Security

Hacking everything, by Chris Evans / scarybeasts

Wednesday, February 25, 2009

Linux kernel minor "seccomp" vulnerability

›
I just released some technical details on why and how "seccomp" is vulnerable to the Linux kernel syscall filtering problems that ...
Tuesday, February 24, 2009

Linux kernel minor signal vulnerability

›
I recently came up with a little API abuse of the clone() system call. Not earth shattering, but definitely fun. Essentially, you can send ...
Friday, February 20, 2009

vsftpd-2.1.0 and ptrace() sandboxing

›
The new sandboxing support mentioned in the vsftpd-2.1.0 announcement post is actually a ptrace() based sandbox. It is experimental and th...
2 comments:
Wednesday, February 18, 2009

vsftpd-2.1.0 released

›
I just released vsftpd-2.1.0, with full details being available on the vsftpd web page: http://vsftpd.beasts.org/ It fixes a bunch of bugs a...
32 comments:
Friday, January 23, 2009

Bypassing syscall filtering technologies on Linux x86_64

›
For those interested in syscall filtering technologies, check out my latest advisory on how policies can be bypassed under certain circumsta...
2 comments:
Thursday, December 18, 2008

Opera, SVGs and Java applets

›
Opera 9.63 was just released with some security fixes . I reported one of these issues, but neither myself nor Tarquin (a super friendly and...
Wednesday, December 17, 2008

Firefox cross-domain text theft....

›
... and a reappearance of the "302 redirect trick". Here's the second bug from my PacSec presentation, and it's another Fi...
‹
›
Home
View web version
Powered by Blogger.