nanog mailing list archives

Re: one shot remote root for linux?


From: "andrew.wallace" <andrew.wallace () rocketmail com>
Date: Tue, 28 Apr 2009 23:31:04 +0100

Why are you alining yourself with a computer hacker? I thought you
were trying to stop these guys releasing exploits in your line of
work?

Andrew

On Tue, Apr 28, 2009 at 3:10 PM, Gadi Evron <ge () linuxbox org> wrote:
This is one of them mysterious and rare cases where a non router OS
vulnerability may affect network operations.

Sometimes news finds us in mysterious yet obvious ways.

HD Moore (respected security researcher) set a status which I noticed on my
twitter:

@hdmoore reading through sctp_houdini.c - one-shot remote linux kernel
root - http://kernelbof.blogspot.com/

I asked him about it on IM, wondering if it is real:
"looks like that
but requires a sctp app to be running"

Naturally, I retweeted.

Signed,

       @gadievron





Current thread: