Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interface foron access scanning

From: Alan Cox
Date: Tue Aug 05 2008 - 07:41:20 EST


> > It may be possible to do in glibc, LD_PRELOAD doesn't exactly work for
> > suid binaries
>
> Are suid binaries something that you feel is necessary to scan from?
>
> I don't see it on the list above :)

Doesn't work very well really does it - ld.so loads files too and can be
attacked.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/