[<prev] [next>] [day] [month] [year] [list]
Message-ID: <72daeffd0901231342g4a174794jc50aea715a6762da@mail.gmail.com>
Date: Fri, 23 Jan 2009 13:42:03 -0800
From: Chris Evans <scarybeasts@...il.com>
To: bugtraq@...urityfocus.com, full-disclosure@...ts.grok.org.uk
Subject: Problems with syscall filtering technologies on
Linux
Hi,
There's a trick which may permit the bypassing of policies in
technologies which do syscall filtering on the Linux x86_64 kernel.
The trick is made possible by the fact that the 32-bit and 64-bit
kernel tables are different, combined with the fact that a 64-bit
process can make a 32-bit syscall and visa versa. The syscall "number"
check can get confused and permit a syscall it did not intend to.
Advisory: http://scary.beasts.org/security/CESA-2009-001.html
Blog post: http://scarybeastsecurity.blogspot.com/2009/01/bypassing-syscall-filtering.html
Cheers
Chris
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists