Security Incidents mailing list archives

Re: Suspicious files in /tmp


From: Valdis.Kletnieks () vt edu
Date: Wed, 20 Jun 2007 12:47:23 -0400

On Tue, 19 Jun 2007 13:33:21 +1200, Robin Sheat said:
I think it's also the case (I don't have a noexec partition handy to test on)
that you can get around this by doing something like:
/lib/ld-linux.so.2 /tmp/mybadbinary
e.g.:
/lib/ld-linux.so.2 /bin/ls

This particular trick was closed in the 2.6.0 kernel.  I am *not* sure whether
the fix was backported to the 2.4 kernel or not.

Attachment: _bin
Description:


Current thread: