|
|
Subscribe / Log in / New account

Linux Local Privilege Escalation via SUID /proc/pid/mem Write (zx2c4)

Linux Local Privilege Escalation via SUID /proc/pid/mem Write (zx2c4)

Posted Jan 24, 2012 10:18 UTC (Tue) by ledow (guest, #11753)
In reply to: Linux Local Privilege Escalation via SUID /proc/pid/mem Write (zx2c4) by dgm
Parent article: Linux Local Privilege Escalation via SUID /proc/pid/mem Write (zx2c4)

Is there a way to block comments from a certain user on this forum?

I'm *really* getting tired of conspiracy-theory-bob every time anything security related comes up, where they just assume everyone should be perfect like them, care about exactly the same things they do, that everyone should go to the news stations with "THIS PATCH COULD MAKE YOUR COMPUTER MELT AND HACKERS DESTROY YOUR LOCAL NUCLEAR POWER STATION" every time there's the slightest hint of an off-by-one in a patch (even if the full impact of things patched can take YEARS to realise), and that they are right and everyone else is wrong.

I don't *CARE* if they are right any more, it's got to the point where the personality and the very sight of their username makes me not want to read the whole thread.

PaXTeam - How many followers do you think you get by doing this every other article, compared to how many you turn off with your obnoxious, over-bearing attitude and inability to drop the long-term bias and discuss only the matter at hand? You are a perfect example of how to disguise a perfectly good message behind a social screen, to the point where nobody cares any more.

WE GET IT. We just don't care. Don't change the message, change the delivery.


to post comments

Linux Local Privilege Escalation via SUID /proc/pid/mem Write (zx2c4)

Posted Jan 24, 2012 11:40 UTC (Tue) by patrick_g (subscriber, #44470) [Link]

You can enable comment filtering in your "My account" page (it's only available for the "professional hackers" subscription level).

Linux Local Privilege Escalation via SUID /proc/pid/mem Write (zx2c4)

Posted Jan 24, 2012 13:15 UTC (Tue) by spaetz (guest, #32870) [Link]

> Is there a way to block comments from a certain user on this forum?

Yes, filter user or somesuch in your account section.
It makes life much better :-)

Linux Local Privilege Escalation via SUID /proc/pid/mem Write (zx2c4)

Posted Jan 24, 2012 17:50 UTC (Tue) by epa (subscriber, #39769) [Link] (3 responses)

I find PaXTeam's comments useful because they give an "outsider" perspective on kernel security. They are by someone who knows what he or she is talking about but who isn't part of the inner circle of kernel developers. That helps to avoid smug groupthink and to point out deficiencies in the development process - though it's a shame that a flamewar erupts every time PaXTeam or someone else points out that the kernel changelog messages are a bit obfuscatory.

Linux Local Privilege Escalation via SUID /proc/pid/mem Write (zx2c4)

Posted Jan 26, 2012 19:34 UTC (Thu) by vonbrand (subscriber, #4458) [Link] (2 responses)

My beef with this whole "Linux security sucks" brouhaha is that it is obviously very easy in hindsight (given that a bug has a exploit posted, and has been dissected to death) to go back and see that very many people didn't talk about it before. And from there, blissfully disregarding Hanlon's razor it is a short step to world-wide conspiracy theories.

Sorry, not each and every fix will ever get this level of scrutiny, probably just a minor fraction of those with real security impact will. Get over it.

Linux Local Privilege Escalation via SUID /proc/pid/mem Write (zx2c4)

Posted Jan 26, 2012 22:24 UTC (Thu) by PaXTeam (guest, #24616) [Link] (1 responses)

sometimes it's worth reading the whole story before you comment. this particular bug was reported in private to the kernel security list as a security bug with a working exploit, there was no question whatsoever about its seriousness. despite that, we know what Linus chose to tell the world about it. and we also know how well that worked out for him ;).

Linux Local Privilege Escalation via SUID /proc/pid/mem Write (zx2c4)

Posted Jan 26, 2012 22:46 UTC (Thu) by raven667 (subscriber, #5198) [Link]

I think a lot of people just don't want to believe that Linus wouldn't be forthright about security so they rationalize that by assuming there must have been an error somewhere, that Linus didn't really know or whatever. That's why we keep getting the same debunked explanations for the observed behavior rather than being able to move on with a discussion of the merits of what actually is happening.


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds