<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Nerdling Sapple</title>
	<atom:link href="http://blog.zx2c4.com/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.zx2c4.com</link>
	<description>{{{ ZX2C4 }}}</description>
	<lastBuildDate>Sat, 12 May 2012 12:43:36 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by harrouz</title>
		<link>http://blog.zx2c4.com/749#comment-6780</link>
		<dc:creator>harrouz</dc:creator>
		<pubDate>Sat, 12 May 2012 12:43:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6780</guid>
		<description>sys/types.h: not file or directory</description>
		<content:encoded><![CDATA[<p>sys/types.h: not file or directory</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by harrouz</title>
		<link>http://blog.zx2c4.com/749#comment-6779</link>
		<dc:creator>harrouz</dc:creator>
		<pubDate>Sat, 12 May 2012 11:27:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6779</guid>
		<description>please how to install lib  sys/types.h  in linux</description>
		<content:encoded><![CDATA[<p>please how to install lib  sys/types.h  in linux</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by harrouz</title>
		<link>http://blog.zx2c4.com/749#comment-6778</link>
		<dc:creator>harrouz</dc:creator>
		<pubDate>Sat, 12 May 2012 11:25:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6778</guid>
		<description>please how to install lib for  in linux</description>
		<content:encoded><![CDATA[<p>please how to install lib for  in linux</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by alex</title>
		<link>http://blog.zx2c4.com/749#comment-6777</link>
		<dc:creator>alex</dc:creator>
		<pubDate>Fri, 11 May 2012 03:20:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6777</guid>
		<description>Linux vu 2.6.38-10-server #46-Ubuntu SMP Tue Jun 28 16:31:00 UTC 2011 x86_64 x86_64 x86_64 GNU/Linux


$ ./mempodipper
[+] Opening parent mem /proc/17231/mem in child.
[+] Sending fd 5 to parent.
$


hi .. what i have done wrong ?</description>
		<content:encoded><![CDATA[<p>Linux vu 2.6.38-10-server #46-Ubuntu SMP Tue Jun 28 16:31:00 UTC 2011 x86_64 x86_64 x86_64 GNU/Linux</p>
<p>$ ./mempodipper<br />
[+] Opening parent mem /proc/17231/mem in child.<br />
[+] Sending fd 5 to parent.<br />
$</p>
<p>hi .. what i have done wrong ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Luddite Seeks Futuristic Phone by tandblekninng med laser</title>
		<link>http://blog.zx2c4.com/614#comment-6776</link>
		<dc:creator>tandblekninng med laser</dc:creator>
		<pubDate>Fri, 11 May 2012 00:41:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=614#comment-6776</guid>
		<description>&lt;strong&gt;tandblekninng med laser...&lt;/strong&gt;

[...]w I have realized that online diploma is getting favorite because obtaining y 9l[...]...</description>
		<content:encoded><![CDATA[<p><strong>tandblekninng med laser&#8230;</strong></p>
<p>[...]w I have realized that online diploma is getting favorite because obtaining y 9l[...]&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Luddite Seeks Futuristic Phone by tandblekninng med laser</title>
		<link>http://blog.zx2c4.com/614#comment-6775</link>
		<dc:creator>tandblekninng med laser</dc:creator>
		<pubDate>Wed, 09 May 2012 23:11:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=614#comment-6775</guid>
		<description>&lt;strong&gt;tandblekninng med laser...&lt;/strong&gt;

[...]w I got what you plan, thanks for putting up. Woh I am glad to learn this web rh[...]...</description>
		<content:encoded><![CDATA[<p><strong>tandblekninng med laser&#8230;</strong></p>
<p>[...]w I got what you plan, thanks for putting up. Woh I am glad to learn this web rh[...]&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on KDE Doesn&#8217;t Suck Anymore, People Finally Realize by Doppelsonnenuhr</title>
		<link>http://blog.zx2c4.com/726#comment-6774</link>
		<dc:creator>Doppelsonnenuhr</dc:creator>
		<pubDate>Tue, 01 May 2012 03:32:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=726#comment-6774</guid>
		<description>I don&#039;t really know what the fuss is all about. I disabled Akonadi and Nepomuk on my old, slower Kubuntu  laptop. It works fine.

I&#039;ve left them running on my newer, faster laptop. It runs SuSE 12.1 - it also works fine.

And, KDE is beautiful.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t really know what the fuss is all about. I disabled Akonadi and Nepomuk on my old, slower Kubuntu  laptop. It works fine.</p>
<p>I&#8217;ve left them running on my newer, faster laptop. It runs SuSE 12.1 &#8211; it also works fine.</p>
<p>And, KDE is beautiful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by CVE-2012-0056linux提权漏洞分析 &#124; bugcx&#039;s blog &#124; 关注网络安全</title>
		<link>http://blog.zx2c4.com/749#comment-6772</link>
		<dc:creator>CVE-2012-0056linux提权漏洞分析 &#124; bugcx&#039;s blog &#124; 关注网络安全</dc:creator>
		<pubDate>Thu, 26 Apr 2012 09:10:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6772</guid>
		<description>[...] 原文链接：http://blog.zx2c4.com/749 [...]</description>
		<content:encoded><![CDATA[<p>[...] 原文链接：http://blog.zx2c4.com/749 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Debian &#8211; Ubuntu: ecco un fix per il commit CVE-2012-0056 (bug Kernel in /proc/pid/mem) - The Silicon Jey</title>
		<link>http://blog.zx2c4.com/749#comment-6769</link>
		<dc:creator>Debian &#8211; Ubuntu: ecco un fix per il commit CVE-2012-0056 (bug Kernel in /proc/pid/mem) - The Silicon Jey</dc:creator>
		<pubDate>Sun, 22 Apr 2012 15:09:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6769</guid>
		<description>[...] vi ho parlato in maniera piuttosto esaustiva di questo bug, e vi ho lasciato anche l&#8217;indirizzo a cui trovare l&#8217;exploit costruito ad hoc. Oggi voglio suggerire un piccolo workaround per Debian, Ubuntu e [...]</description>
		<content:encoded><![CDATA[<p>[...] vi ho parlato in maniera piuttosto esaustiva di questo bug, e vi ho lasciato anche l&#8217;indirizzo a cui trovare l&#8217;exploit costruito ad hoc. Oggi voglio suggerire un piccolo workaround per Debian, Ubuntu e [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Falla nel kernel linux &#124; ReefBits.net</title>
		<link>http://blog.zx2c4.com/749#comment-6768</link>
		<dc:creator>Falla nel kernel linux &#124; ReefBits.net</dc:creator>
		<pubDate>Sun, 22 Apr 2012 11:04:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6768</guid>
		<description>[...] mai ci si è fallato il kernel? Il signor ZX2C4 ci fa sapere che questa falla è dovuta al fatto che a partire dalla versione 2.6.39 (quindi anche tutte quelle [...]</description>
		<content:encoded><![CDATA[<p>[...] mai ci si è fallato il kernel? Il signor ZX2C4 ci fa sapere che questa falla è dovuta al fatto che a partire dalla versione 2.6.39 (quindi anche tutte quelle [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by thomas</title>
		<link>http://blog.zx2c4.com/749#comment-6759</link>
		<dc:creator>thomas</dc:creator>
		<pubDate>Wed, 11 Apr 2012 07:53:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6759</guid>
		<description>Now, I solved the problem before. But I tried &quot;/bin/su&quot; and &quot;gpasswd&quot; both, when I strace the execution, it shows that &quot;execve () = -1 EPERM (Operation not permitted)&quot;
Can somebody tell why?</description>
		<content:encoded><![CDATA[<p>Now, I solved the problem before. But I tried &#8220;/bin/su&#8221; and &#8220;gpasswd&#8221; both, when I strace the execution, it shows that &#8220;execve () = -1 EPERM (Operation not permitted)&#8221;<br />
Can somebody tell why?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by thomas</title>
		<link>http://blog.zx2c4.com/749#comment-6758</link>
		<dc:creator>thomas</dc:creator>
		<pubDate>Wed, 11 Apr 2012 03:01:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6758</guid>
		<description>Hi~ 
I tried this on my Linux， but it blocked in step “Executing su with shellcode”. Then I straced the execution and found that &quot;read(3, 0x7fff5a0709cf, 1) = -1 EAGAIN (Resource temporarily unavailable)
ptrace(PTRACE_SYSCALL, 22373, 0, SIG_0) = 0&quot;
Can you tell me why cause this?  Thanks.
kernel :2.6.32</description>
		<content:encoded><![CDATA[<p>Hi~<br />
I tried this on my Linux， but it blocked in step “Executing su with shellcode”. Then I straced the execution and found that &#8220;read(3, 0x7fff5a0709cf, 1) = -1 EAGAIN (Resource temporarily unavailable)<br />
ptrace(PTRACE_SYSCALL, 22373, 0, SIG_0) = 0&#8243;<br />
Can you tell me why cause this?  Thanks.<br />
kernel :2.6.32</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Rooten - Seite 2 - Android-Hilfe.de</title>
		<link>http://blog.zx2c4.com/749#comment-6753</link>
		<dc:creator>Rooten - Seite 2 - Android-Hilfe.de</dc:creator>
		<pubDate>Wed, 04 Apr 2012 11:23:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6753</guid>
		<description>[...]  [...]</description>
		<content:encoded><![CDATA[<p>[...]  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Need to Upgrade Kernel -- No Internet Access</title>
		<link>http://blog.zx2c4.com/749#comment-6752</link>
		<dc:creator>Need to Upgrade Kernel -- No Internet Access</dc:creator>
		<pubDate>Tue, 03 Apr 2012 12:54:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6752</guid>
		<description>[...] supporting Intel wireless adapters changes: in 3.0 it&#039;s iwlagn, in 3.1 it seems to be iwlcore (but don&#039;t use 3.1), and in 3.2 onwards it&#039;s iwlwifi. There are known problems with Intel Wireless-N adapters in 3.2 [...]</description>
		<content:encoded><![CDATA[<p>[...] supporting Intel wireless adapters changes: in 3.0 it&#039;s iwlagn, in 3.1 it seems to be iwlcore (but don&#039;t use 3.1), and in 3.2 onwards it&#039;s iwlwifi. There are known problems with Intel Wireless-N adapters in 3.2 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by A good reason to stay away from Linux, or upgrade existing systems &#171; &#171; Rage Against The Mushin Rage Against The Mushin</title>
		<link>http://blog.zx2c4.com/749#comment-6745</link>
		<dc:creator>A good reason to stay away from Linux, or upgrade existing systems &#171; &#171; Rage Against The Mushin Rage Against The Mushin</dc:creator>
		<pubDate>Wed, 21 Mar 2012 22:19:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6745</guid>
		<description>[...] http://blog.zx2c4.com/749 [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://blog.zx2c4.com/749" rel="nofollow">http://blog.zx2c4.com/749</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Stripe&#8217;s Capture the Flag &#8212; Solutions by Run your own CTF: Stripe publishes VM images &#124; Ameya Karve&#039;s Weblog</title>
		<link>http://blog.zx2c4.com/781#comment-6744</link>
		<dc:creator>Run your own CTF: Stripe publishes VM images &#124; Ameya Karve&#039;s Weblog</dc:creator>
		<pubDate>Tue, 20 Mar 2012 22:11:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=781#comment-6744</guid>
		<description>[...] my short security talk given at the meetup and the source code of each level. Several people have posted their solutions online. You can find more by searching for the final password: [...]</description>
		<content:encoded><![CDATA[<p>[...] my short security talk given at the meetup and the source code of each level. Several people have posted their solutions online. You can find more by searching for the final password: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Stripe&#8217;s Capture the Flag &#8212; Solutions by cherie</title>
		<link>http://blog.zx2c4.com/781#comment-6738</link>
		<dc:creator>cherie</dc:creator>
		<pubDate>Wed, 14 Mar 2012 15:04:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=781#comment-6738</guid>
		<description>1967 called. Wants its font back.</description>
		<content:encoded><![CDATA[<p>1967 called. Wants its font back.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by centos升级内核教程 &#124; Linglin&#039;S Blog</title>
		<link>http://blog.zx2c4.com/749#comment-6733</link>
		<dc:creator>centos升级内核教程 &#124; Linglin&#039;S Blog</dc:creator>
		<pubDate>Tue, 06 Mar 2012 13:59:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6733</guid>
		<description>[...] 当前系统为CentOS Linux release 6.0 (Final),内核版本为2.6.32-71.el6.i686.由于最近内核出现最新的漏洞(linux kernel 又爆内存提权漏洞，&gt;=2.6.39 内核无一幸免 http://blog.zx2c4.com/749 和http://www.haohtml.com/news/netsafe/47456.html),所以将内核升级至3.2.2最新版本. [...]</description>
		<content:encoded><![CDATA[<p>[...] 当前系统为CentOS Linux release 6.0 (Final),内核版本为2.6.32-71.el6.i686.由于最近内核出现最新的漏洞(linux kernel 又爆内存提权漏洞，&gt;=2.6.39 内核无一幸免 http://blog.zx2c4.com/749 和http://www.haohtml.com/news/netsafe/47456.html),所以将内核升级至3.2.2最新版本. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by ShubhaM</title>
		<link>http://blog.zx2c4.com/749#comment-6730</link>
		<dc:creator>ShubhaM</dc:creator>
		<pubDate>Sun, 04 Mar 2012 06:21:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6730</guid>
		<description>Thank you for the new code..working like charm :)</description>
		<content:encoded><![CDATA[<p>Thank you for the new code..working like charm <img src='http://blog.zx2c4.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Jason</title>
		<link>http://blog.zx2c4.com/749#comment-6729</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Sat, 03 Mar 2012 19:45:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6729</guid>
		<description>I fixed this in the git repo. Download the latest from:

http://git.zx2c4.com/CVE-2012-0056/plain/mempodipper.c</description>
		<content:encoded><![CDATA[<p>I fixed this in the git repo. Download the latest from:</p>
<p><a href="http://git.zx2c4.com/CVE-2012-0056/plain/mempodipper.c" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/git.zx2c4.com/CVE-2012-0056/plain/mempodipper.c?referer=');">http://git.zx2c4.com/CVE-2012-0056/plain/mempodipper.c</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by ShubhaM</title>
		<link>http://blog.zx2c4.com/749#comment-6728</link>
		<dc:creator>ShubhaM</dc:creator>
		<pubDate>Sat, 03 Mar 2012 19:41:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6728</guid>
		<description>Getting Compiling errors, what to do ??


Mempodipper.c:284:2: warning: no newline at end of file
/tmp/ccctRq92.o: In function `ptrace_address&#039;:
Mempodipper.c:(.text+0x249): undefined reference to `pipe2&#039;
collect2: ld returned 1 exit status</description>
		<content:encoded><![CDATA[<p>Getting Compiling errors, what to do ??</p>
<p>Mempodipper.c:284:2: warning: no newline at end of file<br />
/tmp/ccctRq92.o: In function `ptrace_address&#8217;:<br />
Mempodipper.c:(.text+0&#215;249): undefined reference to `pipe2&#8242;<br />
collect2: ld returned 1 exit status</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by mempodipper exploited my slackware 13.37</title>
		<link>http://blog.zx2c4.com/749#comment-6726</link>
		<dc:creator>mempodipper exploited my slackware 13.37</dc:creator>
		<pubDate>Fri, 02 Mar 2012 10:10:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6726</guid>
		<description>[...] Rather than put my write up here, per usual, this time I&#039;ve put it * in a rather lengthy blog post: http://blog.zx2c4.com/749 * * Enjoy. * * - zx2c4 * Jan 21, 2012 * * CVE-2012-0056 */  Regards [...]</description>
		<content:encoded><![CDATA[<p>[...] Rather than put my write up here, per usual, this time I&#039;ve put it * in a rather lengthy blog post: <a href="http://blog.zx2c4.com/749" rel="nofollow">http://blog.zx2c4.com/749</a> * * Enjoy. * * &#8211; zx2c4 * Jan 21, 2012 * * CVE-2012-0056 */  Regards [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Root after M100 update? - Android Forums</title>
		<link>http://blog.zx2c4.com/749#comment-6724</link>
		<dc:creator>Root after M100 update? - Android Forums</dc:creator>
		<pubDate>Wed, 29 Feb 2012 16:48:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6724</guid>
		<description>[...] that the exploit (unless something has changed that I didn&#039;t see in M100) WILL NOT WORK.)  (source: Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#124; Nerdling Sapple [...]</description>
		<content:encoded><![CDATA[<p>[...] that the exploit (unless something has changed that I didn&#039;t see in M100) WILL NOT WORK.)  (source: Linux Local Privilege Escalation via SUID /proc/pid/mem Write | Nerdling Sapple [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Stripe&#8217;s Capture the Flag &#8212; Solutions by shipcode</title>
		<link>http://blog.zx2c4.com/781#comment-6719</link>
		<dc:creator>shipcode</dc:creator>
		<pubDate>Mon, 27 Feb 2012 17:49:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=781#comment-6719</guid>
		<description>I totally salute you brother :)

esepcially for your mempodipper</description>
		<content:encoded><![CDATA[<p>I totally salute you brother <img src='http://blog.zx2c4.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>esepcially for your mempodipper</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Reparenting QGraphicsItem during Mouse Drag by Anthony</title>
		<link>http://blog.zx2c4.com/275#comment-6718</link>
		<dc:creator>Anthony</dc:creator>
		<pubDate>Mon, 27 Feb 2012 01:10:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=275#comment-6718</guid>
		<description>I see this post is old, but I&#039;m experiencing the same problem. As I move around some QGraphicsItems, I want them to &quot;snap&quot; to some other items, and it works visually, but when I try to click on them after moving, it doesn&#039;t work.

Did you ever figure out a nicer solution?</description>
		<content:encoded><![CDATA[<p>I see this post is old, but I&#8217;m experiencing the same problem. As I move around some QGraphicsItems, I want them to &#8220;snap&#8221; to some other items, and it works visually, but when I try to click on them after moving, it doesn&#8217;t work.</p>
<p>Did you ever figure out a nicer solution?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on KDE Doesn&#8217;t Suck Anymore, People Finally Realize by Aaron Seigo</title>
		<link>http://blog.zx2c4.com/726#comment-6712</link>
		<dc:creator>Aaron Seigo</dc:creator>
		<pubDate>Wed, 22 Feb 2012 10:04:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=726#comment-6712</guid>
		<description>@Phrixus: olphin and konqueror use exactly the same code base for remote access, and both can use ioslaves for remote access as well as do just fine with locally mounted (network) partitions.</description>
		<content:encoded><![CDATA[<p>@Phrixus: olphin and konqueror use exactly the same code base for remote access, and both can use ioslaves for remote access as well as do just fine with locally mounted (network) partitions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on KDE Doesn&#8217;t Suck Anymore, People Finally Realize by Phrixus</title>
		<link>http://blog.zx2c4.com/726#comment-6709</link>
		<dc:creator>Phrixus</dc:creator>
		<pubDate>Wed, 22 Feb 2012 05:25:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=726#comment-6709</guid>
		<description>Sorry, but no. came back after 4 years, still cant browse and use my 12tb fileserver.

Looks great, stable, very impressed. bottom line: still sucks.

I will never understand why the dolphin devs think that all files are on a local machine,</description>
		<content:encoded><![CDATA[<p>Sorry, but no. came back after 4 years, still cant browse and use my 12tb fileserver.</p>
<p>Looks great, stable, very impressed. bottom line: still sucks.</p>
<p>I will never understand why the dolphin devs think that all files are on a local machine,</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by A stronger tingling sensation &#124; Anchor Web Hosting Blog</title>
		<link>http://blog.zx2c4.com/749#comment-6702</link>
		<dc:creator>A stronger tingling sensation &#124; Anchor Web Hosting Blog</dc:creator>
		<pubDate>Mon, 20 Feb 2012 00:06:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6702</guid>
		<description>[...] The recent /proc/pid/mem vulnerability in the linux kernel and its easily-demonstrated exploit, Mempodipper, should be a timely reminder of [...]</description>
		<content:encoded><![CDATA[<p>[...] The recent /proc/pid/mem vulnerability in the linux kernel and its easily-demonstrated exploit, Mempodipper, should be a timely reminder of [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by [SOLVED] Acer A200 ROOTED!</title>
		<link>http://blog.zx2c4.com/749#comment-6699</link>
		<dc:creator>[SOLVED] Acer A200 ROOTED!</dc:creator>
		<pubDate>Sun, 19 Feb 2012 06:11:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6699</guid>
		<description>[...] to saurik (https://github.com/saurik/mempodroid) for the root method, Jason A. Donenfeld (zx2c4) (Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#124; Nerdling Sapple) for finding the exploit  and to Rkeene (Rooting the Toshiba Thrive) for Getting around the /system [...]</description>
		<content:encoded><![CDATA[<p>[...] to saurik (<a href="https://github.com/saurik/mempodroid" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/github.com/saurik/mempodroid?referer=');">https://github.com/saurik/mempodroid</a>) for the root method, Jason A. Donenfeld (zx2c4) (Linux Local Privilege Escalation via SUID /proc/pid/mem Write | Nerdling Sapple) for finding the exploit  and to Rkeene (Rooting the Toshiba Thrive) for Getting around the /system [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Galaxy Nexus root / un-root w/o unlocking bootloader - Android Forums</title>
		<link>http://blog.zx2c4.com/749#comment-6698</link>
		<dc:creator>Galaxy Nexus root / un-root w/o unlocking bootloader - Android Forums</dc:creator>
		<pubDate>Sun, 19 Feb 2012 02:11:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6698</guid>
		<description>[...] Jason A. Donenfeld&#039;s Linux Mempodipper exploit who wrote about the CVE-2012-0056 exploit in Hacker News [...]</description>
		<content:encoded><![CDATA[<p>[...] Jason A. Donenfeld&#039;s Linux Mempodipper exploit who wrote about the CVE-2012-0056 exploit in Hacker News [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on KDE Doesn&#8217;t Suck Anymore, People Finally Realize by astotxo</title>
		<link>http://blog.zx2c4.com/726#comment-6693</link>
		<dc:creator>astotxo</dc:creator>
		<pubDate>Thu, 16 Feb 2012 23:19:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=726#comment-6693</guid>
		<description>Although I don&#039;t want hurt anyone, some of my feelings are well expressed in this post. I kept working on KDE3.5 on openSUSE 11.0 for 4 years and enjoyed it really much. &quot;How come did you stick to 11.0?&quot; may ask some people. Well, my computer is a tool I use to achieve work. It worked properly and I couldn&#039;t risk to lose my data or my software functionalities and spend the time to go through all the distribution upgrades only to be &quot;up-to-date&quot;. But since my OS is obsolete I can hardly install new software so I took the decision to upgrade it. So now I spend my time to help my computer to work better when it used to be the other way round!!! I don&#039;t want to judge KDE4, I am just sad to spend extra time in front of my computer to learn how to use KDE4 and notice everything runs slower that before on my 10-year-old computer. 
That&#039;s all for the complaining, now what do you people suggest? I just want to use something that runs as well and as simply as KDE3.5. So, trinity, XFCE?
Cheers!</description>
		<content:encoded><![CDATA[<p>Although I don&#8217;t want hurt anyone, some of my feelings are well expressed in this post. I kept working on KDE3.5 on openSUSE 11.0 for 4 years and enjoyed it really much. &#8220;How come did you stick to 11.0?&#8221; may ask some people. Well, my computer is a tool I use to achieve work. It worked properly and I couldn&#8217;t risk to lose my data or my software functionalities and spend the time to go through all the distribution upgrades only to be &#8220;up-to-date&#8221;. But since my OS is obsolete I can hardly install new software so I took the decision to upgrade it. So now I spend my time to help my computer to work better when it used to be the other way round!!! I don&#8217;t want to judge KDE4, I am just sad to spend extra time in front of my computer to learn how to use KDE4 and notice everything runs slower that before on my 10-year-old computer.<br />
That&#8217;s all for the complaining, now what do you people suggest? I just want to use something that runs as well and as simply as KDE3.5. So, trinity, XFCE?<br />
Cheers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by jechoi</title>
		<link>http://blog.zx2c4.com/749#comment-6683</link>
		<dc:creator>jechoi</dc:creator>
		<pubDate>Wed, 15 Feb 2012 06:34:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6683</guid>
		<description>I&#039;ve confirmed that the exploit code with gpasswd is working on Fedora 16. However, when I also tried with /usr/bin/newgrp (suid, return error message with arbitrary input, not compiled with PIE) on F16, I end up with a segmentation fault. It seems that newgrp has all of the vulnerable conditions and the code calculated padding correctly. Could anyone explain why it happens:

===============================
=          Mempodipper        =
=           by zx2c4          =
=         Jan 21, 2012        =
===============================

[+] Opening socketpair.
[+] Waiting for transferred fd in parent.
[+] Executing child from child fork.
[+] Opening parent mem /proc/3131/mem in child.
[+] Sending fd 5 to parent.
[+] Received fd at 5.
[+] Assigning fd 5 to stderr.
[+] Reading newgrp for exit@plt.
[+] Resolved exit@plt to 0x401bf0.
[+] Calculating newgrp padding.
[+] Seeking to offset 0x401be1.
[+] Executing newgrp with shellcode.
Segmentation fault</description>
		<content:encoded><![CDATA[<p>I&#8217;ve confirmed that the exploit code with gpasswd is working on Fedora 16. However, when I also tried with /usr/bin/newgrp (suid, return error message with arbitrary input, not compiled with PIE) on F16, I end up with a segmentation fault. It seems that newgrp has all of the vulnerable conditions and the code calculated padding correctly. Could anyone explain why it happens:</p>
<p>===============================<br />
=          Mempodipper        =<br />
=           by zx2c4          =<br />
=         Jan 21, 2012        =<br />
===============================</p>
<p>[+] Opening socketpair.<br />
[+] Waiting for transferred fd in parent.<br />
[+] Executing child from child fork.<br />
[+] Opening parent mem /proc/3131/mem in child.<br />
[+] Sending fd 5 to parent.<br />
[+] Received fd at 5.<br />
[+] Assigning fd 5 to stderr.<br />
[+] Reading newgrp for exit@plt.<br />
[+] Resolved exit@plt to 0x401bf0.<br />
[+] Calculating newgrp padding.<br />
[+] Seeking to offset 0x401be1.<br />
[+] Executing newgrp with shellcode.<br />
Segmentation fault</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Root GNex without unlocking bootloader (yep! :) - Android Forums</title>
		<link>http://blog.zx2c4.com/749#comment-6677</link>
		<dc:creator>Root GNex without unlocking bootloader (yep! :) - Android Forums</dc:creator>
		<pubDate>Sun, 12 Feb 2012 22:21:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6677</guid>
		<description>[...] Jason A. Donenfeld&#039;s Linux Mempodipper exploit who wrote about the CVE-2012-0056 exploit in Hacker News [...]</description>
		<content:encoded><![CDATA[<p>[...] Jason A. Donenfeld&#039;s Linux Mempodipper exploit who wrote about the CVE-2012-0056 exploit in Hacker News [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Caçando Fantasmas na memória &#171; Cooler&#039;s Lab</title>
		<link>http://blog.zx2c4.com/749#comment-6673</link>
		<dc:creator>Caçando Fantasmas na memória &#171; Cooler&#039;s Lab</dc:creator>
		<pubDate>Fri, 10 Feb 2012 20:13:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6673</guid>
		<description>[...] Mal uso de funções como printf , sprintf , strcpy , strcat&#8230;  podem colaborar na sua exploração via formatstring,bem como outros fatos podem colaborar na disclosure da memória bem como problemas de permissões , imagine ter acesso a algum PID na pasta &#8220;proc/[0-9]*/mem&#8221;, problemas com memoria estão cada vez mais populares como o último XPL de SUID  Olhe aqui [...]</description>
		<content:encoded><![CDATA[<p>[...] Mal uso de funções como printf , sprintf , strcpy , strcat&#8230;  podem colaborar na sua exploração via formatstring,bem como outros fatos podem colaborar na disclosure da memória bem como problemas de permissões , imagine ter acesso a algum PID na pasta &#8220;proc/[0-9]*/mem&#8221;, problemas com memoria estão cada vez mais populares como o último XPL de SUID  Olhe aqui [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Cosas interesantes que he aprendido &#171; federicoponte</title>
		<link>http://blog.zx2c4.com/749#comment-6662</link>
		<dc:creator>Cosas interesantes que he aprendido &#171; federicoponte</dc:creator>
		<pubDate>Thu, 09 Feb 2012 04:14:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6662</guid>
		<description>[...] un rato que conseguí este excelente artículo: http://blog.zx2c4.com/749. De verdad que impresionante lo que conocimiento y curiosidad pueden [...]</description>
		<content:encoded><![CDATA[<p>[...] un rato que conseguí este excelente artículo: http://blog.zx2c4.com/749. De verdad que impresionante lo que conocimiento y curiosidad pueden [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by 【For InfoQ】QSecurity月度评论 &#124; Wow! Uncle Joey</title>
		<link>http://blog.zx2c4.com/749#comment-6653</link>
		<dc:creator>【For InfoQ】QSecurity月度评论 &#124; Wow! Uncle Joey</dc:creator>
		<pubDate>Tue, 07 Feb 2012 03:42:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6653</guid>
		<description>[...]  Linux内核版本2.6.x本地提权漏洞 http://blog.zx2c4.com/749 [...]</description>
		<content:encoded><![CDATA[<p>[...]  Linux内核版本2.6.x本地提权漏洞 <a href="http://blog.zx2c4.com/749" rel="nofollow">http://blog.zx2c4.com/749</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux kernel CVE-2012-0056 vulnerability &#124; RimuHosting Blog</title>
		<link>http://blog.zx2c4.com/749#comment-6607</link>
		<dc:creator>Linux kernel CVE-2012-0056 vulnerability &#124; RimuHosting Blog</dc:creator>
		<pubDate>Sat, 04 Feb 2012 20:26:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6607</guid>
		<description>[...] released a 3.2.1 kernel patched against the vulnerabilty when we heard about the proof of concept mempodipper exploit. After pushing that kernel out though, we found that it was not compatiable with all of our [...]</description>
		<content:encoded><![CDATA[<p>[...] released a 3.2.1 kernel patched against the vulnerabilty when we heard about the proof of concept mempodipper exploit. After pushing that kernel out though, we found that it was not compatiable with all of our [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by LINUX PE Exploit &#124; ZuLL, יומנו של האקר.</title>
		<link>http://blog.zx2c4.com/749#comment-6605</link>
		<dc:creator>LINUX PE Exploit &#124; ZuLL, יומנו של האקר.</dc:creator>
		<pubDate>Sat, 04 Feb 2012 10:56:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6605</guid>
		<description>[...] למידע נוסף, http://blog.zx2c4.com/749 [...]</description>
		<content:encoded><![CDATA[<p>[...] למידע נוסף, http://blog.zx2c4.com/749 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by PoC exploits for Linux privilege escalation bug published &#124; MYH3R3</title>
		<link>http://blog.zx2c4.com/749#comment-6600</link>
		<dc:creator>PoC exploits for Linux privilege escalation bug published &#124; MYH3R3</dc:creator>
		<pubDate>Thu, 02 Feb 2012 18:15:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6600</guid>
		<description>[...] and programmer Jason Donenfeld first shared some insights about how the flaw can be exploited, and the information was used by others to [...]</description>
		<content:encoded><![CDATA[<p>[...] and programmer Jason Donenfeld first shared some insights about how the flaw can be exploited, and the information was used by others to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by ثغرة فكيرنل اللينكس تتيح لك الدخول للروت &#171; omanix09</title>
		<link>http://blog.zx2c4.com/749#comment-6598</link>
		<dc:creator>ثغرة فكيرنل اللينكس تتيح لك الدخول للروت &#171; omanix09</dc:creator>
		<pubDate>Thu, 02 Feb 2012 07:48:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6598</guid>
		<description>[...] واللي حاب يتعلم ينظر لملف الثغرة وللمزيد من الشرح تابع مدونة مكتشف الثغرة  [...]</description>
		<content:encoded><![CDATA[<p>[...] واللي حاب يتعلم ينظر لملف الثغرة وللمزيد من الشرح تابع مدونة مكتشف الثغرة  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by CVE 2012-0056 &#124; My Blog</title>
		<link>http://blog.zx2c4.com/749#comment-6595</link>
		<dc:creator>CVE 2012-0056 &#124; My Blog</dc:creator>
		<pubDate>Wed, 01 Feb 2012 10:04:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6595</guid>
		<description>[...] was removed. Anyone with the correct permissions could write to process memory. &#8220; &#8212; http://blog.zx2c4.com/749 Like this:LikeBe the first to like this post.   By adl  &#149;   Posted in Uncategorized   [...]</description>
		<content:encoded><![CDATA[<p>[...] was removed. Anyone with the correct permissions could write to process memory. &#8220; &#8212; <a href="http://blog.zx2c4.com/749" rel="nofollow">http://blog.zx2c4.com/749</a> Like this:LikeBe the first to like this post.   By adl  &#8226;   Posted in Uncategorized   [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by PoC exploits for Linux privilege escalation bug published &#124; MYH3R3</title>
		<link>http://blog.zx2c4.com/749#comment-6593</link>
		<dc:creator>PoC exploits for Linux privilege escalation bug published &#124; MYH3R3</dc:creator>
		<pubDate>Tue, 31 Jan 2012 17:25:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6593</guid>
		<description>[...] popping up online, TechWorld reports.Security researcher and programmer Jason Donenfeld first shared some insights about how the flaw can be exploited, and the information was used by others to [...]</description>
		<content:encoded><![CDATA[<p>[...] popping up online, TechWorld reports.Security researcher and programmer Jason Donenfeld first shared some insights about how the flaw can be exploited, and the information was used by others to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Terion</title>
		<link>http://blog.zx2c4.com/749#comment-6591</link>
		<dc:creator>Terion</dc:creator>
		<pubDate>Tue, 31 Jan 2012 09:43:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6591</guid>
		<description>Doesn&#039;t work on my system. What am I doing wrong (right?) Terminal output:
terion@LAPTOP:~/Downloads/mempodipper$ ./build-and-run-exploit.sh
===============================
=          Mempodipper        =
=           by zx2c4          =
=         Jan 21, 2012        =
===============================

[+] Ptracing su to find next instruction without reading binary.
[+] Creating ptrace pipe.
[+] Forking ptrace child.
[+] Waiting for ptraced child to give output on syscalls.
[+] Ptrace_traceme&#039;ing process.
[+] Error message written. Single stepping to find address.
[+] Resolved call address to 0x8049570.
[+] Opening socketpair.
[+] Waiting for transferred fd in parent.
[+] Executing child from child fork.
[+] Opening parent mem /proc/5464/mem in child.
[+] Sending fd 6 to parent.
[+] Received fd at 6.
[+] Assigning fd 6 to stderr.
[+] Calculating su padding.
[+] Seeking to offset 0x8049564.
[+] Executing su with shellcode.
terion@LAPTOP:~/Downloads/mempodipper$ whoami
terion
terion@LAPTOP:~/Downloads/mempodipper$ uname -a
Linux LAPTOP 3.0.0-15-generic-pae #26-Ubuntu SMP Fri Jan 20 17:07:31 UTC 2012 i686 i686 i386 GNU/Linux</description>
		<content:encoded><![CDATA[<p>Doesn&#8217;t work on my system. What am I doing wrong (right?) Terminal output:<br />
terion@LAPTOP:~/Downloads/mempodipper$ ./build-and-run-exploit.sh<br />
===============================<br />
=          Mempodipper        =<br />
=           by zx2c4          =<br />
=         Jan 21, 2012        =<br />
===============================</p>
<p>[+] Ptracing su to find next instruction without reading binary.<br />
[+] Creating ptrace pipe.<br />
[+] Forking ptrace child.<br />
[+] Waiting for ptraced child to give output on syscalls.<br />
[+] Ptrace_traceme&#8217;ing process.<br />
[+] Error message written. Single stepping to find address.<br />
[+] Resolved call address to 0&#215;8049570.<br />
[+] Opening socketpair.<br />
[+] Waiting for transferred fd in parent.<br />
[+] Executing child from child fork.<br />
[+] Opening parent mem /proc/5464/mem in child.<br />
[+] Sending fd 6 to parent.<br />
[+] Received fd at 6.<br />
[+] Assigning fd 6 to stderr.<br />
[+] Calculating su padding.<br />
[+] Seeking to offset 0&#215;8049564.<br />
[+] Executing su with shellcode.<br />
terion@LAPTOP:~/Downloads/mempodipper$ whoami<br />
terion<br />
terion@LAPTOP:~/Downloads/mempodipper$ uname -a<br />
Linux LAPTOP 3.0.0-15-generic-pae #26-Ubuntu SMP Fri Jan 20 17:07:31 UTC 2012 i686 i686 i386 GNU/Linux</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux local privilege escalation via SUID &#171; My Technical Notes</title>
		<link>http://blog.zx2c4.com/749#comment-6590</link>
		<dc:creator>Linux local privilege escalation via SUID &#171; My Technical Notes</dc:creator>
		<pubDate>Tue, 31 Jan 2012 06:24:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6590</guid>
		<description>[...] 2. http://blog.zx2c4.com/749 [...]</description>
		<content:encoded><![CDATA[<p>[...] 2. http://blog.zx2c4.com/749 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by m33x</title>
		<link>http://blog.zx2c4.com/749#comment-6589</link>
		<dc:creator>m33x</dc:creator>
		<pubDate>Tue, 31 Jan 2012 00:24:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6589</guid>
		<description>While I try to start the exploit via PHP (user is www-data) all I get is:

[+] Opening parent mem /proc/25160/mem in child.
[+] Sending fd 8 to parent.

(For sure i changed the executed shell code to something more matching like creating a folder, instead of spawning a shell)</description>
		<content:encoded><![CDATA[<p>While I try to start the exploit via PHP (user is www-data) all I get is:</p>
<p>[+] Opening parent mem /proc/25160/mem in child.<br />
[+] Sending fd 8 to parent.</p>
<p>(For sure i changed the executed shell code to something more matching like creating a folder, instead of spawning a shell)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by La gestion des correctifs sous environnement Linux &#124; Technoweb</title>
		<link>http://blog.zx2c4.com/749#comment-6587</link>
		<dc:creator>La gestion des correctifs sous environnement Linux &#124; Technoweb</dc:creator>
		<pubDate>Mon, 30 Jan 2012 18:48:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6587</guid>
		<description>[...] le cas de la dernière alerte, la mise à disposition d&#8217;un exploit et d&#8217;un très bon tuto a été tellement rapide qu&#8217;il a pris de court les éditeurs de distribution Linux. Sachant [...]</description>
		<content:encoded><![CDATA[<p>[...] le cas de la dernière alerte, la mise à disposition d&#8217;un exploit et d&#8217;un très bon tuto a été tellement rapide qu&#8217;il a pris de court les éditeurs de distribution Linux. Sachant [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by jmz</title>
		<link>http://blog.zx2c4.com/749#comment-6583</link>
		<dc:creator>jmz</dc:creator>
		<pubDate>Mon, 30 Jan 2012 09:52:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6583</guid>
		<description>I actually wasn&#039;t able to find any non-PIE setuid binaries on my Arch install.</description>
		<content:encoded><![CDATA[<p>I actually wasn&#8217;t able to find any non-PIE setuid binaries on my Arch install.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by How to force linux kernel version to 2.6.x &#171; Site News &#171; majestika</title>
		<link>http://blog.zx2c4.com/749#comment-6582</link>
		<dc:creator>How to force linux kernel version to 2.6.x &#171; Site News &#171; majestika</dc:creator>
		<pubDate>Mon, 30 Jan 2012 06:59:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6582</guid>
		<description>[...] to latest code (especially because of certain bugs that recently were patched, such as the famous mempodipper), this is [...]</description>
		<content:encoded><![CDATA[<p>[...] to latest code (especially because of certain bugs that recently were patched, such as the famous mempodipper), this is [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Escabilidad de privilegios en Linux</title>
		<link>http://blog.zx2c4.com/749#comment-6581</link>
		<dc:creator>Escabilidad de privilegios en Linux</dc:creator>
		<pubDate>Mon, 30 Jan 2012 06:50:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6581</guid>
		<description>[...] más info pueden visitar Este link. Saludos!     &lt; Remove WAT [...]</description>
		<content:encoded><![CDATA[<p>[...] más info pueden visitar Este link. Saludos!     &lt; Remove WAT [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Sysadmin Sunday 64 &#171; Boxed Ice Blog</title>
		<link>http://blog.zx2c4.com/749#comment-6573</link>
		<dc:creator>Sysadmin Sunday 64 &#171; Boxed Ice Blog</dc:creator>
		<pubDate>Sun, 29 Jan 2012 16:02:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6573</guid>
		<description>[...] Linux Local Privilege Escalation via SUID /proc/pid/mem Write [...]</description>
		<content:encoded><![CDATA[<p>[...] Linux Local Privilege Escalation via SUID /proc/pid/mem Write [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by centos升级内核教程 &#124; haohtml&#039;s blog</title>
		<link>http://blog.zx2c4.com/749#comment-6572</link>
		<dc:creator>centos升级内核教程 &#124; haohtml&#039;s blog</dc:creator>
		<pubDate>Sun, 29 Jan 2012 09:53:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6572</guid>
		<description>[...] 当前系统内核为2.6.32-71.el6.i686.由于最近内核出现最新的漏洞(linux kernel 又爆内存提权漏洞，&gt;=2.6.39 内核无一幸免 和http://blog.zx2c4.com/749),所以将内核升级至3.2.2最新版本. [...]</description>
		<content:encoded><![CDATA[<p>[...] 当前系统内核为2.6.32-71.el6.i686.由于最近内核出现最新的漏洞(linux kernel 又爆内存提权漏洞，&gt;=2.6.39 内核无一幸免 和http://blog.zx2c4.com/749),所以将内核升级至3.2.2最新版本. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by CVE-2012-0056 Linux privilege escalation [Video Demonstration] &#171; CC&#039;S ONLINE JOURNAL</title>
		<link>http://blog.zx2c4.com/749#comment-6571</link>
		<dc:creator>CVE-2012-0056 Linux privilege escalation [Video Demonstration] &#171; CC&#039;S ONLINE JOURNAL</dc:creator>
		<pubDate>Sun, 29 Jan 2012 04:30:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6571</guid>
		<description>[...] which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper. Read More Here.Video Demonstration:    Advertisement  GA_googleAddAttr(&quot;AdOpt&quot;, &quot;1&quot;); [...]</description>
		<content:encoded><![CDATA[<p>[...] which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper. Read More Here.Video Demonstration:    Advertisement  GA_googleAddAttr(&quot;AdOpt&quot;, &quot;1&quot;); [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Actus Sécurité Grand public 2012 S04 &#124; La Mare du Gof</title>
		<link>http://blog.zx2c4.com/749#comment-6570</link>
		<dc:creator>Actus Sécurité Grand public 2012 S04 &#124; La Mare du Gof</dc:creator>
		<pubDate>Sun, 29 Jan 2012 00:54:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6570</guid>
		<description>[...] =&gt; Une brèche de sécurité « zero day » est ouverte dans le noyau Linux. 26/01/2012. «Une faille de sécurité critique touche le noyau Linux, depuis sa version 2.6.39. Les éditeurs de distributions Linux s’activent pour appliquer le plus vite possible le correctif permettant de combler cette faille. Android est également concerné (&#8230;).» Source : www.silicon.fr/une-breche-de-securite-zero-day-est-ouverte-dans-le-noyau-linux-71125.html Billets en relation : 23/01/2012. Linux Local Privilege Escalation via SUID : blog.zx2c4.com/749 [...]</description>
		<content:encoded><![CDATA[<p>[...] =&gt; Une brèche de sécurité « zero day » est ouverte dans le noyau Linux. 26/01/2012. «Une faille de sécurité critique touche le noyau Linux, depuis sa version 2.6.39. Les éditeurs de distributions Linux s’activent pour appliquer le plus vite possible le correctif permettant de combler cette faille. Android est également concerné (&#8230;).» Source : <a href="http://www.silicon.fr/une-breche-de-securite-zero-day-est-ouverte-dans-le-noyau-linux-71125.html" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/www.silicon.fr/une-breche-de-securite-zero-day-est-ouverte-dans-le-noyau-linux-71125.html?referer=');">http://www.silicon.fr/une-breche-de-securite-zero-day-est-ouverte-dans-le-noyau-linux-71125.html</a> Billets en relation : 23/01/2012. Linux Local Privilege Escalation via SUID : blog.zx2c4.com/749 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by CVE-2012-0056 Linux privilege escalation [Video Demonstration]&#160;/&#160; Hackersplay.com</title>
		<link>http://blog.zx2c4.com/749#comment-6569</link>
		<dc:creator>CVE-2012-0056 Linux privilege escalation [Video Demonstration]&#160;/&#160; Hackersplay.com</dc:creator>
		<pubDate>Sun, 29 Jan 2012 00:27:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6569</guid>
		<description>[...] which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper. Read More [...]</description>
		<content:encoded><![CDATA[<p>[...] which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper. Read More [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by unhackable security &#187; Blog Archive &#187; Linux vendors rush to patch privilege escalation flaw after root exploits emerge</title>
		<link>http://blog.zx2c4.com/749#comment-6568</link>
		<dc:creator>unhackable security &#187; Blog Archive &#187; Linux vendors rush to patch privilege escalation flaw after root exploits emerge</dc:creator>
		<pubDate>Sat, 28 Jan 2012 22:14:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6568</guid>
		<description>[...] published a detailed article about how the vulnerability can be exploited on his blog on Sunday, which served as inspiration for [...]</description>
		<content:encoded><![CDATA[<p>[...] published a detailed article about how the vulnerability can be exploited on his blog on Sunday, which served as inspiration for [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by VU#470151: Linux Kernel local privilege escalation via SUID /proc/pid/mem write</title>
		<link>http://blog.zx2c4.com/749#comment-6556</link>
		<dc:creator>VU#470151: Linux Kernel local privilege escalation via SUID /proc/pid/mem write</dc:creator>
		<pubDate>Fri, 27 Jan 2012 17:16:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6556</guid>
		<description>[...] an attacker can run arbitrary code with root privileges. Further technical details can be found on Jason A. Donenfeld&#8217;s ZX2C4 blog post.II. ImpactA local, authenticated attacker may be able to gain root privileges on the system.III. [...]</description>
		<content:encoded><![CDATA[<p>[...] an attacker can run arbitrary code with root privileges. Further technical details can be found on Jason A. Donenfeld&#8217;s ZX2C4 blog post.II. ImpactA local, authenticated attacker may be able to gain root privileges on the system.III. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on KDE Doesn&#8217;t Suck Anymore, People Finally Realize by Alhana</title>
		<link>http://blog.zx2c4.com/726#comment-6552</link>
		<dc:creator>Alhana</dc:creator>
		<pubDate>Fri, 27 Jan 2012 11:57:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=726#comment-6552</guid>
		<description>It&#039;s not true. KDE is still gaudy, very slow, having misterious segfaults each 15 minutes and consisting of programs which either has too little functions or plainly doesn&#039;t work. It&#039;s nightmare to work with.</description>
		<content:encoded><![CDATA[<p>It&#8217;s not true. KDE is still gaudy, very slow, having misterious segfaults each 15 minutes and consisting of programs which either has too little functions or plainly doesn&#8217;t work. It&#8217;s nightmare to work with.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Exploit root Linux Karena Akses Memori &#124; LinuxBox.Web.ID</title>
		<link>http://blog.zx2c4.com/749#comment-6551</link>
		<dc:creator>Exploit root Linux Karena Akses Memori &#124; LinuxBox.Web.ID</dc:creator>
		<pubDate>Fri, 27 Jan 2012 09:47:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6551</guid>
		<description>[...] dan dapat diakali dengan mudah.Segera setelah publikasi artikel yang menjelaskan hal tersebut di Nerdling Sapple, pengkode lainnya menggunakan informasi yanga da didalam artikel untuk membuat eksploit dan [...]</description>
		<content:encoded><![CDATA[<p>[...] dan dapat diakali dengan mudah.Segera setelah publikasi artikel yang menjelaskan hal tersebut di Nerdling Sapple, pengkode lainnya menggunakan informasi yanga da didalam artikel untuk membuat eksploit dan [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Rolf</title>
		<link>http://blog.zx2c4.com/749#comment-6550</link>
		<dc:creator>Rolf</dc:creator>
		<pubDate>Fri, 27 Jan 2012 08:57:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6550</guid>
		<description>Why is /proc/pid/mem needed anyway?  It seems a huge risk to have direct access to process memory, regardles of security measures.</description>
		<content:encoded><![CDATA[<p>Why is /proc/pid/mem needed anyway?  It seems a huge risk to have direct access to process memory, regardles of security measures.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by André Caldas</title>
		<link>http://blog.zx2c4.com/749#comment-6548</link>
		<dc:creator>André Caldas</dc:creator>
		<pubDate>Fri, 27 Jan 2012 08:02:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6548</guid>
		<description>I find it interesting people arguing that the exploit is flawed!!!

Security does not work that way! You cannot, after an exploit, argue that you could have blocked proc/pid/mem access. Well, you could simply not turn your computer on. The exploit does not block you from turning your computer off and never turning it on again!!! So, it is flawed!!! :-P</description>
		<content:encoded><![CDATA[<p>I find it interesting people arguing that the exploit is flawed!!!</p>
<p>Security does not work that way! You cannot, after an exploit, argue that you could have blocked proc/pid/mem access. Well, you could simply not turn your computer on. The exploit does not block you from turning your computer off and never turning it on again!!! So, it is flawed!!! <img src='http://blog.zx2c4.com/wp-includes/images/smilies/icon_razz.gif' alt=':-P' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Fehler im Linux Kernel ermöglicht ROOT &#124; Tuxxnet.de - Mit Sicherheit einen Schritt voraus!</title>
		<link>http://blog.zx2c4.com/749#comment-6547</link>
		<dc:creator>Fehler im Linux Kernel ermöglicht ROOT &#124; Tuxxnet.de - Mit Sicherheit einen Schritt voraus!</dc:creator>
		<pubDate>Fri, 27 Jan 2012 07:48:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6547</guid>
		<description>[...] vor einigen Tagen von Linus Torvalds im offiziellen Kernel behoben und in Folge an anderer Stelle n&#228;her analyisert. Mittlerweile kursieren bereits diverse Exploits, die den Fehler ausnutzen k&#246;nnen, um [...]</description>
		<content:encoded><![CDATA[<p>[...] vor einigen Tagen von Linus Torvalds im offiziellen Kernel behoben und in Folge an anderer Stelle n&auml;her analyisert. Mittlerweile kursieren bereits diverse Exploits, die den Fehler ausnutzen k&ouml;nnen, um [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux local kernel privilege escalation to root &#171; codeinsecurity</title>
		<link>http://blog.zx2c4.com/749#comment-6546</link>
		<dc:creator>Linux local kernel privilege escalation to root &#171; codeinsecurity</dc:creator>
		<pubDate>Fri, 27 Jan 2012 07:13:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6546</guid>
		<description>[...] security researcher zx2c4 has released a technical description of the bug, as well as an exploit.  Advertisement  GA_googleAddAttr(&quot;AdOpt&quot;, &quot;1&quot;); [...]</description>
		<content:encoded><![CDATA[<p>[...] security researcher zx2c4 has released a technical description of the bug, as well as an exploit.  Advertisement  GA_googleAddAttr(&quot;AdOpt&quot;, &quot;1&quot;); [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Answers for Everyone &#124; Jupiter Broadcasting</title>
		<link>http://blog.zx2c4.com/749#comment-6543</link>
		<dc:creator>Answers for Everyone &#124; Jupiter Broadcasting</dc:creator>
		<pubDate>Fri, 27 Jan 2012 04:41:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6543</guid>
		<description>[...] Analysis  [...]</description>
		<content:encoded><![CDATA[<p>[...] Analysis  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by oiaohm</title>
		<link>http://blog.zx2c4.com/749#comment-6541</link>
		<dc:creator>oiaohm</dc:creator>
		<pubDate>Fri, 27 Jan 2012 03:09:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6541</guid>
		<description>This is not a 100 percent sure will work breach even with a defective kernel.

There is two major issues forgot.  This does not block a LSM from disabling access /proc/*/mem.   This could selinux or smack for sure.

So a kernel update is not required to address this problem.  Turn LSM on set up rules attack is dead as a dodo.    Basically only selinux or smack approve applications can access /proc/*/mem read write.  Every other applicaiton gets read only or nothing. 

Injection is not assured in Linux.

Really is there any critical need for distrobutions with selinux or smack by default to rush out a kernel patch.  Not at all.  Just make sure they have it turned on.

This does ask serous questions why LSM on have not become kinda mandortory.  No need to wait for distribution to fix this.</description>
		<content:encoded><![CDATA[<p>This is not a 100 percent sure will work breach even with a defective kernel.</p>
<p>There is two major issues forgot.  This does not block a LSM from disabling access /proc/*/mem.   This could selinux or smack for sure.</p>
<p>So a kernel update is not required to address this problem.  Turn LSM on set up rules attack is dead as a dodo.    Basically only selinux or smack approve applications can access /proc/*/mem read write.  Every other applicaiton gets read only or nothing. </p>
<p>Injection is not assured in Linux.</p>
<p>Really is there any critical need for distrobutions with selinux or smack by default to rush out a kernel patch.  Not at all.  Just make sure they have it turned on.</p>
<p>This does ask serous questions why LSM on have not become kinda mandortory.  No need to wait for distribution to fix this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by skunk</title>
		<link>http://blog.zx2c4.com/749#comment-6534</link>
		<dc:creator>skunk</dc:creator>
		<pubDate>Thu, 26 Jan 2012 20:38:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6534</guid>
		<description>hi jason, it works perfectly on my gentoo box but not on my hardened gentoo server:

skunk@web1 CVE-2012-0056 % uname -a
Linux web1 2.6.39-hardened-r8 #1 SMP Sat Sep 17 13:58:22 CEST 2011 x86_64 Intel(R) Xeon(R) CPU E5520 @ 2.27GHz GenuineIntel GNU/Linuxskunk@web1 CVE-2012-0056 % ./build-and-run-exploit.sh 
===============================
=          Mempodipper        =
=           by zx2c4          =
=         Jan 21, 2012        =
===============================

[+] Ptracing su to find next instruction without reading binary.
[+] Creating ptrace pipe.
[+] Forking ptrace child.
[+] Waiting for ptraced child to give output on syscalls.
[+] Ptrace_traceme&#039;ing process.
[+] Error message written. Single stepping to find address.
[+] Resolved call address to 0x716a3d5b70.
[+] Opening socketpair.
[+] Waiting for transferred fd in parent.
[+] Executing child from child fork.
[+] Opening parent mem /proc/18668/mem in child.
[+] Sending fd 6 to parent.
[+] Received fd at 6.
[+] Assigning fd 6 to stderr.
[+] Calculating su padding.
[+] Seeking to offset 0x716a3d5b64.
[+] Executing su with shellcode.
skunk@web1 CVE-2012-0056 % whoami
skunk</description>
		<content:encoded><![CDATA[<p>hi jason, it works perfectly on my gentoo box but not on my hardened gentoo server:</p>
<p>skunk@web1 CVE-2012-0056 % uname -a<br />
Linux web1 2.6.39-hardened-r8 #1 SMP Sat Sep 17 13:58:22 CEST 2011 x86_64 Intel(R) Xeon(R) CPU E5520 @ 2.27GHz GenuineIntel GNU/Linuxskunk@web1 CVE-2012-0056 % ./build-and-run-exploit.sh<br />
===============================<br />
=          Mempodipper        =<br />
=           by zx2c4          =<br />
=         Jan 21, 2012        =<br />
===============================</p>
<p>[+] Ptracing su to find next instruction without reading binary.<br />
[+] Creating ptrace pipe.<br />
[+] Forking ptrace child.<br />
[+] Waiting for ptraced child to give output on syscalls.<br />
[+] Ptrace_traceme&#8217;ing process.<br />
[+] Error message written. Single stepping to find address.<br />
[+] Resolved call address to 0x716a3d5b70.<br />
[+] Opening socketpair.<br />
[+] Waiting for transferred fd in parent.<br />
[+] Executing child from child fork.<br />
[+] Opening parent mem /proc/18668/mem in child.<br />
[+] Sending fd 6 to parent.<br />
[+] Received fd at 6.<br />
[+] Assigning fd 6 to stderr.<br />
[+] Calculating su padding.<br />
[+] Seeking to offset 0x716a3d5b64.<br />
[+] Executing su with shellcode.<br />
skunk@web1 CVE-2012-0056 % whoami<br />
skunk</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Elevación de privilegios en el kernel Linux y un exploit interesante &#124; MundoPC.NET</title>
		<link>http://blog.zx2c4.com/749#comment-6524</link>
		<dc:creator>Elevación de privilegios en el kernel Linux y un exploit interesante &#124; MundoPC.NET</dc:creator>
		<pubDate>Thu, 26 Jan 2012 14:54:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6524</guid>
		<description>[...]  [...]</description>
		<content:encoded><![CDATA[<p>[...]  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux vendors rush to patch privilege escalation flaw after root exploits emerge : News Sluice</title>
		<link>http://blog.zx2c4.com/749#comment-6522</link>
		<dc:creator>Linux vendors rush to patch privilege escalation flaw after root exploits emerge : News Sluice</dc:creator>
		<pubDate>Thu, 26 Jan 2012 12:57:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6522</guid>
		<description>[...] published a detailed article about how the vulnerability can be exploited on his blog on Sunday, which served as inspiration [...]</description>
		<content:encoded><![CDATA[<p>[...] published a detailed article about how the vulnerability can be exploited on his blog on Sunday, which served as inspiration [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by eXactBot Hosting Solutions &#187; Did Linus Jump the Gun on a Kernel security fix?</title>
		<link>http://blog.zx2c4.com/749#comment-6521</link>
		<dc:creator>eXactBot Hosting Solutions &#187; Did Linus Jump the Gun on a Kernel security fix?</dc:creator>
		<pubDate>Thu, 26 Jan 2012 12:15:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6521</guid>
		<description>[...] flaw. As it turns out the flaw was exploited quickly once Torvalds put out the patch with a proof of concept emerging [...]</description>
		<content:encoded><![CDATA[<p>[...] flaw. As it turns out the flaw was exploited quickly once Torvalds put out the patch with a proof of concept emerging [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Chris Mylonas</title>
		<link>http://blog.zx2c4.com/749#comment-6520</link>
		<dc:creator>Chris Mylonas</dc:creator>
		<pubDate>Thu, 26 Jan 2012 11:15:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6520</guid>
		<description>Wow!  What an impressive post...
Thanks for breaking it down like that.   The number and relevance of your peers&#039; comments reflect my initial sentiments.

Thanks for sharing.</description>
		<content:encoded><![CDATA[<p>Wow!  What an impressive post&#8230;<br />
Thanks for breaking it down like that.   The number and relevance of your peers&#8217; comments reflect my initial sentiments.</p>
<p>Thanks for sharing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by IO</title>
		<link>http://blog.zx2c4.com/749#comment-6517</link>
		<dc:creator>IO</dc:creator>
		<pubDate>Thu, 26 Jan 2012 09:38:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6517</guid>
		<description>Is 3.2-1 affected? there is no mention in changelog about this  behavior,  however  Debian whit official linux-source 3.2-1 seems to be immune.

http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.1

http://packages.debian.org/changelogs/pool/main/l/linux-2.6/linux-2.6_3.2.1-1/changelog</description>
		<content:encoded><![CDATA[<p>Is 3.2-1 affected? there is no mention in changelog about this  behavior,  however  Debian whit official linux-source 3.2-1 seems to be immune.</p>
<p><a href="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.1" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.1?referer=');">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.1</a></p>
<p><a href="http://packages.debian.org/changelogs/pool/main/l/linux-2.6/linux-2.6_3.2.1-1/changelog" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/packages.debian.org/changelogs/pool/main/l/linux-2.6/linux-2.6_3.2.1-1/changelog?referer=');">http://packages.debian.org/changelogs/pool/main/l/linux-2.6/linux-2.6_3.2.1-1/changelog</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Red Hat, Ubuntu, and Arch Linux patch Linux kernel exploit &#124; Matias Vangsnes</title>
		<link>http://blog.zx2c4.com/749#comment-6512</link>
		<dc:creator>Red Hat, Ubuntu, and Arch Linux patch Linux kernel exploit &#124; Matias Vangsnes</dc:creator>
		<pubDate>Wed, 25 Jan 2012 19:35:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6512</guid>
		<description>[...] Jason A. Donenfeld posted a proof-of-concept exploit called &#8220;mempodipper,&#8221; and then published an in-depth technical overview.Donenfield&#8217;s explanation inspired other hackers to post additional exploits, according to [...]</description>
		<content:encoded><![CDATA[<p>[...] Jason A. Donenfeld posted a proof-of-concept exploit called &#8220;mempodipper,&#8221; and then published an in-depth technical overview.Donenfield&#8217;s explanation inspired other hackers to post additional exploits, according to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by zac</title>
		<link>http://blog.zx2c4.com/749#comment-6510</link>
		<dc:creator>zac</dc:creator>
		<pubDate>Wed, 25 Jan 2012 18:41:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6510</guid>
		<description>for your command look up, in particular line 140 of Mempodipper you can use which to more robustly lookup command e.g. 
objdump -d `which gpasswd`&#124;grep &#039;&#039;&#124;head -n 1&#124;cut -d &#039; &#039; -f 1&#124;sed &#039;s/^[0]*\\([^0]*\\)/0x\\1/&#039;
rather than:
objdump -d /usr/bin/gpasswd&#124;grep &#039;&#039;&#124;head -n 1&#124;cut -d &#039; &#039; -f 1&#124;sed &#039;s/^[0]*\\([^0]*\\)/0x\\1/&#039;</description>
		<content:encoded><![CDATA[<p>for your command look up, in particular line 140 of Mempodipper you can use which to more robustly lookup command e.g.<br />
objdump -d `which gpasswd`|grep &#8221;|head -n 1|cut -d &#8216; &#8216; -f 1|sed &#8216;s/^[0]*\\([^0]*\\)/0x\\1/&#8217;<br />
rather than:<br />
objdump -d /usr/bin/gpasswd|grep &#8221;|head -n 1|cut -d &#8216; &#8216; -f 1|sed &#8216;s/^[0]*\\([^0]*\\)/0x\\1/&#8217;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by SecureIT &#187; Linux Kernel Vulnerability CVE-2012-0056</title>
		<link>http://blog.zx2c4.com/749#comment-6509</link>
		<dc:creator>SecureIT &#187; Linux Kernel Vulnerability CVE-2012-0056</dc:creator>
		<pubDate>Wed, 25 Jan 2012 17:28:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6509</guid>
		<description>[...] few days ago a reliable privileged escalation vulnerability was found in recent versions of the Linux kernel. Point and click exploits are showing up around [...]</description>
		<content:encoded><![CDATA[<p>[...] few days ago a reliable privileged escalation vulnerability was found in recent versions of the Linux kernel. Point and click exploits are showing up around [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Michael</title>
		<link>http://blog.zx2c4.com/749#comment-6506</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Wed, 25 Jan 2012 10:18:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6506</guid>
		<description>Same here on CentOS 5 and CentOS 6 (pipe2 problem)</description>
		<content:encoded><![CDATA[<p>Same here on CentOS 5 and CentOS 6 (pipe2 problem)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux vendors rush to patch privilege escalation flaw after root exploits emerge - HackerMuslim.com &#124; HackerMuslim.com</title>
		<link>http://blog.zx2c4.com/749#comment-6504</link>
		<dc:creator>Linux vendors rush to patch privilege escalation flaw after root exploits emerge - HackerMuslim.com &#124; HackerMuslim.com</dc:creator>
		<pubDate>Wed, 25 Jan 2012 09:56:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6504</guid>
		<description>[...] published a detailed article about how a disadvantage can be exploited on his blog on Sunday, that served as impulse for other [...]</description>
		<content:encoded><![CDATA[<p>[...] published a detailed article about how a disadvantage can be exploited on his blog on Sunday, that served as impulse for other [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by antonone</title>
		<link>http://blog.zx2c4.com/749#comment-6503</link>
		<dc:creator>antonone</dc:creator>
		<pubDate>Wed, 25 Jan 2012 08:45:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6503</guid>
		<description>Recent Fedora updates mitigate this exploit. F.e. in kernel:

2.6.41.10-3.fc15.x86_64 #1 SMP Mon Jan 23 15:46:37 UTC 2012

it doesn&#039;t work. But it worked before ;)</description>
		<content:encoded><![CDATA[<p>Recent Fedora updates mitigate this exploit. F.e. in kernel:</p>
<p>2.6.41.10-3.fc15.x86_64 #1 SMP Mon Jan 23 15:46:37 UTC 2012</p>
<p>it doesn&#8217;t work. But it worked before <img src='http://blog.zx2c4.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Caleb Everett</title>
		<link>http://blog.zx2c4.com/749#comment-6501</link>
		<dc:creator>Caleb Everett</dc:creator>
		<pubDate>Wed, 25 Jan 2012 05:28:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6501</guid>
		<description>Compiled, but did not work on my arch system.
Did not compile on schools red hat system, couldn&#039;t find pipe2.</description>
		<content:encoded><![CDATA[<p>Compiled, but did not work on my arch system.<br />
Did not compile on schools red hat system, couldn&#8217;t find pipe2.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux vendors rush to patch privilege escalation flaw after root exploits emerge &#187; Linux news</title>
		<link>http://blog.zx2c4.com/749#comment-6500</link>
		<dc:creator>Linux vendors rush to patch privilege escalation flaw after root exploits emerge &#187; Linux news</dc:creator>
		<pubDate>Tue, 24 Jan 2012 23:52:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6500</guid>
		<description>[...] published a detailed article about how the vulnerability can be exploited on his blog on Sunday, which served as inspiration for [...]</description>
		<content:encoded><![CDATA[<p>[...] published a detailed article about how the vulnerability can be exploited on his blog on Sunday, which served as inspiration for [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Get root? I &#8220;Escalando privilegios con Mempodipper CVE-2012-0056&#8243;</title>
		<link>http://blog.zx2c4.com/749#comment-6499</link>
		<dc:creator>Get root? I &#8220;Escalando privilegios con Mempodipper CVE-2012-0056&#8243;</dc:creator>
		<pubDate>Tue, 24 Jan 2012 21:57:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6499</guid>
		<description>[...] exploit es datado el 21 de Enero de 2012 por zx2c4 .Las pruebas realizadas a nivel personal  han sido satisfactorias en BackTrack5 R1 con un kernel [...]</description>
		<content:encoded><![CDATA[<p>[...] exploit es datado el 21 de Enero de 2012 por zx2c4 .Las pruebas realizadas a nivel personal  han sido satisfactorias en BackTrack5 R1 con un kernel [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by fixing vulnerabilities with systemtap &#171; codeblog</title>
		<link>http://blog.zx2c4.com/749#comment-6498</link>
		<dc:creator>fixing vulnerabilities with systemtap &#171; codeblog</dc:creator>
		<pubDate>Tue, 24 Jan 2012 19:33:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6498</guid>
		<description>[...] there is now a nearly-complete walk-through, the urgency for fixing this is higher. While you&#8217;re waiting for your distribution&#8217;s [...]</description>
		<content:encoded><![CDATA[<p>[...] there is now a nearly-complete walk-through, the urgency for fixing this is higher. While you&#8217;re waiting for your distribution&#8217;s [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by ITGeeks.us &#187; Linux root Exploit Vulnerability (CVE 2012-0056)</title>
		<link>http://blog.zx2c4.com/749#comment-6497</link>
		<dc:creator>ITGeeks.us &#187; Linux root Exploit Vulnerability (CVE 2012-0056)</dc:creator>
		<pubDate>Tue, 24 Jan 2012 18:34:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6497</guid>
		<description>[...] is an exploit called &#8220;Mempodipper&#8221; published last January 21, 2012 that enables normal users to escalate their privileges, [...]</description>
		<content:encoded><![CDATA[<p>[...] is an exploit called &#8220;Mempodipper&#8221; published last January 21, 2012 that enables normal users to escalate their privileges, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Escalada de privilegios con /proc/pid/mem write &#124; ANIME LINUX STYLE IN THE WORLD</title>
		<link>http://blog.zx2c4.com/749#comment-6496</link>
		<dc:creator>Escalada de privilegios con /proc/pid/mem write &#124; ANIME LINUX STYLE IN THE WORLD</dc:creator>
		<pubDate>Tue, 24 Jan 2012 18:14:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6496</guid>
		<description>[...] explicación completa está en http://blog.zx2c4.com/749 (en ingles) en donde este experto ha explicado cómo funciona el exploit para la vulnerabilidad [...]</description>
		<content:encoded><![CDATA[<p>[...] explicación completa está en http://blog.zx2c4.com/749 (en ingles) en donde este experto ha explicado cómo funciona el exploit para la vulnerabilidad [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux root Exploit Vulnerability (CVE 2012-0056) &#124; ProjectX Blog &#8211; Information Security Redefined</title>
		<link>http://blog.zx2c4.com/749#comment-6494</link>
		<dc:creator>Linux root Exploit Vulnerability (CVE 2012-0056) &#124; ProjectX Blog &#8211; Information Security Redefined</dc:creator>
		<pubDate>Tue, 24 Jan 2012 17:06:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6494</guid>
		<description>[...] Linux by tuldok &#8212; Leave a comment January 24, 2012    There is an exploit called &#8220;Mempodipper&#8221; published last January 23, 2012 that enables normal users to escalate their privileges, [...]</description>
		<content:encoded><![CDATA[<p>[...] Linux by tuldok &mdash; Leave a comment January 24, 2012    There is an exploit called &#8220;Mempodipper&#8221; published last January 23, 2012 that enables normal users to escalate their privileges, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by ex falso</title>
		<link>http://blog.zx2c4.com/749#comment-6490</link>
		<dc:creator>ex falso</dc:creator>
		<pubDate>Tue, 24 Jan 2012 15:18:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6490</guid>
		<description>exfalso@QuodLibet ~/tmp % gcc -o mkroot mkroot.c -O0
exfalso@QuodLibet ~/tmp % uname -r
3.2.1-1-ARCH
exfalso@QuodLibet ~/tmp % ./mkroot
===============================
=          Mempodipper        =
=           by zx2c4          =
=         Jan 21, 2012        =
===============================

[+] Waiting for transferred fd in parent.
[+] Executing child from child fork.
[+] Opening parent mem /proc/8332/mem in child.
[+] Sending fd 3 to parent.
[+] Received fd at 5.
[+] Assigning fd 5 to stderr.
[+] Reading su for exit@plt.
[+] Resolved exit@plt to 0x401a60.
[+] Calculating su padding.
[+] Seeking to offset 0x401a57.
[+] Executing su with shellcode.
[1]    8332 segmentation fault  ./mkroot


l2program lol</description>
		<content:encoded><![CDATA[<p>exfalso@QuodLibet ~/tmp % gcc -o mkroot mkroot.c -O0<br />
exfalso@QuodLibet ~/tmp % uname -r<br />
3.2.1-1-ARCH<br />
exfalso@QuodLibet ~/tmp % ./mkroot<br />
===============================<br />
=          Mempodipper        =<br />
=           by zx2c4          =<br />
=         Jan 21, 2012        =<br />
===============================</p>
<p>[+] Waiting for transferred fd in parent.<br />
[+] Executing child from child fork.<br />
[+] Opening parent mem /proc/8332/mem in child.<br />
[+] Sending fd 3 to parent.<br />
[+] Received fd at 5.<br />
[+] Assigning fd 5 to stderr.<br />
[+] Reading su for exit@plt.<br />
[+] Resolved exit@plt to 0x401a60.<br />
[+] Calculating su padding.<br />
[+] Seeking to offset 0x401a57.<br />
[+] Executing su with shellcode.<br />
[1]    8332 segmentation fault  ./mkroot</p>
<p>l2program lol</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by André Caldas</title>
		<link>http://blog.zx2c4.com/749#comment-6483</link>
		<dc:creator>André Caldas</dc:creator>
		<pubDate>Tue, 24 Jan 2012 12:31:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6483</guid>
		<description>It seems to me that the problem here is that &quot;self_exec_id&quot; is implicitly understood to be unique. But &quot;unique&quot; has three meanings here:

TYPE 1. It is IMPOSSIBLE to have collisions.
TYPE 2. It is HIGHLY IMPROBABLE to have &quot;natural&quot; collisions.
TYPE 3. It is HIGHLY IMPROBABLE to have &quot;natural&quot; collisions, and when it happens, it is HIGHLY IMPROBABLE we will even notice.

Given the fact that the self_exec_id is reset when it reaches its maximum value, we can say that the code that generates it does not understand that it is &quot;type 1 unique&quot;. No security check should rely on any definition of unique different from &quot;type 1 unique&quot;. Is it hard to always implement &quot;type 1 unique&quot;? (this is not a rhetorical question!)

Well, it is very easy for me to just point... but I think it is worth mentioning...</description>
		<content:encoded><![CDATA[<p>It seems to me that the problem here is that &#8220;self_exec_id&#8221; is implicitly understood to be unique. But &#8220;unique&#8221; has three meanings here:</p>
<p>TYPE 1. It is IMPOSSIBLE to have collisions.<br />
TYPE 2. It is HIGHLY IMPROBABLE to have &#8220;natural&#8221; collisions.<br />
TYPE 3. It is HIGHLY IMPROBABLE to have &#8220;natural&#8221; collisions, and when it happens, it is HIGHLY IMPROBABLE we will even notice.</p>
<p>Given the fact that the self_exec_id is reset when it reaches its maximum value, we can say that the code that generates it does not understand that it is &#8220;type 1 unique&#8221;. No security check should rely on any definition of unique different from &#8220;type 1 unique&#8221;. Is it hard to always implement &#8220;type 1 unique&#8221;? (this is not a rhetorical question!)</p>
<p>Well, it is very easy for me to just point&#8230; but I think it is worth mentioning&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Escalada de privilegios remota con /proc/pid/mem write</title>
		<link>http://blog.zx2c4.com/749#comment-6482</link>
		<dc:creator>Escalada de privilegios remota con /proc/pid/mem write</dc:creator>
		<pubDate>Tue, 24 Jan 2012 12:02:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6482</guid>
		<description>[...] explicación al completo la tenéis en el blog ZX2C4 -nombre curioso, habría que buscar su explicación- en donde este experto ha explicado cómo [...]</description>
		<content:encoded><![CDATA[<p>[...] explicación al completo la tenéis en el blog ZX2C4 -nombre curioso, habría que buscar su explicación- en donde este experto ha explicado cómo [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Another root exploit for linux &#124; Scali&#039;s blog</title>
		<link>http://blog.zx2c4.com/749#comment-6481</link>
		<dc:creator>Another root exploit for linux &#124; Scali&#039;s blog</dc:creator>
		<pubDate>Tue, 24 Jan 2012 11:21:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6481</guid>
		<description>[...] A few days ago, the following exploit was published: http://blog.zx2c4.com/749 [...]</description>
		<content:encoded><![CDATA[<p>[...] A few days ago, the following exploit was published: <a href="http://blog.zx2c4.com/749" rel="nofollow">http://blog.zx2c4.com/749</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Veovis</title>
		<link>http://blog.zx2c4.com/749#comment-6479</link>
		<dc:creator>Veovis</dc:creator>
		<pubDate>Tue, 24 Jan 2012 10:19:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6479</guid>
		<description>selinux is active on my box but in permissive mode.</description>
		<content:encoded><![CDATA[<p>selinux is active on my box but in permissive mode.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Veovis</title>
		<link>http://blog.zx2c4.com/749#comment-6478</link>
		<dc:creator>Veovis</dc:creator>
		<pubDate>Tue, 24 Jan 2012 10:18:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6478</guid>
		<description>Does not pown Gentoo Hardened (grsec+selinux-rbac) on kernel 3.1.5 x64 with last git commit at that time.</description>
		<content:encoded><![CDATA[<p>Does not pown Gentoo Hardened (grsec+selinux-rbac) on kernel 3.1.5 x64 with last git commit at that time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Nächstes Treffen am 03.02.2012 &#124; Chaostreff Salzburg</title>
		<link>http://blog.zx2c4.com/749#comment-6476</link>
		<dc:creator>Nächstes Treffen am 03.02.2012 &#124; Chaostreff Salzburg</dc:creator>
		<pubDate>Tue, 24 Jan 2012 09:06:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6476</guid>
		<description>[...] Linux: Root-Rechte durch Speicherzugriff [mehr] [...]</description>
		<content:encoded><![CDATA[<p>[...] Linux: Root-Rechte durch Speicherzugriff [mehr] [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux 本地提权漏洞 &#187; GAL(grep art life)</title>
		<link>http://blog.zx2c4.com/749#comment-6475</link>
		<dc:creator>Linux 本地提权漏洞 &#187; GAL(grep art life)</dc:creator>
		<pubDate>Tue, 24 Jan 2012 08:20:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6475</guid>
		<description>[...] 读 LWN 新闻时看到了 Linux 内核的一个本地提权漏洞。zx2c4 博客有详细介绍，强烈建议阅读。 [...]</description>
		<content:encoded><![CDATA[<p>[...] 读 LWN 新闻时看到了 Linux 内核的一个本地提权漏洞。zx2c4 博客有详细介绍，强烈建议阅读。 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by CVE-2012-0056 &#8211; Mempodipper, a linux local root exploit.</title>
		<link>http://blog.zx2c4.com/749#comment-6474</link>
		<dc:creator>CVE-2012-0056 &#8211; Mempodipper, a linux local root exploit.</dc:creator>
		<pubDate>Tue, 24 Jan 2012 08:18:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6474</guid>
		<description>[...] 分析原文：Linux Local Privilege Escalation via SUID /proc/pid/mem Write [...]</description>
		<content:encoded><![CDATA[<p>[...] 分析原文：Linux Local Privilege Escalation via SUID /proc/pid/mem Write [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Jason Donenfeld</title>
		<link>http://blog.zx2c4.com/749#comment-6473</link>
		<dc:creator>Jason Donenfeld</dc:creator>
		<pubDate>Tue, 24 Jan 2012 08:00:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6473</guid>
		<description>Well, just implemented this. It now exploits Gentoo, even with no read permissions on /bin/su.</description>
		<content:encoded><![CDATA[<p>Well, just implemented this. It now exploits Gentoo, even with no read permissions on /bin/su.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Jason Donenfeld</title>
		<link>http://blog.zx2c4.com/749#comment-6472</link>
		<dc:creator>Jason Donenfeld</dc:creator>
		<pubDate>Tue, 24 Jan 2012 08:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6472</guid>
		<description>Okay. I just implemented this. It now pwn&#039;s gentoo even with no read permissions on /bin/su.</description>
		<content:encoded><![CDATA[<p>Okay. I just implemented this. It now pwn&#8217;s gentoo even with no read permissions on /bin/su.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#8230; &#124; Tech Unleashed</title>
		<link>http://blog.zx2c4.com/749#comment-6470</link>
		<dc:creator>Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#8230; &#124; Tech Unleashed</dc:creator>
		<pubDate>Tue, 24 Jan 2012 06:20:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6470</guid>
		<description>[...] Follow this link: Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] Follow this link: Linux Local Privilege Escalation via SUID /proc/pid/mem Write &#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Archie</title>
		<link>http://blog.zx2c4.com/749#comment-6468</link>
		<dc:creator>Archie</dc:creator>
		<pubDate>Tue, 24 Jan 2012 03:34:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6468</guid>
		<description>Why it is an issue for someone that THIS program does not work for their system?  Article itself explains clearly why this kind of attact works and how to fix program if there is something different in their system.  Anyway it is just proof of consept showing that there is a problem.</description>
		<content:encoded><![CDATA[<p>Why it is an issue for someone that THIS program does not work for their system?  Article itself explains clearly why this kind of attact works and how to fix program if there is something different in their system.  Anyway it is just proof of consept showing that there is a problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by local suid in linux ;) &#124; deranfangvomen.de</title>
		<link>http://blog.zx2c4.com/749#comment-6467</link>
		<dc:creator>local suid in linux ;) &#124; deranfangvomen.de</dc:creator>
		<pubDate>Mon, 23 Jan 2012 23:07:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6467</guid>
		<description>[...] http://blog.zx2c4.com/749 [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://blog.zx2c4.com/749" rel="nofollow">http://blog.zx2c4.com/749</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Mempodipper &#8211; Root-Rootrechte durch Speicherzugriff &#124; Embedded Engineering Blog</title>
		<link>http://blog.zx2c4.com/749#comment-6466</link>
		<dc:creator>Mempodipper &#8211; Root-Rootrechte durch Speicherzugriff &#124; Embedded Engineering Blog</dc:creator>
		<pubDate>Mon, 23 Jan 2012 22:37:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6466</guid>
		<description>[...] Linux-Systems sofort Root-Rechte. Eine genauere Erklärung, was da passiert, liefert der Artikel Nerdling Sapple von ZX2C4. Leider kam schon ein Systemupdate rein, auf Linux 3.0.0-15-generic #26-Ubuntu [...]</description>
		<content:encoded><![CDATA[<p>[...] Linux-Systems sofort Root-Rechte. Eine genauere Erklärung, was da passiert, liefert der Artikel Nerdling Sapple von ZX2C4. Leider kam schon ein Systemupdate rein, auf Linux 3.0.0-15-generic #26-Ubuntu [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Jason</title>
		<link>http://blog.zx2c4.com/749#comment-6465</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Mon, 23 Jan 2012 22:28:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6465</guid>
		<description>Not the case. it&#039;s possible to determine the offsets using ptrace, even on hardened gentoo. See the full-disclosure discussion for details.</description>
		<content:encoded><![CDATA[<p>Not the case. it&#8217;s possible to determine the offsets using ptrace, even on hardened gentoo. See the full-disclosure discussion for details.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Linux Local Privilege Escalation via SUID /proc/pid/mem Write by Linux local root exploit via SUID - Tux-planet</title>
		<link>http://blog.zx2c4.com/749#comment-6464</link>
		<dc:creator>Linux local root exploit via SUID - Tux-planet</dc:creator>
		<pubDate>Mon, 23 Jan 2012 22:26:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.zx2c4.com/?p=749#comment-6464</guid>
		<description>[...] Les explications sont ici : http://blog.zx2c4.com/749 [...]</description>
		<content:encoded><![CDATA[<p>[...] Les explications sont ici : <a href="http://blog.zx2c4.com/749" rel="nofollow">http://blog.zx2c4.com/749</a> [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

