Linux local privilege escalation via SUID

According to CVE-2012-0056, linux kernel 2.6.39 and later versions is vulnerable to local privilege escalation by any local users due to the mem_write function does not properly check for permissions when writing to /proc/<pid>/mem, when ASLR is disabled.

Please take a look at this demonstration to see how it works.

Reference:

1. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0056

2. http://blog.zx2c4.com/749

 

Possibly Related [...]

CisCo : Installing the VSG ( Virutual Security Gateway ) Software from an ISO File

DETAILED STEPS

Step 1 Upload the Cisco Virtual Security Gateway ISO image to the vCenter datastore.

Step 2 From the data center in the vSphere Client menu, choose your ESX host where you want to install the Cisco Virtual Security Gateway and choose New Virtual Machine.

The Create New Virtual Machine dialog box opens.

Step [...]

Cisco : How to install SSL cert on Cisco ACS ?

Install your Trustwave SSL Certificate

Click “System Configuration” in the navigation bar and click “ACS Certificate Setup”. Click “Install ACS Certificate” and choose the “Read certificate from file” option. Then provide the full path and filename of the .cer file which was e-mailed to you by Trustwave. Also, provide the full path and filename to [...]

News : Have Facebook accounts been hacked in Bangalore?

Bangalore:  Across the world, thousands of Facebook users have been spammed. The spam is a flood of porn and violent images and other graphic content spread across the site over the past couple of days.

 

Read more Here

Possibly Related Posts:

Linux local privilege escalation via SUID CisCo : Installing the VSG ( Virutual Security Gateway ) Software from an ISO File
Cisco : How to install SSL cert on Cisco ACS ?
News : Cyber attacks hit Fujitsu local government system
News : Notorious eBay hacker gets 3-year suspended sentence

News : Hackers break SSL encryption used by millions of sites

Hackers break SSL encryption used by millions of sites ,   Beware of BEAST decrypting secret PayPal cookies

By Dan Goodin in San Francisco Posted in ID, 19th September 2011 21:10 GMT

Researchers have discovered a serious weakness in virtually all websites protected by the secure sockets layer protocol that allows attackers to silently decrypt data [...]