Gentoo Archives: gentoo-dev

From: Josh Saddler <nightmorph@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Making procfs mount as nosuid,noexec by default
Date: Sun, 16 Jul 2006 08:12:27
Message-Id: 44B9F3DD.8000204@gentoo.org
In Reply to: [gentoo-dev] Making procfs mount as nosuid,noexec by default by Daniel Drake
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 Daniel Drake wrote:
5 > Hi,
6 >
7 > The local root exploit-of-the-week would have been unable to run if our
8 > users systems had /proc mounted with nosuid and/or noexec
9 >
10 > It would be worthwhile considering making this a default. What are
11 > people's thoughts?
12 >
13 > Additional testing of this change would be appreciated (just ensure that
14 > nothing breaks). To do it as a one off:
15 >
16 > # mount -o remount,nosuid,noexec /proc
17 >
18 > To make it more permanent, /etc/fstab has:
19 >
20 > proc /proc proc defaults 0 0
21 >
22 > Change to:
23 >
24 > proc /proc proc nosuid,noexec 0 0
25
26 Is there an open bug or security advisory for this exploit I missed? I tried the
27 CLI solution; works just fine here. No wild behavior so far. Any suggestions on
28 what to look for, or how to really hammer /proc? :)
29 -----BEGIN PGP SIGNATURE-----
30 Version: GnuPG v1.4.2.2 (GNU/Linux)
31
32 iD8DBQFEufPcrsJQqN81j74RAjHhAJ9wbrRi/h8b603Ra8W6F5uk0biDVACcCy62
33 WX+lVNRJoJNTLAG2wxg9Mlc=
34 =RVRq
35 -----END PGP SIGNATURE-----
36 --
37 gentoo-dev@g.o mailing list

Replies

Subject Author
Re: [gentoo-dev] Making procfs mount as nosuid,noexec by default Christian Heim <phreak@g.o>