1 |
Hi there, |
2 |
|
3 |
On 5/13/05, Pedro Venda <pjvenda@××××××××××××.org> wrote: |
4 |
> hi everyone, |
5 |
> |
6 |
> Has anyone got a clue on how should the proof of concept code behave on |
7 |
> vulnerable and not vulnerable machines? |
8 |
> |
9 |
> On a PaX+grsecurity hardened server, it outputs: |
10 |
> |
11 |
> [+] ./elfcd1 argv_start=0xb47b23d4 argv_end=0xb47b23dc ESP: 0xb47b1890 |
12 |
> [+] phase 1 |
13 |
> [+] AAAA argv_start=0xb5e0442e argv_end=0xb5e04432 ESP: 0xb5e03930 |
14 |
> [+] phase2, <RET> to crash Killed |
15 |
> |
16 |
> and doesn't core-dump. Also it doesn't warn about the segmentation violation |
17 |
> process in the logs... |
18 |
> |
19 |
> On my laptop, a test server and 2 other workstations (standard 2.6.11.5-8 |
20 |
> kernels) results are consistent but different from the hardened server: |
21 |
> pjlv@archon test $ ./elfcd1 |
22 |
> |
23 |
> [+] ./elfcd1 argv_start=0xbfffeff7 argv_end=0xbfffefff ESP: 0xbfffedb0 |
24 |
> [+] phase 1 |
25 |
> [+] AAAA argv_start=0xbfff6fee argv_end=0xbfff6ff2 ESP: 0xbfff6e80 |
26 |
> [+] phase 2, <RET> to crash Segmentation fault (core dumped) |
27 |
> |
28 |
> and core-dumps. |
29 |
> |
30 |
> any help? is the hardened server secure? I suppose so, since it didn't core |
31 |
> dump. |
32 |
> |
33 |
|
34 |
>From what I understood, a core dump doesn't meen the POC worked. |
35 |
But I could be wrong... |
36 |
|
37 |
> regards, |
38 |
> pedro venda. |
39 |
> -- |
40 |
> |
41 |
> Pedro João Lopes Venda |
42 |
> email: pjvenda < at > arrakis.dhis.org |
43 |
> http://arrakis.dhis.org |
44 |
> |
45 |
> |
46 |
> |
47 |
|
48 |
best regards, e abraços pa ti pj! :-p |
49 |
|
50 |
|
51 |
|
52 |
-- |
53 |
Miguel Sousa Filipe |
54 |
|
55 |
-- |
56 |
gentoo-security@g.o mailing list |
57 |
|
58 |
-- |
59 |
gentoo-hardened@g.o mailing list |