On Mon, Dec 22, 2003 at 08:35:36PM -0000, Lu�s Miguel Silva wrote: > Hello all, > > I know the do_brk vulnerability is "a thing of the past" but, I just > tried out the exploit on one of my vservers just to see what happened.
[exploit attempt censored ;] > And now for a developer question: is a local kernel root exploit able > to break the vserver environment? depends on the kind of exploit ... approaches modifying kernel structures could be used to 'escape' the context, thus gaining host administator powers ... > If a normal user was to successfully exploit a vserver with a local > exploit would he: assumed that the user uses an exploit tool which works on a 'normal' machine, he probably will gain root on the vserver, if he adapts this, and manages to modify task/context structures, he will become root on the host ... > a) be root on the vserver? > > b) Be root on the root server? > > c) None of the above. > Aliens would invade earth and it would > rain chocolate candy...heh that's my favorite, so I'll go for c) merry xmas, Herbert > Best, > > +------------------------------------------- > > | Lu�s Miguel Silva > > | Network Administrator@ ISPGaya.pt > > | Rua Ant�nio Rodrigues da Rocha, 291/341 > > | Sto. Ov�dio o 4400-025 V. N. de Gaia > > | Portugal > > | T: +351 22 3745730/3/5 F: +351 22 3745738 > > | G: +351 93 6371253 E: [EMAIL PROTECTED] > > | H: http://lms.ispgaya.pt/ > > +------------------------------------------- _______________________________________________ Vserver mailing list [EMAIL PROTECTED] http://list.linux-vserver.org/mailman/listinfo/vserver
