Re: Re[2]: Apache Exploit

From: SpaceWalker (spacewalker@altern.org)
Date: 06/21/02


Date: Fri, 21 Jun 2002 01:29:24 +0200
From: SpaceWalker <spacewalker@altern.org>
To: Michal Zalewski <lcamtuf@coredump.cx>

I took a look, and I was unable to send any of those two signals to apache during the faulty memcpy().

On Thu, 20 Jun 2002 18:40:55 -0400 (EDT)
Michal Zalewski <lcamtuf@coredump.cx> wrote:
...
> This is not to say that delivering signals is not the way to exploit
> problems like that - conditions that would otherwise lead directly to SEGV
> because of access to non-allocated memory, for example. Quite
> (un)fortunately, there are only two signals that could be perhaps
> delivered to Apache (which, keep in mind, is running as a standalone
> daemon) - SIGPIPE and SIGURG - that is, if they are not ignored and if the
> handler does something interesting, which I'm not so sure about (but
> haven't looked in a while).
>
> --
> _____________________________________________________
> Michal Zalewski [lcamtuf@bos.bindview.com] [security]
> [http://lcamtuf.coredump.cx] <=-=> bash$ :(){ :|:&};:
> =-=> Did you know that clones never use mirrors? <=-=
> http://lcamtuf.coredump.cx/photo/
>



Relevant Pages

  • RE: newsyslog and apache
    ... > most-recent work on the newsyslog command. ... > up sending multiple USR1 signals to apache. ... the domain name for each logfile into the filename itself, ...
    (freebsd-questions)
  • Re: Apache Rotate Logs and Log Rotate.
    ... it safe for Syslogd to send a kill -HUP to apache? ... 1.3.x handles kill signals here: ... otherwise you'll lose logs when newsyslog rotates them. ...
    (freebsd-questions)
  • Re: singal get lost while shuting down Apache
    ... Nick Kew wrote: ... >> I'm developing an Apache 2.0.52 module that executed on Linux ... Not one of the signals Apache uses itself? ...
    (comp.infosystems.www.servers.unix)
  • Re: Protecting a mod perl 1.3 site from slow MySql processes
    ... signals wont work in a threaded mpm (shouldnt matter for you since you ... signals can conflict with apache signals (apache 1.3 uses alarm for i/o ... Then I wonder why my test code is successfully interrupting the ...
    (perl.dbi.users)

Quantcast