Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Symlinks and Cryogenic Sleep
From: casper () HOLLAND SUN COM (Casper Dik)
Date: Tue, 4 Jan 2000 21:40:55 +0100


When
the application reaches the critical section of code between the
lstat and the open, you stop it by sending it a SIGSTOP. You record
the device and inode number of your /tmp file, remove it, and wait.

The ploy should fail right here: as far as I'm aware, this protection
only works on sticky directories.  In that case, it's not possible to
remove it.

Maybe I'm just naive, but it's my understanding that you cannot send signals
to a process you don't own unless you are root.

You can, but only from a terminal. (I.e., if you start su/passwd/rsh,
etc, you can ^Z them)

Casper


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]