On Mon, Dec 22, 2003 at 08:35:36PM -0000, Lu�s Miguel Silva wrote:
>    Hello all,
> 
>    I  know  the do_brk vulnerability is "a thing of the past" but, I just
>    tried out the exploit on one of my vservers just to see what happened.

[exploit attempt censored ;]

>    And  now for a developer question: is a local kernel root exploit able
>    to break the vserver environment?

depends on the kind of exploit ...

approaches modifying kernel structures could
be used to 'escape' the context, thus gaining
host administator powers ...

>    If  a  normal  user was to successfully exploit a vserver with a local
>    exploit would he:

assumed that the user uses an exploit tool which
works on a 'normal' machine, he probably will gain
root on the vserver, if he adapts this, and manages
to modify task/context structures, he will become
root on the host ...

>    a)       be root on the vserver?
> 
>    b)       Be root on the root server?
> 
>    c)       None of the above. 
>             Aliens would invade earth and it would
>             rain chocolate candy...heh

that's my favorite, so I'll go for c)

merry xmas,
Herbert

>    Best,
> 
>    +-------------------------------------------
> 
>    | Lu�s Miguel Silva
> 
>    | Network Administrator@ ISPGaya.pt
> 
>    | Rua Ant�nio Rodrigues da Rocha, 291/341
> 
>    | Sto. Ov�dio o 4400-025 V. N. de Gaia
> 
>    | Portugal
> 
>    | T: +351 22 3745730/3/5  F: +351 22 3745738
> 
>    | G: +351 93 6371253      E: [EMAIL PROTECTED]
> 
>    | H: http://lms.ispgaya.pt/
> 
>    +-------------------------------------------
_______________________________________________
Vserver mailing list
[EMAIL PROTECTED]
http://list.linux-vserver.org/mailman/listinfo/vserver

Reply via email to