[Full-Disclosure] Re: ABfrag followup / WITHOUT ATTACHMENT

From: enigmatic-arcanum@another.com
Date: 10/25/02


From: enigmatic-arcanum@another.com (enigmatic-arcanum@another.com)
Date: Fri, 25 Oct 2002 01:47:56 +0100 (BST)


------=_Part_4740_4908378.1035506876803
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

>As for the gateway machine itself; it was running no server processes and
>has very little client activity - only the occasional reboot or reconfiguration.
>We had installed the 'grsec' security patch and had enabled non-executable
>user pages as a precaution against intrustion. Due to performance hits, however,
>we had not enabled ET_DYN or non-executable kernel pages.
>

Oh, you're confident that openwall-alike patches will solve your problem ? good.

I wouldn't consider installing grsecurity in order to overcome this specific matter, here goes some hints:

1. Openwall-alike patches will certainly not do anything against this problem. Take alook at the patch:

 #ifdef CONFIG_GRKERNSEC_STACK
 /* Check if it was return from a signal handler */
         if ((regs->xcs & 0xFFFF) == __USER_CS)
         if (*(unsigned char *)regs->eip == 0xC3)
<....>

does __USER_CS rings a bell? it stands for "USER CODE SEGMENT", i still don't *clearly* see any __KERNEL_CS in there :-)

Based on my previous post, which for some reason have not been moderated by our bugtraq' hangman^H^H^H^H^H^H^Hmoderator, for those wondering what was in there take a look here: http://lists.netsys.com/pipermail/full-disclosure/2002-October/002577.html

2. I would have the feeling that the vulnerability existed on grsecurity rather than on Linux (hint ;-)

3. Even if you had non-exec stack turned on, you wouldn't for sure have non-exec heap and none of the underground descriptions of this aparent vulnerability mentions stack or heap, so in resume, you're as vulnerable with the patch or without it, unless my above hint holds true. ;-)

>Yours,
>Daniel Roberts
>Head Network Manager

--
Enigmatic Arcanum
--
Personalised email by http://another.com
------=_Part_4740_4908378.1035506876803--


Relevant Pages

  • RE: Windows to Oracle
    ... I don't have the Oracle client on that m/c, ... and I finally got the connection to work after installing ... it that I intend to make - after I've found how big it is... ... Thanks to the list for general nudges and hints rather than ...
    (perl.dbi.users)
  • Re: KB911280 Breaks DUN
    ... Once again it appears that another bunch of updates are causing havoc??? ... security patch from Windows Update, rebooted and tried dialing out but got ... installing KB911280. ... My local proxy settings and some of the Advanced & Security settings in IE had been reset. ...
    (microsoft.public.windowsxp.general)
  • RE: code red---- on system that is already (and has been) patched
    ... security patch but have not yet removed the relevant script mappings from ... in itself prove the success or failure of the attack. ... As your customer might already know, just installing patches does not by ...
    (Focus-Microsoft)
  • Re: Security Update for Windows XP (KB835732)
    ... > the KB835732 security patch on my computer. ... Your Cryptographic Service is most likely running fine, ... The Catroot2 problem can be avoided in the future by installing Q817287. ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
    (microsoft.public.security.virus)
  • Cannot shutdown / restart the stystem
    ... is caused after installing a security patch or service ... pack, this problem occurs typically because one of the ... blinking cursor towards the left hand side of the screen. ...
    (microsoft.public.win2000.registry)