User: Password:
|
|
Subscribe / Log in / New account

efficacy of mounting with noexec

efficacy of mounting with noexec

Posted Jul 20, 2006 13:15 UTC (Thu) by sweikart (guest, #4276)
In reply to: The /proc vulnerability by nix
Parent article: The /proc vulnerability

> The latter doesn't work in recent versions of glibc ...

It worked with ld-2.2.5.so (Red Hat Linux 7.3), but not ld-2.3.3.so (Fedora Core 2).

> ... but a determined attacker could build a modified ld.so that
> doesn't check noexec.

Which can be foiled in a chroot jail by mounting writable filing systems noexec.

-scott


(Log in to post comments)


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds