Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Request for discussion.
From: casper () fwi uva nl (Casper Dik)
Date: Wed, 08 Feb 1995 16:24:08 +0100





Not if "Real OS(tm)" == Linux. (which of course has the best procfs money can't
buy).


Which is why Linux procfs has tons of security holes.

Casper


Such as?


Hm, they seem to be fix now.  In early rleases the permissions
of the fd and cd and exec files weren't right.

Now it uses some ugly hack that looks like the modes on the symlink
are 700 (lrwx------)  which only seems to work on the funny symlinks
under /proc.

Hm, it just occured to me that, as root, hijackling connections under Linux
is real simple, you just open the right /proc/pid/fd/<num>

Casper



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]