Reply
Cambridge Researcher Breaks OpenBSD Systrace
Old 08-09-2007, 05:50 PM Cambridge Researcher Breaks OpenBSD Systrace
TimSchroeder's Avatar
Admin/Owner

Posts: 6,142
Location: Orlando, FL
An anonymous reader writes "University of Cambridge researcher Robert Watson has published a paper at the First USENIX Workshop On Offensive Technology in which he describes serious vulnerabilities in OpenBSD's Systrace, Sudo, Sysjail, the TIS GSWTK framework, and CerbNG. The technique is also effective against many commercially available anti-virus systems. His slides include sample exploit code that bypasses access control, virtualization, and intrusion detection in under 20 lines of C code consisting solely of memcpy() and fork(). Sysjail has now withdrawn their software, recommending against any use, and NetBSD has disabled Systrace by default in their upcoming release."Read more of this story at Slashdot.
</img>


Read More about: Cambridge Researcher Breaks OpenBSD Systrace...
TimSchroeder is offline
Reply With Quote
View Public Profile Visit TimSchroeder's homepage!
 
When You Register, These Ads Go Away!
Reply     « Reply to Cambridge Researcher Breaks OpenBSD Systrace
 

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML

 


Page generated in 0.10605 seconds with 12 queries