Featured Worklog

Price Search



PC Apex Sponsor


PC Apex Sponsors



PC Apex RSS Feeds

RSS Feed for PC Apex Reviews & ArticlesRSS Feed for PC Apex PC Modding WorklogsRSS Feed for the PC Apex Daily DisturbanceRSS Feed for the latest PC Apex Site NewsRSS Feed for PC Apex Affiliate and Web NewsRSS Feed for PC Apex Deals and Steals

Go Back   Apex Community Forums // PC Apex Forums // PC Apex News // PC Apex Member Posted News

PC Apex Member Posted News Tech and other news from around the web and around the world posted by PCApex Members.

Reply
 
LinkBack Thread Tools Display Modes
Old 14-August-09, 10:04 AM   #1 (permalink)
PcApEX's PuNK ROckER
THRiLL KiLL's Avatar
Default Linux Kernal 2.4 / 2.6 has expliot that makes linux just like windows!

Quote:
It's the end of the world. Again. According to some Linux developers and security researchers, a bug in the Linux kernel has just been uncovered that makes just about every distribution utilizing kernel 2.4 and 2.6 on just about all architectures since May of 2001 vulnerable to a certain kind of attack.

I'm not any sort of developer, so basically all of this makes no sense to me except that whatever comprises the aforementioned bug allows an attacker to escalate local privileges and completely compromise the entire system. Julien Tinnes, a security researcher who does know his way around kernel code, wrote the following details about the bug.

Quote:
At first sight, the code in af_ipx.c looks correct and seems to initialize .sendpage properly. However, due to a bug in the SOCKOPS_WRAP macro, sock_sendpage will not be initialized. This code is very fragile and there are many other protocols where proto_ops are not correctly initialized at all (vulnerable even without the bug in SOCKOPS_WRAP)... Since it leads to the kernel executing code at NULL, the vulnerability is as trivial as it can get to exploit: an attacker can just put code in the first page that will get executed with kernel privileges.Since it leads to the kernel executing code at NULL, the vulnerability is as trivial as it can get to exploit: an attacker can just put code in the first page that will get executed with kernel privileges.

Quote:
Rodney Taylor, from security research at Secorix, said that the bug "passes my it's-not-crying-wolf test so far," and that he'd definitely check his enterprise Linux systems (providing he had any), see if it was related, and see if he needed to get a patch.
Lucky for us, there already is a patch, and it should be implemented into all future kernels from here on out.


they fixed it, but just like windows, many people wont patch it.

and who said you couldnt hack linux =P
THRiLL KiLL is offline     Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux-Gamers :. NVIDIA SLI: Linux vs. Windows Gizmo Linux-Gamers RSS 0 29-September-07 06:40 AM
Linux-Gamers :. NVIDIA GeForce 8: Linux vs. Windows Gizmo Linux-Gamers RSS 0 19-July-07 12:51 PM
Linux-Gamers :. Final exam poll: "switching from windows to linux" Gizmo Linux-Gamers RSS 0 23-December-06 07:45 AM
Linux-Gamers :. Online-Poll "switching from windows to linux" Gizmo Linux-Gamers RSS 0 22-November-06 03:45 PM
Windows Media Makes Its Way to Linux scapegoat PC Apex Web News 0 09-April-03 04:57 AM


All times are GMT -5. The time now is 09:18 AM.


Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.0
Copyright PCApex.com, GameApex.com, ForumApex.com 2001 - 2008
Advertisements

Page generated in 0.12918 seconds with 9 queries