Re: Linux proc exploit

Harald Koenig (koenig@tat.physik.uni-tuebingen.de)
Thu, 27 Nov 1997 11:04:56 +0100


On Nov 26, D.P.Simpson@ecs.soton.ac.uk wrote:

>
> The slternative fix is to only allow /proc to be mounted once.
> (Oops! I should have said only allow mounting of the proc filing system once).

IMHO this would be a Bad Thing! I'm using different system trees
with chroot (say one complete ELF and one complete a.out system)
to have different system personalities online at the same time
and I need procfs in every of these `personality trees'
(so e.g. /proc for the base system, /aout/proc for a.out personality,
/sysv/proc for ...)

Harald

--
All SCSI disks will from now on                     ___       _____
be required to send an email notice                0--,|    /OOOOOOO\
24 hours prior to complete hardware failure!      <_/  /  /OOOOOOOOOOO\
                                                    \  \/OOOOOOOOOOOOOOO\
                                                      \ OOOOOOOOOOOOOOOOO|//
Harald Koenig,                                         \/\/\/\/\/\/\/\/\/
Inst.f.Theoret.Astrophysik                              //  /     \\  \
koenig@tat.physik.uni-tuebingen.de                     ^^^^^       ^^^^^