Vulnerability Development mailing list archives
Re: OT? Are chroots immune to buffer overflows?
From: Greg Hunt <greg () supplyedge com>
Date: Wed, 22 May 2002 11:36:34 -0700
Looking online, I found shellcode that breaks chroot by doing a mkdir("sh") chroot("sh") chroot("../../../../../../"); then running /bin/sh Other chroot breaking shellcode online does variations of the same thing. I haven't tested this out so I can't say for sure if this works, anyone else know? Shellcode available at: http://www.groar.org/expl/linux-x86/chroot.c http://www.groar.org/expl/linux-x86/chroot1.c
I've heard of shellcode that supposedly jumps out of the chroot jail, but it's probably been fixed now (whatever bug in chroot the shellcode exploited). The buffer overflow would work (it'd overflow the buffer yes) but as to whether you'd get a shell, probably not... Unless someone dropped a bash shell in there :)
-- ------SupplyEdge------- Greg Hunt 800-733-3380 x 107 greg () supplyedge com
Current thread:
- Re: OT? Are chroots immune to buffer overflows?, (continued)
- Re: OT? Are chroots immune to buffer overflows? aazubel (May 23)
- Re: OT? Are chroots immune to buffer overflows? Valdis . Kletnieks (May 22)
- Re: OT? Are chroots immune to buffer overflows? Kalle Andersson (May 22)
- Re: OT? Are chroots immune to buffer overflows? KF (May 23)
- Re: OT? Are chroots immune to buffer overflows? Edwin Groothuis (May 22)
- Re: OT? Are chroots immune to buffer overflows? Jose Nazario (May 23)
- Re: OT? Are chroots immune to buffer overflows? Kurt Seifried (May 23)
- Re: OT? Are chroots immune to buffer overflows? Berend De Schouwer (May 22)
- Re: OT? Are chroots immune to buffer overflows? L. Walker (May 22)
- Re: OT? Are chroots immune to buffer overflows? Jan Werner (May 23)
- Re: OT? Are chroots immune to buffer overflows? Greg Hunt (May 23)
- Re: OT? Are chroots immune to buffer overflows? Birger Toedtmann (May 22)
- Re: OT? Are chroots immune to buffer overflows? sd (May 22)
- Re: OT? Are chroots immune to buffer overflows? Andreas Ferber (May 22)
- Re: OT? Are chroots immune to buffer overflows? jove (May 23)
- Re: OT? Are chroots immune to buffer overflows? Dave Ahmad (May 23)
- Message not available
- Re: OT? Are chroots immune to buffer overflows? Jason Haar (May 23)
- Re: OT? Are chroots immune to buffer overflows? dev-null (May 22)
- RE: OT? Are chroots immune to buffer overflows? Stuart Adamson (May 22)
- RE: OT? Are chroots immune to buffer overflows? Steve Bremer (May 23)
- Re: OT? Are chroots immune to buffer overflows? Adam Lydick (May 23)