andrew.wallace@rocketmail.com>
To: Gadi Evron <ge@linuxbox.org>, nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
Why are you alining yourself with a computer hacker? I thought you
were trying to stop these guys releasing exploits in your line of
work?
Andrew
On Tue, Apr 28, 2009 at 3:10 PM, Gadi Evron <ge@linuxbox.org> wrote:
> This is one of them mysterious and rare cases where a non router OS
> vulnerability may affect network operations.
>
> Sometimes news finds us in mysterious yet obvious ways.
>
> HD Moore (respected security researcher) set a status which I noticed on =
my
> twitter:
>
> @hdmoore reading through sctp_houdini.c - one-shot remote linux kernel
> root - http://kernelbof.blogspot.com/
>
> I asked him about it on IM, wondering if it is real:
> "looks like that
> but requires a sctp app to be running"
>
> Naturally, I retweeted.
>
> Signed,
>
> =A0 =A0 =A0 =A0@gadievron
>
>
>