<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Nerdling Sapple</title>
	<atom:link href="http://blog.zx2c4.com/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.zx2c4.com</link>
	<description>{{{ ZX2C4 }}}</description>
	<lastBuildDate>Sat, 04 Feb 2012 10:56:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by LINUX PE Exploit &#124; ZuLL, יומנו של האקר.</title>
		<link>http://blog.zx2c4.com/749#comment-6605</link>
		<dc:creator>LINUX PE Exploit &#124; ZuLL, יומנו של האקר.</dc:creator>
		<pubDate>Sat, 04 Feb 2012 10:56:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6605</guid>
		<description>[...] למידע נוסף, http://blog.zx2c4.com/749 [...]</description>
		<content:encoded><![CDATA[<p>[...] למידע נוסף, http://blog.zx2c4.com/749 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by PoC exploits for Linux privilege escalation bug published &#124; MYH3R3</title>
		<link>http://blog.zx2c4.com/749#comment-6600</link>
		<dc:creator>PoC exploits for Linux privilege escalation bug published &#124; MYH3R3</dc:creator>
		<pubDate>Thu, 02 Feb 2012 18:15:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6600</guid>
		<description>[...] and programmer Jason Donenfeld first shared some insights about how the flaw can be exploited, and the information was used by others to [...]</description>
		<content:encoded><![CDATA[<p>[...] and programmer Jason Donenfeld first shared some insights about how the flaw can be exploited, and the information was used by others to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by ثغرة فكيرنل اللينكس تتيح لك الدخول للروت &#171; omanix09</title>
		<link>http://blog.zx2c4.com/749#comment-6598</link>
		<dc:creator>ثغرة فكيرنل اللينكس تتيح لك الدخول للروت &#171; omanix09</dc:creator>
		<pubDate>Thu, 02 Feb 2012 07:48:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6598</guid>
		<description>[...] واللي حاب يتعلم ينظر لملف الثغرة وللمزيد من الشرح تابع مدونة مكتشف الثغرة  [...]</description>
		<content:encoded><![CDATA[<p>[...] واللي حاب يتعلم ينظر لملف الثغرة وللمزيد من الشرح تابع مدونة مكتشف الثغرة  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by CVE 2012-0056 &#124; My Blog</title>
		<link>http://blog.zx2c4.com/749#comment-6595</link>
		<dc:creator>CVE 2012-0056 &#124; My Blog</dc:creator>
		<pubDate>Wed, 01 Feb 2012 10:04:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6595</guid>
		<description>[...] was removed. Anyone with the correct permissions could write to process memory. &#8220; &#8212; http://blog.zx2c4.com/749 Like this:LikeBe the first to like this post.   By adl  &#149;   Posted in Uncategorized   [...]</description>
		<content:encoded><![CDATA[<p>[...] was removed. Anyone with the correct permissions could write to process memory. &#8220; &#8212; <a href="http://blog.zx2c4.com/749" rel="nofollow">http://blog.zx2c4.com/749</a> Like this:LikeBe the first to like this post.   By adl  &#8226;   Posted in Uncategorized   [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by PoC exploits for Linux privilege escalation bug published &#124; MYH3R3</title>
		<link>http://blog.zx2c4.com/749#comment-6593</link>
		<dc:creator>PoC exploits for Linux privilege escalation bug published &#124; MYH3R3</dc:creator>
		<pubDate>Tue, 31 Jan 2012 17:25:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6593</guid>
		<description>[...] popping up online, TechWorld reports.Security researcher and programmer Jason Donenfeld first shared some insights about how the flaw can be exploited, and the information was used by others to [...]</description>
		<content:encoded><![CDATA[<p>[...] popping up online, TechWorld reports.Security researcher and programmer Jason Donenfeld first shared some insights about how the flaw can be exploited, and the information was used by others to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Terion</title>
		<link>http://blog.zx2c4.com/749#comment-6591</link>
		<dc:creator>Terion</dc:creator>
		<pubDate>Tue, 31 Jan 2012 09:43:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6591</guid>
		<description>Doesn&#039;t work on my system. What am I doing wrong (right?) Terminal output:
terion@LAPTOP:~/Downloads/mempodipper$ ./build-and-run-exploit.sh
===============================
=          Mempodipper        =
=           by zx2c4          =
=         Jan 21, 2012        =
===============================

[+] Ptracing su to find next instruction without reading binary.
[+] Creating ptrace pipe.
[+] Forking ptrace child.
[+] Waiting for ptraced child to give output on syscalls.
[+] Ptrace_traceme&#039;ing process.
[+] Error message written. Single stepping to find address.
[+] Resolved call address to 0x8049570.
[+] Opening socketpair.
[+] Waiting for transferred fd in parent.
[+] Executing child from child fork.
[+] Opening parent mem /proc/5464/mem in child.
[+] Sending fd 6 to parent.
[+] Received fd at 6.
[+] Assigning fd 6 to stderr.
[+] Calculating su padding.
[+] Seeking to offset 0x8049564.
[+] Executing su with shellcode.
terion@LAPTOP:~/Downloads/mempodipper$ whoami
terion
terion@LAPTOP:~/Downloads/mempodipper$ uname -a
Linux LAPTOP 3.0.0-15-generic-pae #26-Ubuntu SMP Fri Jan 20 17:07:31 UTC 2012 i686 i686 i386 GNU/Linux</description>
		<content:encoded><![CDATA[<p>Doesn&#8217;t work on my system. What am I doing wrong (right?) Terminal output:<br />
terion@LAPTOP:~/Downloads/mempodipper$ ./build-and-run-exploit.sh<br />
===============================<br />
=          Mempodipper        =<br />
=           by zx2c4          =<br />
=         Jan 21, 2012        =<br />
===============================</p>
<p>[+] Ptracing su to find next instruction without reading binary.<br />
[+] Creating ptrace pipe.<br />
[+] Forking ptrace child.<br />
[+] Waiting for ptraced child to give output on syscalls.<br />
[+] Ptrace_traceme&#8217;ing process.<br />
[+] Error message written. Single stepping to find address.<br />
[+] Resolved call address to 0&#215;8049570.<br />
[+] Opening socketpair.<br />
[+] Waiting for transferred fd in parent.<br />
[+] Executing child from child fork.<br />
[+] Opening parent mem /proc/5464/mem in child.<br />
[+] Sending fd 6 to parent.<br />
[+] Received fd at 6.<br />
[+] Assigning fd 6 to stderr.<br />
[+] Calculating su padding.<br />
[+] Seeking to offset 0&#215;8049564.<br />
[+] Executing su with shellcode.<br />
terion@LAPTOP:~/Downloads/mempodipper$ whoami<br />
terion<br />
terion@LAPTOP:~/Downloads/mempodipper$ uname -a<br />
Linux LAPTOP 3.0.0-15-generic-pae #26-Ubuntu SMP Fri Jan 20 17:07:31 UTC 2012 i686 i686 i386 GNU/Linux</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux local privilege escalation via SUID &#171; My Technical Notes</title>
		<link>http://blog.zx2c4.com/749#comment-6590</link>
		<dc:creator>Linux local privilege escalation via SUID &#171; My Technical Notes</dc:creator>
		<pubDate>Tue, 31 Jan 2012 06:24:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6590</guid>
		<description>[...] 2. http://blog.zx2c4.com/749 [...]</description>
		<content:encoded><![CDATA[<p>[...] 2. http://blog.zx2c4.com/749 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by m33x</title>
		<link>http://blog.zx2c4.com/749#comment-6589</link>
		<dc:creator>m33x</dc:creator>
		<pubDate>Tue, 31 Jan 2012 00:24:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6589</guid>
		<description>While I try to start the exploit via PHP (user is www-data) all I get is:

[+] Opening parent mem /proc/25160/mem in child.
[+] Sending fd 8 to parent.

(For sure i changed the executed shell code to something more matching like creating a folder, instead of spawning a shell)</description>
		<content:encoded><![CDATA[<p>While I try to start the exploit via PHP (user is www-data) all I get is:</p>
<p>[+] Opening parent mem /proc/25160/mem in child.<br />
[+] Sending fd 8 to parent.</p>
<p>(For sure i changed the executed shell code to something more matching like creating a folder, instead of spawning a shell)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by La gestion des correctifs sous environnement Linux &#124; Technoweb</title>
		<link>http://blog.zx2c4.com/749#comment-6587</link>
		<dc:creator>La gestion des correctifs sous environnement Linux &#124; Technoweb</dc:creator>
		<pubDate>Mon, 30 Jan 2012 18:48:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6587</guid>
		<description>[...] le cas de la dernière alerte, la mise à disposition d&#8217;un exploit et d&#8217;un très bon tuto a été tellement rapide qu&#8217;il a pris de court les éditeurs de distribution Linux. Sachant [...]</description>
		<content:encoded><![CDATA[<p>[...] le cas de la dernière alerte, la mise à disposition d&#8217;un exploit et d&#8217;un très bon tuto a été tellement rapide qu&#8217;il a pris de court les éditeurs de distribution Linux. Sachant [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by jmz</title>
		<link>http://blog.zx2c4.com/749#comment-6583</link>
		<dc:creator>jmz</dc:creator>
		<pubDate>Mon, 30 Jan 2012 09:52:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6583</guid>
		<description>I actually wasn&#039;t able to find any non-PIE setuid binaries on my Arch install.</description>
		<content:encoded><![CDATA[<p>I actually wasn&#8217;t able to find any non-PIE setuid binaries on my Arch install.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by How to force linux kernel version to 2.6.x &#171; Site News &#171; majestika</title>
		<link>http://blog.zx2c4.com/749#comment-6582</link>
		<dc:creator>How to force linux kernel version to 2.6.x &#171; Site News &#171; majestika</dc:creator>
		<pubDate>Mon, 30 Jan 2012 06:59:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6582</guid>
		<description>[...] to latest code (especially because of certain bugs that recently were patched, such as the famous mempodipper), this is [...]</description>
		<content:encoded><![CDATA[<p>[...] to latest code (especially because of certain bugs that recently were patched, such as the famous mempodipper), this is [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Escabilidad de privilegios en Linux</title>
		<link>http://blog.zx2c4.com/749#comment-6581</link>
		<dc:creator>Escabilidad de privilegios en Linux</dc:creator>
		<pubDate>Mon, 30 Jan 2012 06:50:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6581</guid>
		<description>[...] más info pueden visitar Este link. Saludos!     &lt; Remove WAT [...]</description>
		<content:encoded><![CDATA[<p>[...] más info pueden visitar Este link. Saludos!     &lt; Remove WAT [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Sysadmin Sunday 64 &#171; Boxed Ice Blog</title>
		<link>http://blog.zx2c4.com/749#comment-6573</link>
		<dc:creator>Sysadmin Sunday 64 &#171; Boxed Ice Blog</dc:creator>
		<pubDate>Sun, 29 Jan 2012 16:02:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6573</guid>
		<description>[...] Linux Local Privilege Escalation via SUID /proc/pid/mem Write [...]</description>
		<content:encoded><![CDATA[<p>[...] Linux Local Privilege Escalation via SUID /proc/pid/mem Write [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by centos升级内核教程 &#124; haohtml&#039;s blog</title>
		<link>http://blog.zx2c4.com/749#comment-6572</link>
		<dc:creator>centos升级内核教程 &#124; haohtml&#039;s blog</dc:creator>
		<pubDate>Sun, 29 Jan 2012 09:53:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6572</guid>
		<description>[...] 当前系统内核为2.6.32-71.el6.i686.由于最近内核出现最新的漏洞(linux kernel 又爆内存提权漏洞，&gt;=2.6.39 内核无一幸免 和http://blog.zx2c4.com/749),所以将内核升级至3.2.2最新版本. [...]</description>
		<content:encoded><![CDATA[<p>[...] 当前系统内核为2.6.32-71.el6.i686.由于最近内核出现最新的漏洞(linux kernel 又爆内存提权漏洞，&gt;=2.6.39 内核无一幸免 和http://blog.zx2c4.com/749),所以将内核升级至3.2.2最新版本. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by CVE-2012-0056 Linux privilege escalation [Video Demonstration] &#171; CC&#039;S ONLINE JOURNAL</title>
		<link>http://blog.zx2c4.com/749#comment-6571</link>
		<dc:creator>CVE-2012-0056 Linux privilege escalation [Video Demonstration] &#171; CC&#039;S ONLINE JOURNAL</dc:creator>
		<pubDate>Sun, 29 Jan 2012 04:30:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6571</guid>
		<description>[...] which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper. Read More Here.Video Demonstration:    Advertisement  GA_googleAddAttr(&quot;AdOpt&quot;, &quot;1&quot;); [...]</description>
		<content:encoded><![CDATA[<p>[...] which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper. Read More Here.Video Demonstration:    Advertisement  GA_googleAddAttr(&quot;AdOpt&quot;, &quot;1&quot;); [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by CVE-2012-0056 Linux privilege escalation [Video Demonstration]&#160;/&#160; Hackersplay.com</title>
		<link>http://blog.zx2c4.com/749#comment-6569</link>
		<dc:creator>CVE-2012-0056 Linux privilege escalation [Video Demonstration]&#160;/&#160; Hackersplay.com</dc:creator>
		<pubDate>Sun, 29 Jan 2012 00:27:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6569</guid>
		<description>[...] which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper. Read More [...]</description>
		<content:encoded><![CDATA[<p>[...] which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper. Read More [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by unhackable security &#187; Blog Archive &#187; Linux vendors rush to patch privilege escalation flaw after root exploits emerge</title>
		<link>http://blog.zx2c4.com/749#comment-6568</link>
		<dc:creator>unhackable security &#187; Blog Archive &#187; Linux vendors rush to patch privilege escalation flaw after root exploits emerge</dc:creator>
		<pubDate>Sat, 28 Jan 2012 22:14:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6568</guid>
		<description>[...] published a detailed article about how the vulnerability can be exploited on his blog on Sunday, which served as inspiration for [...]</description>
		<content:encoded><![CDATA[<p>[...] published a detailed article about how the vulnerability can be exploited on his blog on Sunday, which served as inspiration for [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by VU#470151: Linux Kernel local privilege escalation via SUID /proc/pid/mem write</title>
		<link>http://blog.zx2c4.com/749#comment-6556</link>
		<dc:creator>VU#470151: Linux Kernel local privilege escalation via SUID /proc/pid/mem write</dc:creator>
		<pubDate>Fri, 27 Jan 2012 17:16:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6556</guid>
		<description>[...] an attacker can run arbitrary code with root privileges. Further technical details can be found on Jason A. Donenfeld&#8217;s ZX2C4 blog post.II. ImpactA local, authenticated attacker may be able to gain root privileges on the system.III. [...]</description>
		<content:encoded><![CDATA[<p>[...] an attacker can run arbitrary code with root privileges. Further technical details can be found on Jason A. Donenfeld&#8217;s ZX2C4 blog post.II. ImpactA local, authenticated attacker may be able to gain root privileges on the system.III. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on KDE Doesn&#8217;t Suck Anymore, People Finally Realize by Alhana</title>
		<link>http://blog.zx2c4.com/726#comment-6552</link>
		<dc:creator>Alhana</dc:creator>
		<pubDate>Fri, 27 Jan 2012 11:57:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=726#comment-6552</guid>
		<description>It&#039;s not true. KDE is still gaudy, very slow, having misterious segfaults each 15 minutes and consisting of programs which either has too little functions or plainly doesn&#039;t work. It&#039;s nightmare to work with.</description>
		<content:encoded><![CDATA[<p>It&#8217;s not true. KDE is still gaudy, very slow, having misterious segfaults each 15 minutes and consisting of programs which either has too little functions or plainly doesn&#8217;t work. It&#8217;s nightmare to work with.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Exploit root Linux Karena Akses Memori &#124; LinuxBox.Web.ID</title>
		<link>http://blog.zx2c4.com/749#comment-6551</link>
		<dc:creator>Exploit root Linux Karena Akses Memori &#124; LinuxBox.Web.ID</dc:creator>
		<pubDate>Fri, 27 Jan 2012 09:47:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6551</guid>
		<description>[...] dan dapat diakali dengan mudah.Segera setelah publikasi artikel yang menjelaskan hal tersebut di Nerdling Sapple, pengkode lainnya menggunakan informasi yanga da didalam artikel untuk membuat eksploit dan [...]</description>
		<content:encoded><![CDATA[<p>[...] dan dapat diakali dengan mudah.Segera setelah publikasi artikel yang menjelaskan hal tersebut di Nerdling Sapple, pengkode lainnya menggunakan informasi yanga da didalam artikel untuk membuat eksploit dan [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Rolf</title>
		<link>http://blog.zx2c4.com/749#comment-6550</link>
		<dc:creator>Rolf</dc:creator>
		<pubDate>Fri, 27 Jan 2012 08:57:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6550</guid>
		<description>Why is /proc/pid/mem needed anyway?  It seems a huge risk to have direct access to process memory, regardles of security measures.</description>
		<content:encoded><![CDATA[<p>Why is /proc/pid/mem needed anyway?  It seems a huge risk to have direct access to process memory, regardles of security measures.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by André Caldas</title>
		<link>http://blog.zx2c4.com/749#comment-6548</link>
		<dc:creator>André Caldas</dc:creator>
		<pubDate>Fri, 27 Jan 2012 08:02:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6548</guid>
		<description>I find it interesting people arguing that the exploit is flawed!!!

Security does not work that way! You cannot, after an exploit, argue that you could have blocked proc/pid/mem access. Well, you could simply not turn your computer on. The exploit does not block you from turning your computer off and never turning it on again!!! So, it is flawed!!! :-P</description>
		<content:encoded><![CDATA[<p>I find it interesting people arguing that the exploit is flawed!!!</p>
<p>Security does not work that way! You cannot, after an exploit, argue that you could have blocked proc/pid/mem access. Well, you could simply not turn your computer on. The exploit does not block you from turning your computer off and never turning it on again!!! So, it is flawed!!! <img src='http://blog.zx2c4.com/wp-includes/images/smilies/icon_razz.gif' alt=':-P' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Fehler im Linux Kernel ermöglicht ROOT &#124; Tuxxnet.de - Mit Sicherheit einen Schritt voraus!</title>
		<link>http://blog.zx2c4.com/749#comment-6547</link>
		<dc:creator>Fehler im Linux Kernel ermöglicht ROOT &#124; Tuxxnet.de - Mit Sicherheit einen Schritt voraus!</dc:creator>
		<pubDate>Fri, 27 Jan 2012 07:48:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6547</guid>
		<description>[...] vor einigen Tagen von Linus Torvalds im offiziellen Kernel behoben und in Folge an anderer Stelle n&#228;her analyisert. Mittlerweile kursieren bereits diverse Exploits, die den Fehler ausnutzen k&#246;nnen, um [...]</description>
		<content:encoded><![CDATA[<p>[...] vor einigen Tagen von Linus Torvalds im offiziellen Kernel behoben und in Folge an anderer Stelle n&auml;her analyisert. Mittlerweile kursieren bereits diverse Exploits, die den Fehler ausnutzen k&ouml;nnen, um [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux local kernel privilege escalation to root &#171; codeinsecurity</title>
		<link>http://blog.zx2c4.com/749#comment-6546</link>
		<dc:creator>Linux local kernel privilege escalation to root &#171; codeinsecurity</dc:creator>
		<pubDate>Fri, 27 Jan 2012 07:13:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6546</guid>
		<description>[...] security researcher zx2c4 has released a technical description of the bug, as well as an exploit.  Advertisement  GA_googleAddAttr(&quot;AdOpt&quot;, &quot;1&quot;); [...]</description>
		<content:encoded><![CDATA[<p>[...] security researcher zx2c4 has released a technical description of the bug, as well as an exploit.  Advertisement  GA_googleAddAttr(&quot;AdOpt&quot;, &quot;1&quot;); [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Answers for Everyone &#124; Jupiter Broadcasting</title>
		<link>http://blog.zx2c4.com/749#comment-6543</link>
		<dc:creator>Answers for Everyone &#124; Jupiter Broadcasting</dc:creator>
		<pubDate>Fri, 27 Jan 2012 04:41:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6543</guid>
		<description>[...] Analysis  [...]</description>
		<content:encoded><![CDATA[<p>[...] Analysis  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by oiaohm</title>
		<link>http://blog.zx2c4.com/749#comment-6541</link>
		<dc:creator>oiaohm</dc:creator>
		<pubDate>Fri, 27 Jan 2012 03:09:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6541</guid>
		<description>This is not a 100 percent sure will work breach even with a defective kernel.

There is two major issues forgot.  This does not block a LSM from disabling access /proc/*/mem.   This could selinux or smack for sure.

So a kernel update is not required to address this problem.  Turn LSM on set up rules attack is dead as a dodo.    Basically only selinux or smack approve applications can access /proc/*/mem read write.  Every other applicaiton gets read only or nothing. 

Injection is not assured in Linux.

Really is there any critical need for distrobutions with selinux or smack by default to rush out a kernel patch.  Not at all.  Just make sure they have it turned on.

This does ask serous questions why LSM on have not become kinda mandortory.  No need to wait for distribution to fix this.</description>
		<content:encoded><![CDATA[<p>This is not a 100 percent sure will work breach even with a defective kernel.</p>
<p>There is two major issues forgot.  This does not block a LSM from disabling access /proc/*/mem.   This could selinux or smack for sure.</p>
<p>So a kernel update is not required to address this problem.  Turn LSM on set up rules attack is dead as a dodo.    Basically only selinux or smack approve applications can access /proc/*/mem read write.  Every other applicaiton gets read only or nothing. </p>
<p>Injection is not assured in Linux.</p>
<p>Really is there any critical need for distrobutions with selinux or smack by default to rush out a kernel patch.  Not at all.  Just make sure they have it turned on.</p>
<p>This does ask serous questions why LSM on have not become kinda mandortory.  No need to wait for distribution to fix this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by skunk</title>
		<link>http://blog.zx2c4.com/749#comment-6534</link>
		<dc:creator>skunk</dc:creator>
		<pubDate>Thu, 26 Jan 2012 20:38:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6534</guid>
		<description>hi jason, it works perfectly on my gentoo box but not on my hardened gentoo server:

skunk@web1 CVE-2012-0056 % uname -a
Linux web1 2.6.39-hardened-r8 #1 SMP Sat Sep 17 13:58:22 CEST 2011 x86_64 Intel(R) Xeon(R) CPU E5520 @ 2.27GHz GenuineIntel GNU/Linuxskunk@web1 CVE-2012-0056 % ./build-and-run-exploit.sh 
===============================
=          Mempodipper        =
=           by zx2c4          =
=         Jan 21, 2012        =
===============================

[+] Ptracing su to find next instruction without reading binary.
[+] Creating ptrace pipe.
[+] Forking ptrace child.
[+] Waiting for ptraced child to give output on syscalls.
[+] Ptrace_traceme&#039;ing process.
[+] Error message written. Single stepping to find address.
[+] Resolved call address to 0x716a3d5b70.
[+] Opening socketpair.
[+] Waiting for transferred fd in parent.
[+] Executing child from child fork.
[+] Opening parent mem /proc/18668/mem in child.
[+] Sending fd 6 to parent.
[+] Received fd at 6.
[+] Assigning fd 6 to stderr.
[+] Calculating su padding.
[+] Seeking to offset 0x716a3d5b64.
[+] Executing su with shellcode.
skunk@web1 CVE-2012-0056 % whoami
skunk</description>
		<content:encoded><![CDATA[<p>hi jason, it works perfectly on my gentoo box but not on my hardened gentoo server:</p>
<p>skunk@web1 CVE-2012-0056 % uname -a<br />
Linux web1 2.6.39-hardened-r8 #1 SMP Sat Sep 17 13:58:22 CEST 2011 x86_64 Intel(R) Xeon(R) CPU E5520 @ 2.27GHz GenuineIntel GNU/Linuxskunk@web1 CVE-2012-0056 % ./build-and-run-exploit.sh<br />
===============================<br />
=          Mempodipper        =<br />
=           by zx2c4          =<br />
=         Jan 21, 2012        =<br />
===============================</p>
<p>[+] Ptracing su to find next instruction without reading binary.<br />
[+] Creating ptrace pipe.<br />
[+] Forking ptrace child.<br />
[+] Waiting for ptraced child to give output on syscalls.<br />
[+] Ptrace_traceme&#8217;ing process.<br />
[+] Error message written. Single stepping to find address.<br />
[+] Resolved call address to 0x716a3d5b70.<br />
[+] Opening socketpair.<br />
[+] Waiting for transferred fd in parent.<br />
[+] Executing child from child fork.<br />
[+] Opening parent mem /proc/18668/mem in child.<br />
[+] Sending fd 6 to parent.<br />
[+] Received fd at 6.<br />
[+] Assigning fd 6 to stderr.<br />
[+] Calculating su padding.<br />
[+] Seeking to offset 0x716a3d5b64.<br />
[+] Executing su with shellcode.<br />
skunk@web1 CVE-2012-0056 % whoami<br />
skunk</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Elevación de privilegios en el kernel Linux y un exploit interesante &#124; MundoPC.NET</title>
		<link>http://blog.zx2c4.com/749#comment-6524</link>
		<dc:creator>Elevación de privilegios en el kernel Linux y un exploit interesante &#124; MundoPC.NET</dc:creator>
		<pubDate>Thu, 26 Jan 2012 14:54:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6524</guid>
		<description>[...]  [...]</description>
		<content:encoded><![CDATA[<p>[...]  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux vendors rush to patch privilege escalation flaw after root exploits emerge : News Sluice</title>
		<link>http://blog.zx2c4.com/749#comment-6522</link>
		<dc:creator>Linux vendors rush to patch privilege escalation flaw after root exploits emerge : News Sluice</dc:creator>
		<pubDate>Thu, 26 Jan 2012 12:57:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6522</guid>
		<description>[...] published a detailed article about how the vulnerability can be exploited on his blog on Sunday, which served as inspiration [...]</description>
		<content:encoded><![CDATA[<p>[...] published a detailed article about how the vulnerability can be exploited on his blog on Sunday, which served as inspiration [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by eXactBot Hosting Solutions &#187; Did Linus Jump the Gun on a Kernel security fix?</title>
		<link>http://blog.zx2c4.com/749#comment-6521</link>
		<dc:creator>eXactBot Hosting Solutions &#187; Did Linus Jump the Gun on a Kernel security fix?</dc:creator>
		<pubDate>Thu, 26 Jan 2012 12:15:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6521</guid>
		<description>[...] flaw. As it turns out the flaw was exploited quickly once Torvalds put out the patch with a proof of concept emerging [...]</description>
		<content:encoded><![CDATA[<p>[...] flaw. As it turns out the flaw was exploited quickly once Torvalds put out the patch with a proof of concept emerging [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Chris Mylonas</title>
		<link>http://blog.zx2c4.com/749#comment-6520</link>
		<dc:creator>Chris Mylonas</dc:creator>
		<pubDate>Thu, 26 Jan 2012 11:15:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6520</guid>
		<description>Wow!  What an impressive post...
Thanks for breaking it down like that.   The number and relevance of your peers&#039; comments reflect my initial sentiments.

Thanks for sharing.</description>
		<content:encoded><![CDATA[<p>Wow!  What an impressive post&#8230;<br />
Thanks for breaking it down like that.   The number and relevance of your peers&#8217; comments reflect my initial sentiments.</p>
<p>Thanks for sharing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by IO</title>
		<link>http://blog.zx2c4.com/749#comment-6517</link>
		<dc:creator>IO</dc:creator>
		<pubDate>Thu, 26 Jan 2012 09:38:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6517</guid>
		<description>Is 3.2-1 affected? there is no mention in changelog about this  behavior,  however  Debian whit official linux-source 3.2-1 seems to be immune.

http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.1

http://packages.debian.org/changelogs/pool/main/l/linux-2.6/linux-2.6_3.2.1-1/changelog</description>
		<content:encoded><![CDATA[<p>Is 3.2-1 affected? there is no mention in changelog about this  behavior,  however  Debian whit official linux-source 3.2-1 seems to be immune.</p>
<p><a href="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.1" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.1?referer=');">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.1</a></p>
<p><a href="http://packages.debian.org/changelogs/pool/main/l/linux-2.6/linux-2.6_3.2.1-1/changelog" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/packages.debian.org/changelogs/pool/main/l/linux-2.6/linux-2.6_3.2.1-1/changelog?referer=');">http://packages.debian.org/changelogs/pool/main/l/linux-2.6/linux-2.6_3.2.1-1/changelog</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Red Hat, Ubuntu, and Arch Linux patch Linux kernel exploit &#124; Matias Vangsnes</title>
		<link>http://blog.zx2c4.com/749#comment-6512</link>
		<dc:creator>Red Hat, Ubuntu, and Arch Linux patch Linux kernel exploit &#124; Matias Vangsnes</dc:creator>
		<pubDate>Wed, 25 Jan 2012 19:35:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6512</guid>
		<description>[...] Jason A. Donenfeld posted a proof-of-concept exploit called &#8220;mempodipper,&#8221; and then published an in-depth technical overview.Donenfield&#8217;s explanation inspired other hackers to post additional exploits, according to [...]</description>
		<content:encoded><![CDATA[<p>[...] Jason A. Donenfeld posted a proof-of-concept exploit called &#8220;mempodipper,&#8221; and then published an in-depth technical overview.Donenfield&#8217;s explanation inspired other hackers to post additional exploits, according to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by zac</title>
		<link>http://blog.zx2c4.com/749#comment-6510</link>
		<dc:creator>zac</dc:creator>
		<pubDate>Wed, 25 Jan 2012 18:41:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6510</guid>
		<description>for your command look up, in particular line 140 of Mempodipper you can use which to more robustly lookup command e.g. 
objdump -d `which gpasswd`&#124;grep &#039;&#039;&#124;head -n 1&#124;cut -d &#039; &#039; -f 1&#124;sed &#039;s/^[0]*\\([^0]*\\)/0x\\1/&#039;
rather than:
objdump -d /usr/bin/gpasswd&#124;grep &#039;&#039;&#124;head -n 1&#124;cut -d &#039; &#039; -f 1&#124;sed &#039;s/^[0]*\\([^0]*\\)/0x\\1/&#039;</description>
		<content:encoded><![CDATA[<p>for your command look up, in particular line 140 of Mempodipper you can use which to more robustly lookup command e.g.<br />
objdump -d `which gpasswd`|grep &#8221;|head -n 1|cut -d &#8216; &#8216; -f 1|sed &#8216;s/^[0]*\\([^0]*\\)/0x\\1/&#8217;<br />
rather than:<br />
objdump -d /usr/bin/gpasswd|grep &#8221;|head -n 1|cut -d &#8216; &#8216; -f 1|sed &#8216;s/^[0]*\\([^0]*\\)/0x\\1/&#8217;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Michael</title>
		<link>http://blog.zx2c4.com/749#comment-6506</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Wed, 25 Jan 2012 10:18:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6506</guid>
		<description>Same here on CentOS 5 and CentOS 6 (pipe2 problem)</description>
		<content:encoded><![CDATA[<p>Same here on CentOS 5 and CentOS 6 (pipe2 problem)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux vendors rush to patch privilege escalation flaw after root exploits emerge - HackerMuslim.com &#124; HackerMuslim.com</title>
		<link>http://blog.zx2c4.com/749#comment-6504</link>
		<dc:creator>Linux vendors rush to patch privilege escalation flaw after root exploits emerge - HackerMuslim.com &#124; HackerMuslim.com</dc:creator>
		<pubDate>Wed, 25 Jan 2012 09:56:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6504</guid>
		<description>[...] published a detailed article about how a disadvantage can be exploited on his blog on Sunday, that served as impulse for other [...]</description>
		<content:encoded><![CDATA[<p>[...] published a detailed article about how a disadvantage can be exploited on his blog on Sunday, that served as impulse for other [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by antonone</title>
		<link>http://blog.zx2c4.com/749#comment-6503</link>
		<dc:creator>antonone</dc:creator>
		<pubDate>Wed, 25 Jan 2012 08:45:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6503</guid>
		<description>Recent Fedora updates mitigate this exploit. F.e. in kernel:

2.6.41.10-3.fc15.x86_64 #1 SMP Mon Jan 23 15:46:37 UTC 2012

it doesn&#039;t work. But it worked before ;)</description>
		<content:encoded><![CDATA[<p>Recent Fedora updates mitigate this exploit. F.e. in kernel:</p>
<p>2.6.41.10-3.fc15.x86_64 #1 SMP Mon Jan 23 15:46:37 UTC 2012</p>
<p>it doesn&#8217;t work. But it worked before <img src='http://blog.zx2c4.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Caleb Everett</title>
		<link>http://blog.zx2c4.com/749#comment-6501</link>
		<dc:creator>Caleb Everett</dc:creator>
		<pubDate>Wed, 25 Jan 2012 05:28:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6501</guid>
		<description>Compiled, but did not work on my arch system.
Did not compile on schools red hat system, couldn&#039;t find pipe2.</description>
		<content:encoded><![CDATA[<p>Compiled, but did not work on my arch system.<br />
Did not compile on schools red hat system, couldn&#8217;t find pipe2.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux vendors rush to patch privilege escalation flaw after root exploits emerge &#187; Linux news</title>
		<link>http://blog.zx2c4.com/749#comment-6500</link>
		<dc:creator>Linux vendors rush to patch privilege escalation flaw after root exploits emerge &#187; Linux news</dc:creator>
		<pubDate>Tue, 24 Jan 2012 23:52:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6500</guid>
		<description>[...] published a detailed article about how the vulnerability can be exploited on his blog on Sunday, which served as inspiration for [...]</description>
		<content:encoded><![CDATA[<p>[...] published a detailed article about how the vulnerability can be exploited on his blog on Sunday, which served as inspiration for [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Get root? I &#8220;Escalando privilegios con Mempodipper CVE-2012-0056&#8243;</title>
		<link>http://blog.zx2c4.com/749#comment-6499</link>
		<dc:creator>Get root? I &#8220;Escalando privilegios con Mempodipper CVE-2012-0056&#8243;</dc:creator>
		<pubDate>Tue, 24 Jan 2012 21:57:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6499</guid>
		<description>[...] exploit es datado el 21 de Enero de 2012 por zx2c4 .Las pruebas realizadas a nivel personal  han sido satisfactorias en BackTrack5 R1 con un kernel [...]</description>
		<content:encoded><![CDATA[<p>[...] exploit es datado el 21 de Enero de 2012 por zx2c4 .Las pruebas realizadas a nivel personal  han sido satisfactorias en BackTrack5 R1 con un kernel [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by fixing vulnerabilities with systemtap &#171; codeblog</title>
		<link>http://blog.zx2c4.com/749#comment-6498</link>
		<dc:creator>fixing vulnerabilities with systemtap &#171; codeblog</dc:creator>
		<pubDate>Tue, 24 Jan 2012 19:33:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6498</guid>
		<description>[...] there is now a nearly-complete walk-through, the urgency for fixing this is higher. While you&#8217;re waiting for your distribution&#8217;s [...]</description>
		<content:encoded><![CDATA[<p>[...] there is now a nearly-complete walk-through, the urgency for fixing this is higher. While you&#8217;re waiting for your distribution&#8217;s [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by ITGeeks.us &#187; Linux root Exploit Vulnerability (CVE 2012-0056)</title>
		<link>http://blog.zx2c4.com/749#comment-6497</link>
		<dc:creator>ITGeeks.us &#187; Linux root Exploit Vulnerability (CVE 2012-0056)</dc:creator>
		<pubDate>Tue, 24 Jan 2012 18:34:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6497</guid>
		<description>[...] is an exploit called &#8220;Mempodipper&#8221; published last January 21, 2012 that enables normal users to escalate their privileges, [...]</description>
		<content:encoded><![CDATA[<p>[...] is an exploit called &#8220;Mempodipper&#8221; published last January 21, 2012 that enables normal users to escalate their privileges, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Escalada de privilegios con /proc/pid/mem write &#124; ANIME LINUX STYLE IN THE WORLD</title>
		<link>http://blog.zx2c4.com/749#comment-6496</link>
		<dc:creator>Escalada de privilegios con /proc/pid/mem write &#124; ANIME LINUX STYLE IN THE WORLD</dc:creator>
		<pubDate>Tue, 24 Jan 2012 18:14:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6496</guid>
		<description>[...] explicación completa está en http://blog.zx2c4.com/749 (en ingles) en donde este experto ha explicado cómo funciona el exploit para la vulnerabilidad [...]</description>
		<content:encoded><![CDATA[<p>[...] explicación completa está en http://blog.zx2c4.com/749 (en ingles) en donde este experto ha explicado cómo funciona el exploit para la vulnerabilidad [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux root Exploit Vulnerability (CVE 2012-0056) &#124; ProjectX Blog &#8211; Information Security Redefined</title>
		<link>http://blog.zx2c4.com/749#comment-6494</link>
		<dc:creator>Linux root Exploit Vulnerability (CVE 2012-0056) &#124; ProjectX Blog &#8211; Information Security Redefined</dc:creator>
		<pubDate>Tue, 24 Jan 2012 17:06:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6494</guid>
		<description>[...] Linux by tuldok &#8212; Leave a comment January 24, 2012    There is an exploit called &#8220;Mempodipper&#8221; published last January 23, 2012 that enables normal users to escalate their privileges, [...]</description>
		<content:encoded><![CDATA[<p>[...] Linux by tuldok &mdash; Leave a comment January 24, 2012    There is an exploit called &#8220;Mempodipper&#8221; published last January 23, 2012 that enables normal users to escalate their privileges, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by ex falso</title>
		<link>http://blog.zx2c4.com/749#comment-6490</link>
		<dc:creator>ex falso</dc:creator>
		<pubDate>Tue, 24 Jan 2012 15:18:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6490</guid>
		<description>exfalso@QuodLibet ~/tmp % gcc -o mkroot mkroot.c -O0
exfalso@QuodLibet ~/tmp % uname -r
3.2.1-1-ARCH
exfalso@QuodLibet ~/tmp % ./mkroot
===============================
=          Mempodipper        =
=           by zx2c4          =
=         Jan 21, 2012        =
===============================

[+] Waiting for transferred fd in parent.
[+] Executing child from child fork.
[+] Opening parent mem /proc/8332/mem in child.
[+] Sending fd 3 to parent.
[+] Received fd at 5.
[+] Assigning fd 5 to stderr.
[+] Reading su for exit@plt.
[+] Resolved exit@plt to 0x401a60.
[+] Calculating su padding.
[+] Seeking to offset 0x401a57.
[+] Executing su with shellcode.
[1]    8332 segmentation fault  ./mkroot


l2program lol</description>
		<content:encoded><![CDATA[<p>exfalso@QuodLibet ~/tmp % gcc -o mkroot mkroot.c -O0<br />
exfalso@QuodLibet ~/tmp % uname -r<br />
3.2.1-1-ARCH<br />
exfalso@QuodLibet ~/tmp % ./mkroot<br />
===============================<br />
=          Mempodipper        =<br />
=           by zx2c4          =<br />
=         Jan 21, 2012        =<br />
===============================</p>
<p>[+] Waiting for transferred fd in parent.<br />
[+] Executing child from child fork.<br />
[+] Opening parent mem /proc/8332/mem in child.<br />
[+] Sending fd 3 to parent.<br />
[+] Received fd at 5.<br />
[+] Assigning fd 5 to stderr.<br />
[+] Reading su for exit@plt.<br />
[+] Resolved exit@plt to 0x401a60.<br />
[+] Calculating su padding.<br />
[+] Seeking to offset 0x401a57.<br />
[+] Executing su with shellcode.<br />
[1]    8332 segmentation fault  ./mkroot</p>
<p>l2program lol</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by André Caldas</title>
		<link>http://blog.zx2c4.com/749#comment-6483</link>
		<dc:creator>André Caldas</dc:creator>
		<pubDate>Tue, 24 Jan 2012 12:31:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6483</guid>
		<description>It seems to me that the problem here is that &quot;self_exec_id&quot; is implicitly understood to be unique. But &quot;unique&quot; has three meanings here:

TYPE 1. It is IMPOSSIBLE to have collisions.
TYPE 2. It is HIGHLY IMPROBABLE to have &quot;natural&quot; collisions.
TYPE 3. It is HIGHLY IMPROBABLE to have &quot;natural&quot; collisions, and when it happens, it is HIGHLY IMPROBABLE we will even notice.

Given the fact that the self_exec_id is reset when it reaches its maximum value, we can say that the code that generates it does not understand that it is &quot;type 1 unique&quot;. No security check should rely on any definition of unique different from &quot;type 1 unique&quot;. Is it hard to always implement &quot;type 1 unique&quot;? (this is not a rhetorical question!)

Well, it is very easy for me to just point... but I think it is worth mentioning...</description>
		<content:encoded><![CDATA[<p>It seems to me that the problem here is that &#8220;self_exec_id&#8221; is implicitly understood to be unique. But &#8220;unique&#8221; has three meanings here:</p>
<p>TYPE 1. It is IMPOSSIBLE to have collisions.<br />
TYPE 2. It is HIGHLY IMPROBABLE to have &#8220;natural&#8221; collisions.<br />
TYPE 3. It is HIGHLY IMPROBABLE to have &#8220;natural&#8221; collisions, and when it happens, it is HIGHLY IMPROBABLE we will even notice.</p>
<p>Given the fact that the self_exec_id is reset when it reaches its maximum value, we can say that the code that generates it does not understand that it is &#8220;type 1 unique&#8221;. No security check should rely on any definition of unique different from &#8220;type 1 unique&#8221;. Is it hard to always implement &#8220;type 1 unique&#8221;? (this is not a rhetorical question!)</p>
<p>Well, it is very easy for me to just point&#8230; but I think it is worth mentioning&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Escalada de privilegios remota con /proc/pid/mem write</title>
		<link>http://blog.zx2c4.com/749#comment-6482</link>
		<dc:creator>Escalada de privilegios remota con /proc/pid/mem write</dc:creator>
		<pubDate>Tue, 24 Jan 2012 12:02:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6482</guid>
		<description>[...] explicación al completo la tenéis en el blog ZX2C4 -nombre curioso, habría que buscar su explicación- en donde este experto ha explicado cómo [...]</description>
		<content:encoded><![CDATA[<p>[...] explicación al completo la tenéis en el blog ZX2C4 -nombre curioso, habría que buscar su explicación- en donde este experto ha explicado cómo [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Another root exploit for linux &#124; Scali&#039;s blog</title>
		<link>http://blog.zx2c4.com/749#comment-6481</link>
		<dc:creator>Another root exploit for linux &#124; Scali&#039;s blog</dc:creator>
		<pubDate>Tue, 24 Jan 2012 11:21:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6481</guid>
		<description>[...] A few days ago, the following exploit was published: http://blog.zx2c4.com/749 [...]</description>
		<content:encoded><![CDATA[<p>[...] A few days ago, the following exploit was published: <a href="http://blog.zx2c4.com/749" rel="nofollow">http://blog.zx2c4.com/749</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Veovis</title>
		<link>http://blog.zx2c4.com/749#comment-6479</link>
		<dc:creator>Veovis</dc:creator>
		<pubDate>Tue, 24 Jan 2012 10:19:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6479</guid>
		<description>selinux is active on my box but in permissive mode.</description>
		<content:encoded><![CDATA[<p>selinux is active on my box but in permissive mode.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Veovis</title>
		<link>http://blog.zx2c4.com/749#comment-6478</link>
		<dc:creator>Veovis</dc:creator>
		<pubDate>Tue, 24 Jan 2012 10:18:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6478</guid>
		<description>Does not pown Gentoo Hardened (grsec+selinux-rbac) on kernel 3.1.5 x64 with last git commit at that time.</description>
		<content:encoded><![CDATA[<p>Does not pown Gentoo Hardened (grsec+selinux-rbac) on kernel 3.1.5 x64 with last git commit at that time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Nächstes Treffen am 03.02.2012 &#124; Chaostreff Salzburg</title>
		<link>http://blog.zx2c4.com/749#comment-6476</link>
		<dc:creator>Nächstes Treffen am 03.02.2012 &#124; Chaostreff Salzburg</dc:creator>
		<pubDate>Tue, 24 Jan 2012 09:06:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6476</guid>
		<description>[...] Linux: Root-Rechte durch Speicherzugriff [mehr] [...]</description>
		<content:encoded><![CDATA[<p>[...] Linux: Root-Rechte durch Speicherzugriff [mehr] [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux 本地提权漏洞 &#187; GAL(grep art life)</title>
		<link>http://blog.zx2c4.com/749#comment-6475</link>
		<dc:creator>Linux 本地提权漏洞 &#187; GAL(grep art life)</dc:creator>
		<pubDate>Tue, 24 Jan 2012 08:20:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6475</guid>
		<description>[...] 读 LWN 新闻时看到了 Linux 内核的一个本地提权漏洞。zx2c4 博客有详细介绍，强烈建议阅读。 [...]</description>
		<content:encoded><![CDATA[<p>[...] 读 LWN 新闻时看到了 Linux 内核的一个本地提权漏洞。zx2c4 博客有详细介绍，强烈建议阅读。 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by CVE-2012-0056 &#8211; Mempodipper, a linux local root exploit.</title>
		<link>http://blog.zx2c4.com/749#comment-6474</link>
		<dc:creator>CVE-2012-0056 &#8211; Mempodipper, a linux local root exploit.</dc:creator>
		<pubDate>Tue, 24 Jan 2012 08:18:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6474</guid>
		<description>[...] 分析原文：Linux Local Privilege Escalation via SUID /proc/pid/mem Write [...]</description>
		<content:encoded><![CDATA[<p>[...] 分析原文：Linux Local Privilege Escalation via SUID /proc/pid/mem Write [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Jason Donenfeld</title>
		<link>http://blog.zx2c4.com/749#comment-6473</link>
		<dc:creator>Jason Donenfeld</dc:creator>
		<pubDate>Tue, 24 Jan 2012 08:00:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6473</guid>
		<description>Well, just implemented this. It now exploits Gentoo, even with no read permissions on /bin/su.</description>
		<content:encoded><![CDATA[<p>Well, just implemented this. It now exploits Gentoo, even with no read permissions on /bin/su.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Jason Donenfeld</title>
		<link>http://blog.zx2c4.com/749#comment-6472</link>
		<dc:creator>Jason Donenfeld</dc:creator>
		<pubDate>Tue, 24 Jan 2012 08:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6472</guid>
		<description>Okay. I just implemented this. It now pwn&#039;s gentoo even with no read permissions on /bin/su.</description>
		<content:encoded><![CDATA[<p>Okay. I just implemented this. It now pwn&#8217;s gentoo even with no read permissions on /bin/su.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#8230; &#124; Tech Unleashed</title>
		<link>http://blog.zx2c4.com/749#comment-6470</link>
		<dc:creator>Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#8230; &#124; Tech Unleashed</dc:creator>
		<pubDate>Tue, 24 Jan 2012 06:20:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6470</guid>
		<description>[...] Follow this link: Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] Follow this link: Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Archie</title>
		<link>http://blog.zx2c4.com/749#comment-6468</link>
		<dc:creator>Archie</dc:creator>
		<pubDate>Tue, 24 Jan 2012 03:34:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6468</guid>
		<description>Why it is an issue for someone that THIS program does not work for their system?  Article itself explains clearly why this kind of attact works and how to fix program if there is something different in their system.  Anyway it is just proof of consept showing that there is a problem.</description>
		<content:encoded><![CDATA[<p>Why it is an issue for someone that THIS program does not work for their system?  Article itself explains clearly why this kind of attact works and how to fix program if there is something different in their system.  Anyway it is just proof of consept showing that there is a problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by local suid in linux ;) &#124; deranfangvomen.de</title>
		<link>http://blog.zx2c4.com/749#comment-6467</link>
		<dc:creator>local suid in linux ;) &#124; deranfangvomen.de</dc:creator>
		<pubDate>Mon, 23 Jan 2012 23:07:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6467</guid>
		<description>[...] http://blog.zx2c4.com/749 [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://blog.zx2c4.com/749" rel="nofollow">http://blog.zx2c4.com/749</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Mempodipper &#8211; Root-Rootrechte durch Speicherzugriff &#124; Embedded Engineering Blog</title>
		<link>http://blog.zx2c4.com/749#comment-6466</link>
		<dc:creator>Mempodipper &#8211; Root-Rootrechte durch Speicherzugriff &#124; Embedded Engineering Blog</dc:creator>
		<pubDate>Mon, 23 Jan 2012 22:37:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6466</guid>
		<description>[...] Linux-Systems sofort Root-Rechte. Eine genauere Erklärung, was da passiert, liefert der Artikel Nerdling Sapple von ZX2C4. Leider kam schon ein Systemupdate rein, auf Linux 3.0.0-15-generic #26-Ubuntu [...]</description>
		<content:encoded><![CDATA[<p>[...] Linux-Systems sofort Root-Rechte. Eine genauere Erklärung, was da passiert, liefert der Artikel Nerdling Sapple von ZX2C4. Leider kam schon ein Systemupdate rein, auf Linux 3.0.0-15-generic #26-Ubuntu [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Jason</title>
		<link>http://blog.zx2c4.com/749#comment-6465</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Mon, 23 Jan 2012 22:28:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6465</guid>
		<description>Not the case. it&#039;s possible to determine the offsets using ptrace, even on hardened gentoo. See the full-disclosure discussion for details.</description>
		<content:encoded><![CDATA[<p>Not the case. it&#8217;s possible to determine the offsets using ptrace, even on hardened gentoo. See the full-disclosure discussion for details.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux local root exploit via SUID - Tux-planet</title>
		<link>http://blog.zx2c4.com/749#comment-6464</link>
		<dc:creator>Linux local root exploit via SUID - Tux-planet</dc:creator>
		<pubDate>Mon, 23 Jan 2012 22:26:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6464</guid>
		<description>[...] Les explications sont ici : http://blog.zx2c4.com/749 [...]</description>
		<content:encoded><![CDATA[<p>[...] Les explications sont ici : <a href="http://blog.zx2c4.com/749" rel="nofollow">http://blog.zx2c4.com/749</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by t4c</title>
		<link>http://blog.zx2c4.com/749#comment-6463</link>
		<dc:creator>t4c</dc:creator>
		<pubDate>Mon, 23 Jan 2012 22:20:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6463</guid>
		<description>Arch:
Linux pandora 3.1.5-1-ARCH 

Gentoo:
Linux udopiv3 3.1.1-hardened #31337
Linux digital-bitch 3.1.6-gentoo #1 

Not vulnerable oob cause of correct permissions of /bin/su.</description>
		<content:encoded><![CDATA[<p>Arch:<br />
Linux pandora 3.1.5-1-ARCH </p>
<p>Gentoo:<br />
Linux udopiv3 3.1.1-hardened #31337<br />
Linux digital-bitch 3.1.6-gentoo #1 </p>
<p>Not vulnerable oob cause of correct permissions of /bin/su.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by darkfader</title>
		<link>http://blog.zx2c4.com/749#comment-6462</link>
		<dc:creator>darkfader</dc:creator>
		<pubDate>Mon, 23 Jan 2012 21:28:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6462</guid>
		<description>linux, bringing the unix flaws from the 90s to you in the 2010&#039;s.
&lt;3</description>
		<content:encoded><![CDATA[<p>linux, bringing the unix flaws from the 90s to you in the 2010&#8242;s.<br />
&lt;3</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by explicit</title>
		<link>http://blog.zx2c4.com/749#comment-6460</link>
		<dc:creator>explicit</dc:creator>
		<pubDate>Mon, 23 Jan 2012 20:11:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6460</guid>
		<description>True.</description>
		<content:encoded><![CDATA[<p>True.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#124; Systemoveride.net</title>
		<link>http://blog.zx2c4.com/749#comment-6458</link>
		<dc:creator>Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#124; Systemoveride.net</dc:creator>
		<pubDate>Mon, 23 Jan 2012 19:31:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6458</guid>
		<description>[...] root in un sistema . La vulnerabilità è stata scoperta da ZX2C4, e riportata sul suo blog al link http://blog.zx2c4.com/749 [...]</description>
		<content:encoded><![CDATA[<p>[...] root in un sistema . La vulnerabilità è stata scoperta da ZX2C4, e riportata sul suo blog al link <a href="http://blog.zx2c4.com/749" rel="nofollow">http://blog.zx2c4.com/749</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux root exploit due to memory access &#8211; Update 2 &#124; Matias Vangsnes</title>
		<link>http://blog.zx2c4.com/749#comment-6456</link>
		<dc:creator>Linux root exploit due to memory access &#8211; Update 2 &#124; Matias Vangsnes</dc:creator>
		<pubDate>Mon, 23 Jan 2012 19:16:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6456</guid>
		<description>[...] inadequate and could be easily fooled.Shortly after the publication of an explanatory article on Nerdling Sapple, other coders used the information contained in the article to create exploits and made them [...]</description>
		<content:encoded><![CDATA[<p>[...] inadequate and could be easily fooled.Shortly after the publication of an explanatory article on Nerdling Sapple, other coders used the information contained in the article to create exploits and made them [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Jason Donenfeld</title>
		<link>http://blog.zx2c4.com/749#comment-6455</link>
		<dc:creator>Jason Donenfeld</dc:creator>
		<pubDate>Mon, 23 Jan 2012 18:36:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6455</guid>
		<description>This version works on Fedora: http://git.zx2c4.com/CVE-2012-0056/tree/mempodipper.c?h=fedora</description>
		<content:encoded><![CDATA[<p>This version works on Fedora: <a href="http://git.zx2c4.com/CVE-2012-0056/tree/mempodipper.c?h=fedora" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/git.zx2c4.com/CVE-2012-0056/tree/mempodipper.c?h=fedora&amp;referer=');">http://git.zx2c4.com/CVE-2012-0056/tree/mempodipper.c?h=fedora</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by explicit</title>
		<link>http://blog.zx2c4.com/749#comment-6454</link>
		<dc:creator>explicit</dc:creator>
		<pubDate>Mon, 23 Jan 2012 18:19:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6454</guid>
		<description>Won&#039;t work on f16, with or without selinux.</description>
		<content:encoded><![CDATA[<p>Won&#8217;t work on f16, with or without selinux.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by В ядре Linux найдена локальная root-уязвимость&#160;&#124;&#160;AllUNIX.ru &#8212; Всероссийский портал о UNIX-системах</title>
		<link>http://blog.zx2c4.com/749#comment-6453</link>
		<dc:creator>В ядре Linux найдена локальная root-уязвимость&#160;&#124;&#160;AllUNIX.ru &#8212; Всероссийский портал о UNIX-системах</dc:creator>
		<pubDate>Mon, 23 Jan 2012 17:31:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6453</guid>
		<description>[...] ядре Linux найдена опасная уязвимость, позволяющая локальному злоумышленнику выполнить код [...]</description>
		<content:encoded><![CDATA[<p>[...] ядре Linux найдена опасная уязвимость, позволяющая локальному злоумышленнику выполнить код [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by anonymous</title>
		<link>http://blog.zx2c4.com/749#comment-6452</link>
		<dc:creator>anonymous</dc:creator>
		<pubDate>Mon, 23 Jan 2012 15:42:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6452</guid>
		<description>actually, this is really old news, it was covered in a talk at WHAT THE HACK in 2005: http://web.archive.org/web/20080724225443/http://wiki.whatthehack.org/index.php/The_/proc/pid/mem_problem</description>
		<content:encoded><![CDATA[<p>actually, this is really old news, it was covered in a talk at WHAT THE HACK in 2005: <a href="http://web.archive.org/web/20080724225443/http://wiki.whatthehack.org/index.php/The_/proc/pid/mem_problem" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/web.archive.org/web/20080724225443/http_//wiki.whatthehack.org/index.php/The_/proc/pid/mem_problem?referer=');">http://web.archive.org/web/20080724225443/http://wiki.whatthehack.org/index.php/The_/proc/pid/mem_problem</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by __sporkbomb</title>
		<link>http://blog.zx2c4.com/749#comment-6451</link>
		<dc:creator>__sporkbomb</dc:creator>
		<pubDate>Mon, 23 Jan 2012 15:30:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6451</guid>
		<description>Ah, true, that&#039;s a pretty neat way of handling it.</description>
		<content:encoded><![CDATA[<p>Ah, true, that&#8217;s a pretty neat way of handling it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Jeff Schroeder</title>
		<link>http://blog.zx2c4.com/749#comment-6450</link>
		<dc:creator>Jeff Schroeder</dc:creator>
		<pubDate>Mon, 23 Jan 2012 15:30:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6450</guid>
		<description>I&#039;m curious to know if SELinux in Fedora blocks this.</description>
		<content:encoded><![CDATA[<p>I&#8217;m curious to know if SELinux in Fedora blocks this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Jason Donenfeld</title>
		<link>http://blog.zx2c4.com/749#comment-6449</link>
		<dc:creator>Jason Donenfeld</dc:creator>
		<pubDate>Mon, 23 Jan 2012 14:40:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6449</guid>
		<description>That&#039;s a good one-liner. The thing is, I think there&#039;s still a way to determine the offset without having read access to the binary. Check out the discussion between sd and I on full-disclosure.</description>
		<content:encoded><![CDATA[<p>That&#8217;s a good one-liner. The thing is, I think there&#8217;s still a way to determine the offset without having read access to the binary. Check out the discussion between sd and I on full-disclosure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by __sporkbomb</title>
		<link>http://blog.zx2c4.com/749#comment-6447</link>
		<dc:creator>__sporkbomb</dc:creator>
		<pubDate>Mon, 23 Jan 2012 14:38:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6447</guid>
		<description>Just a short piece of advice:
Some distributions are not directly vulnerable to the exploit, as it needs read permission on /bin/su. One example is Gentoo - its sys-apps/shadow package, which owns /bin/su, sets 4711 (i.e. o-r) on the executables it installs.

BUT if you&#039;re running a vulnerable kernel version and want to test it, here&#039;s a short snippet for you:

for p in $(echo $PATH &#124; tr &#039;:&#039; &#039; &#039;); do find &quot;$p&quot; -perm -4005; done

Which will print all SUID executables in $PATH that are both readable and executable by all users.
Now you have a list of potentially vulnerable executables. You still need to see if that binary will print user input as-is. If it does, congratulations, the easy part is done.
The next step is to adapt the exploit to that executable. As we say in academia, &quot;left as an exercise to the reader&quot; ;)</description>
		<content:encoded><![CDATA[<p>Just a short piece of advice:<br />
Some distributions are not directly vulnerable to the exploit, as it needs read permission on /bin/su. One example is Gentoo &#8211; its sys-apps/shadow package, which owns /bin/su, sets 4711 (i.e. o-r) on the executables it installs.</p>
<p>BUT if you&#8217;re running a vulnerable kernel version and want to test it, here&#8217;s a short snippet for you:</p>
<p>for p in $(echo $PATH | tr &#8216;:&#8217; &#8216; &#8216;); do find &#8220;$p&#8221; -perm -4005; done</p>
<p>Which will print all SUID executables in $PATH that are both readable and executable by all users.<br />
Now you have a list of potentially vulnerable executables. You still need to see if that binary will print user input as-is. If it does, congratulations, the easy part is done.<br />
The next step is to adapt the exploit to that executable. As we say in academia, &#8220;left as an exercise to the reader&#8221; <img src='http://blog.zx2c4.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Kill</title>
		<link>http://blog.zx2c4.com/749#comment-6444</link>
		<dc:creator>Kill</dc:creator>
		<pubDate>Mon, 23 Jan 2012 12:46:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6444</guid>
		<description>sh-3.2$ ./exp
[+] Opening parent mem /proc/26524/mem in child.
[+] Sending fd 6 to parent.
su: must be run from a terminal

and

sh-3.00$ gcc mempodipper.c -o exp
sh-3.00$ ./exp
[+] Opening parent mem /proc/27364/mem in child.
[+] Sending fd 330 to parent.
sh-3.00$ id
uid=48(apache) gid=48(apache) groups=48(apache),99(nobody)

=\</description>
		<content:encoded><![CDATA[<p>sh-3.2$ ./exp<br />
[+] Opening parent mem /proc/26524/mem in child.<br />
[+] Sending fd 6 to parent.<br />
su: must be run from a terminal</p>
<p>and</p>
<p>sh-3.00$ gcc mempodipper.c -o exp<br />
sh-3.00$ ./exp<br />
[+] Opening parent mem /proc/27364/mem in child.<br />
[+] Sending fd 330 to parent.<br />
sh-3.00$ id<br />
uid=48(apache) gid=48(apache) groups=48(apache),99(nobody)</p>
<p>=\</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Jason</title>
		<link>http://blog.zx2c4.com/749#comment-6443</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Mon, 23 Jan 2012 12:22:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6443</guid>
		<description>Awesome. So yea -- even on fairly &quot;hardened&quot; systems, there&#039;s probably going to be one suid executable that spits out arbitrary info on stdout or stderr that isn&#039;t compiled with PIE.</description>
		<content:encoded><![CDATA[<p>Awesome. So yea &#8212; even on fairly &#8220;hardened&#8221; systems, there&#8217;s probably going to be one suid executable that spits out arbitrary info on stdout or stderr that isn&#8217;t compiled with PIE.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Jason</title>
		<link>http://blog.zx2c4.com/749#comment-6442</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Mon, 23 Jan 2012 12:22:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6442</guid>
		<description>http://git.zx2c4.com/CVE-2012-0056/commit/?id=5714b07049b0e401b20bbce383c663d131911066

Did I do it right?</description>
		<content:encoded><![CDATA[<p><a href="http://git.zx2c4.com/CVE-2012-0056/commit/?id=5714b07049b0e401b20bbce383c663d131911066" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/git.zx2c4.com/CVE-2012-0056/commit/?id=5714b07049b0e401b20bbce383c663d131911066&amp;referer=');">http://git.zx2c4.com/CVE-2012-0056/commit/?id=5714b07049b0e401b20bbce383c663d131911066</a></p>
<p>Did I do it right?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Luca</title>
		<link>http://blog.zx2c4.com/749#comment-6440</link>
		<dc:creator>Luca</dc:creator>
		<pubDate>Mon, 23 Jan 2012 12:20:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6440</guid>
		<description>openSuse 12.1 is not vulnerable via su, however you can do the same exploit with the /bin/eject binary.</description>
		<content:encoded><![CDATA[<p>openSuse 12.1 is not vulnerable via su, however you can do the same exploit with the /bin/eject binary.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on KDE Doesn&#8217;t Suck Anymore, People Finally Realize by Masud</title>
		<link>http://blog.zx2c4.com/726#comment-6438</link>
		<dc:creator>Masud</dc:creator>
		<pubDate>Mon, 23 Jan 2012 11:55:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=726#comment-6438</guid>
		<description>I recently abandoned GNOME because of Unity, I absolutely hated it. I then tried the classic version of GNOME which seemed fairly broken on Ubuntu 11.10. I tried KDE and was quite surprised to see how good it has become. However, for a person who hasn&#039;t used KDE for years now, I found it rather cumbersome. A lot of things were hidden behind a beautiful interface. I personally like clean simple interfaces. I tried Xfce 4.8 and have not gone back to either GNOME or KDE since then.

I guess it is a personal choice at the end of the day, but I do acknowledge that KDE has come bounds and leaps since its early days.</description>
		<content:encoded><![CDATA[<p>I recently abandoned GNOME because of Unity, I absolutely hated it. I then tried the classic version of GNOME which seemed fairly broken on Ubuntu 11.10. I tried KDE and was quite surprised to see how good it has become. However, for a person who hasn&#8217;t used KDE for years now, I found it rather cumbersome. A lot of things were hidden behind a beautiful interface. I personally like clean simple interfaces. I tried Xfce 4.8 and have not gone back to either GNOME or KDE since then.</p>
<p>I guess it is a personal choice at the end of the day, but I do acknowledge that KDE has come bounds and leaps since its early days.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Jason</title>
		<link>http://blog.zx2c4.com/749#comment-6437</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Mon, 23 Jan 2012 11:54:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6437</guid>
		<description>AWESOME! Thanks a lot. Updating the source now.</description>
		<content:encoded><![CDATA[<p>AWESOME! Thanks a lot. Updating the source now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Raghavendra Prabhu</title>
		<link>http://blog.zx2c4.com/749#comment-6436</link>
		<dc:creator>Raghavendra Prabhu</dc:creator>
		<pubDate>Mon, 23 Jan 2012 11:43:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6436</guid>
		<description>As followup and right offset (with -o) from someone else, it worked. 

I guess it depends on calculating the right offset which the C prgrm was not calculating correctly.</description>
		<content:encoded><![CDATA[<p>As followup and right offset (with -o) from someone else, it worked. </p>
<p>I guess it depends on calculating the right offset which the C prgrm was not calculating correctly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Raghavendra Prabhu</title>
		<link>http://blog.zx2c4.com/749#comment-6435</link>
		<dc:creator>Raghavendra Prabhu</dc:creator>
		<pubDate>Mon, 23 Jan 2012 11:35:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6435</guid>
		<description>Doesn&#039;t work for me.

Running it as mentioned in site causes it to segfault

Then someone mentioned to give right offset . I get a shell but no privilege escalation either

I also disabled all CFLAGS related to stack protection etc and built it and tried again -- doesn&#039;t work

This is with a kernel built on Jan 5th (self built but also tested on Arch distro kernel) 

and 

su from 

==========================
su --version                                                                                                                                                                                                                                      
su (GNU coreutils) 8.15
Copyright (C) 2012 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later .
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.

Written by David MacKenzie
=================================</description>
		<content:encoded><![CDATA[<p>Doesn&#8217;t work for me.</p>
<p>Running it as mentioned in site causes it to segfault</p>
<p>Then someone mentioned to give right offset . I get a shell but no privilege escalation either</p>
<p>I also disabled all CFLAGS related to stack protection etc and built it and tried again &#8212; doesn&#8217;t work</p>
<p>This is with a kernel built on Jan 5th (self built but also tested on Arch distro kernel) </p>
<p>and </p>
<p>su from </p>
<p>==========================<br />
su &#8211;version<br />
su (GNU coreutils) 8.15<br />
Copyright (C) 2012 Free Software Foundation, Inc.<br />
License GPLv3+: GNU GPL version 3 or later .<br />
This is free software: you are free to change and redistribute it.<br />
There is NO WARRANTY, to the extent permitted by law.</p>
<p>Written by David MacKenzie<br />
=================================</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by How do I check my Linux kernel against root exploits? &#124; web technical support</title>
		<link>http://blog.zx2c4.com/749#comment-6434</link>
		<dc:creator>How do I check my Linux kernel against root exploits? &#124; web technical support</dc:creator>
		<pubDate>Mon, 23 Jan 2012 11:19:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6434</guid>
		<description>[...] example, today this exploit came out: http://blog.zx2c4.com/749 Debian 6 (2.6.32) isn&#8217;t vulnerable. Ubuntu 10.04 (2.6.32) isn&#8217;t vulnerable. But one of [...]</description>
		<content:encoded><![CDATA[<p>[...] example, today this exploit came out: <a href="http://blog.zx2c4.com/749" rel="nofollow">http://blog.zx2c4.com/749</a> Debian 6 (2.6.32) isn&#8217;t vulnerable. Ubuntu 10.04 (2.6.32) isn&#8217;t vulnerable. But one of [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Boris</title>
		<link>http://blog.zx2c4.com/749#comment-6432</link>
		<dc:creator>Boris</dc:creator>
		<pubDate>Mon, 23 Jan 2012 11:10:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6432</guid>
		<description>3.0.0-14-generic-pae #23-Ubuntu SMP Mon Nov 21 22:07:10 UTC 2011 i686 i686 i386 GNU/Linux

Works... crap...</description>
		<content:encoded><![CDATA[<p>3.0.0-14-generic-pae #23-Ubuntu SMP Mon Nov 21 22:07:10 UTC 2011 i686 i686 i386 GNU/Linux</p>
<p>Works&#8230; crap&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by ⬡</title>
		<link>http://blog.zx2c4.com/749#comment-6431</link>
		<dc:creator>⬡</dc:creator>
		<pubDate>Mon, 23 Jan 2012 10:38:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6431</guid>
		<description>Hm, doesn&#039;t seem to work for me. Same output, but no shell, no escalation.</description>
		<content:encoded><![CDATA[<p>Hm, doesn&#8217;t seem to work for me. Same output, but no shell, no escalation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Kines</title>
		<link>http://blog.zx2c4.com/749#comment-6429</link>
		<dc:creator>Kines</dc:creator>
		<pubDate>Mon, 23 Jan 2012 09:45:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6429</guid>
		<description>su: must be run from a terminal
=(</description>
		<content:encoded><![CDATA[<p>su: must be run from a terminal<br />
=(</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Tom</title>
		<link>http://blog.zx2c4.com/749#comment-6428</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Mon, 23 Jan 2012 09:36:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6428</guid>
		<description>Thank you for the great article. Since I am not really familiar with linux system programming I did not understand all of it. Anyway, I was curious enough to give your exploit a try on my own machine (openSuse12.1, 64bit), without success. 
According to your article it seems that openSuse12.1 has compiled su with PIE:
&gt; readelf -h /bin/su &#124; grep Type
&gt; Type:                              DYN (Shared object file)</description>
		<content:encoded><![CDATA[<p>Thank you for the great article. Since I am not really familiar with linux system programming I did not understand all of it. Anyway, I was curious enough to give your exploit a try on my own machine (openSuse12.1, 64bit), without success.<br />
According to your article it seems that openSuse12.1 has compiled su with PIE:<br />
&gt; readelf -h /bin/su | grep Type<br />
&gt; Type:                              DYN (Shared object file)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Nobody</title>
		<link>http://blog.zx2c4.com/749#comment-6427</link>
		<dc:creator>Nobody</dc:creator>
		<pubDate>Mon, 23 Jan 2012 09:33:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6427</guid>
		<description>Thank you for this article, great job.</description>
		<content:encoded><![CDATA[<p>Thank you for this article, great job.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#8230; &#124; What is Linux</title>
		<link>http://blog.zx2c4.com/749#comment-6425</link>
		<dc:creator>Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#8230; &#124; What is Linux</dc:creator>
		<pubDate>Mon, 23 Jan 2012 08:45:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6425</guid>
		<description>[...] excerpt from: Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#8230; Be Sociable, Share!           Tweet(function() {var s = document.createElement(&#039;SCRIPT&#039;), s1 = [...]</description>
		<content:encoded><![CDATA[<p>[...] excerpt from: Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#8230; Be Sociable, Share!           Tweet(function() {var s = document.createElement(&#039;SCRIPT&#039;), s1 = [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Franklin</title>
		<link>http://blog.zx2c4.com/749#comment-6423</link>
		<dc:creator>Franklin</dc:creator>
		<pubDate>Mon, 23 Jan 2012 07:51:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6423</guid>
		<description>Thanks for the article. I am very interested in knowing how you did find this bug !
Thanks,

F.</description>
		<content:encoded><![CDATA[<p>Thanks for the article. I am very interested in knowing how you did find this bug !<br />
Thanks,</p>
<p>F.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by caf</title>
		<link>http://blog.zx2c4.com/749#comment-6422</link>
		<dc:creator>caf</dc:creator>
		<pubDate>Mon, 23 Jan 2012 06:18:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6422</guid>
		<description>Agreed, that is why I said &quot;(which of course does not affect this exploit)&quot;.

My quick experiment seems to indicate that you could wrap self_exec_id in days or hours, which is certainly viable if there are any other uses of this value for security purposes.</description>
		<content:encoded><![CDATA[<p>Agreed, that is why I said &#8220;(which of course does not affect this exploit)&#8221;.</p>
<p>My quick experiment seems to indicate that you could wrap self_exec_id in days or hours, which is certainly viable if there are any other uses of this value for security purposes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Kees Cook</title>
		<link>http://blog.zx2c4.com/749#comment-6421</link>
		<dc:creator>Kees Cook</dc:creator>
		<pubDate>Mon, 23 Jan 2012 05:40:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6421</guid>
		<description>Instead of leaving a AF_UNIX socket on the filesystem, you can use socketpair() to create a AF_LOCAL socket between parent and child (like pipe()).</description>
		<content:encoded><![CDATA[<p>Instead of leaving a AF_UNIX socket on the filesystem, you can use socketpair() to create a AF_LOCAL socket between parent and child (like pipe()).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Jason Donenfeld</title>
		<link>http://blog.zx2c4.com/749#comment-6420</link>
		<dc:creator>Jason Donenfeld</dc:creator>
		<pubDate>Mon, 23 Jan 2012 05:24:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6420</guid>
		<description>You&#039;re missing the point -- if we try to open a mem of a process we create before execing to suid, then the 600 perms apply to us, and so there are no restrictions for us to beat when opening. But yea, you&#039;re right; post updated to be less ambiguous.

Yea -- this was my first idea too, that it could wrap around. Unfortunately, 32bits is big, and exec is a (comparatively) slow system call, so I think it&#039;d take wayyy too long.</description>
		<content:encoded><![CDATA[<p>You&#8217;re missing the point &#8212; if we try to open a mem of a process we create before execing to suid, then the 600 perms apply to us, and so there are no restrictions for us to beat when opening. But yea, you&#8217;re right; post updated to be less ambiguous.</p>
<p>Yea &#8212; this was my first idea too, that it could wrap around. Unfortunately, 32bits is big, and exec is a (comparatively) slow system call, so I think it&#8217;d take wayyy too long.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by caf</title>
		<link>http://blog.zx2c4.com/749#comment-6419</link>
		<dc:creator>caf</dc:creator>
		<pubDate>Mon, 23 Jan 2012 05:16:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6419</guid>
		<description>It&#039;s not quite accurate to say that &quot;There are no restrictions on opening&quot; - the normal VFS permissions are still applied, and the /proc//mem file has 0600 permissions.  This means that you can only open the /proc//mem files for processes running under the same UID (which of course does not affect this exploit).

I note that the self_exec_id is only an unsigned 32 bit type - I wonder if it would also be possible to repeatedly exec() 4 billion times until you wrap back around to the original value?</description>
		<content:encoded><![CDATA[<p>It&#8217;s not quite accurate to say that &#8220;There are no restrictions on opening&#8221; &#8211; the normal VFS permissions are still applied, and the /proc//mem file has 0600 permissions.  This means that you can only open the /proc//mem files for processes running under the same UID (which of course does not affect this exploit).</p>
<p>I note that the self_exec_id is only an unsigned 32 bit type &#8211; I wonder if it would also be possible to repeatedly exec() 4 billion times until you wrap back around to the original value?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux Local Root &#8212; CVE-2012-0056 &#8212; Detailed Write-up &#124; THIS IS TRUXST</title>
		<link>http://blog.zx2c4.com/749#comment-6418</link>
		<dc:creator>Linux Local Root &#8212; CVE-2012-0056 &#8212; Detailed Write-up &#124; THIS IS TRUXST</dc:creator>
		<pubDate>Mon, 23 Jan 2012 05:08:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6418</guid>
		<description>[...] write up is available on my blog here: http://blog.zx2c4.com/749 . [...]</description>
		<content:encoded><![CDATA[<p>[...] write up is available on my blog here: <a href="http://blog.zx2c4.com/749" rel="nofollow">http://blog.zx2c4.com/749</a> . [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by ipv</title>
		<link>http://blog.zx2c4.com/749#comment-6416</link>
		<dc:creator>ipv</dc:creator>
		<pubDate>Mon, 23 Jan 2012 01:58:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6416</guid>
		<description>Great article, and exploit is well written, congrats :)</description>
		<content:encoded><![CDATA[<p>Great article, and exploit is well written, congrats <img src='http://blog.zx2c4.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on KDE Doesn&#8217;t Suck Anymore, People Finally Realize by boooger</title>
		<link>http://blog.zx2c4.com/726#comment-6408</link>
		<dc:creator>boooger</dc:creator>
		<pubDate>Tue, 17 Jan 2012 09:11:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=726#comment-6408</guid>
		<description>rant
Why does Akonadi IMAP have to suck *so* badly. It literally eats camel turds and does not much else. It&#039;s ruined Kmail. I cannot use KDE&#039;s PIM anymore. I may as well through the whole thing out. Yes, I really think that way - even before you mentioned it. One thing I have to say is that *some* of the KDE devs are really social morons. I am a social moron as well. But I think I could show some remorse when I realized I fucked all my users over.
/rant</description>
		<content:encoded><![CDATA[<p>rant<br />
Why does Akonadi IMAP have to suck *so* badly. It literally eats camel turds and does not much else. It&#8217;s ruined Kmail. I cannot use KDE&#8217;s PIM anymore. I may as well through the whole thing out. Yes, I really think that way &#8211; even before you mentioned it. One thing I have to say is that *some* of the KDE devs are really social morons. I am a social moron as well. But I think I could show some remorse when I realized I fucked all my users over.<br />
/rant</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Finding Freelance Jobs by Druckerzuebehoer</title>
		<link>http://blog.zx2c4.com/118#comment-6387</link>
		<dc:creator>Druckerzuebehoer</dc:creator>
		<pubDate>Mon, 09 Jan 2012 20:53:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=118#comment-6387</guid>
		<description>Great ides with a blog article to advertise against a known problem, the &quot;no experience in worklife&quot; problem many people have.</description>
		<content:encoded><![CDATA[<p>Great ides with a blog article to advertise against a known problem, the &#8220;no experience in worklife&#8221; problem many people have.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trying to Leave Catch-All E-Mail Behind by David</title>
		<link>http://blog.zx2c4.com/261#comment-6361</link>
		<dc:creator>David</dc:creator>
		<pubDate>Sun, 01 Jan 2012 12:48:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=261#comment-6361</guid>
		<description>Josh,

The following my be helpful.

I actually went through switching over about a year ago. I thought about it for a few 
years and then made the change. I wanted a shorter email and the first domain I had and 
a handful of accounts I tried to sign up for would not recognize the .info extention 
as valid. In addition the first first domain I use was actually quite long.

For your question on what would be a good new domain, you may want to try a
domain search form to find a domain name with your initials
or some other letter combination that makes sense to you. For example I used one to
find a domain with my two initials seperated by the letter n and a number at the end.
This shorter domain is much easier to type in all the time than the other one I used.

After I decided to make the switch I didn&#039;t just switch right away.
It actually took me about a year and half. After creating the second account
and changing all the accounts over that I kept track of I ran both catch all 
emails for about a year and a half. This way I made sure I didn&#039;t miss anything. 

Hope that helps. Stay safe.

David
$.02</description>
		<content:encoded><![CDATA[<p>Josh,</p>
<p>The following my be helpful.</p>
<p>I actually went through switching over about a year ago. I thought about it for a few<br />
years and then made the change. I wanted a shorter email and the first domain I had and<br />
a handful of accounts I tried to sign up for would not recognize the .info extention<br />
as valid. In addition the first first domain I use was actually quite long.</p>
<p>For your question on what would be a good new domain, you may want to try a<br />
domain search form to find a domain name with your initials<br />
or some other letter combination that makes sense to you. For example I used one to<br />
find a domain with my two initials seperated by the letter n and a number at the end.<br />
This shorter domain is much easier to type in all the time than the other one I used.</p>
<p>After I decided to make the switch I didn&#8217;t just switch right away.<br />
It actually took me about a year and half. After creating the second account<br />
and changing all the accounts over that I kept track of I ran both catch all<br />
emails for about a year and a half. This way I made sure I didn&#8217;t miss anything. </p>
<p>Hope that helps. Stay safe.</p>
<p>David<br />
$.02</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on KDE Doesn&#8217;t Suck Anymore, People Finally Realize by Mitch</title>
		<link>http://blog.zx2c4.com/726#comment-6343</link>
		<dc:creator>Mitch</dc:creator>
		<pubDate>Mon, 26 Dec 2011 04:22:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=726#comment-6343</guid>
		<description>The application that didn&#039;t work out of the box for me was digikam, which frankly is one of the really great things about KDE.

(One thing that is missing from this thread is the discussion of the applications in KDE, which is really what I like so much about it.  Amarok was - and is again - an music player that is better than anything you&#039;ll find on Mac or Windows - and digikam is brilliant as well.)

I have never used any of the mail, calendar, or contact applications, so maybe I have avoided the problems.  I have had some mixed results with OpenOffice but that&#039;s not part of KDE per se.</description>
		<content:encoded><![CDATA[<p>The application that didn&#8217;t work out of the box for me was digikam, which frankly is one of the really great things about KDE.</p>
<p>(One thing that is missing from this thread is the discussion of the applications in KDE, which is really what I like so much about it.  Amarok was &#8211; and is again &#8211; an music player that is better than anything you&#8217;ll find on Mac or Windows &#8211; and digikam is brilliant as well.)</p>
<p>I have never used any of the mail, calendar, or contact applications, so maybe I have avoided the problems.  I have had some mixed results with OpenOffice but that&#8217;s not part of KDE per se.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

