Re: 2.2.0 SECURITY - *IMPORTANT*

Paul Bunyk (paul@pbunyk.physics.sunysb.edu)
Wed, 27 Jan 1999 10:15:59 -0500 (EST)


Alex Buell writes:
> Guys,
>
> Temporary workaround - type in the following:
>
> limit coredumpsize 0
>
> This will tell Linux NEVER to dump a core. Do this for accounts you think
> might do something like ldd core. =)
>
> Cheers,
> Alex

... and the bad guy will just bring coredump from another system...

BTW, 'ldd ./core' rebooted my dual PII/MMX with 2.2.0.final, ldd is
2.0.7 from stock RH5.2, but I think we can not blame
glibc/ldd/whatever userland here, it must be a kernel bug (again, bad
guy might bring ldd statically linked with "right" (for him) glibc and
kill the system. The 'core' used was from a silly C probram.

I also tried ldd on some old-old-old core file, it did not reboot, but
dumped core itself:

pbunyk:~> ldd CSE/Claudio/STree/core
ldd: warning: you do not have execution permission for `./CSE/Claudio/STree/core'
not a dynamic executable
pbunyk:~> file core
core: ELF 32-bit LSB core file of 'ld-linux.so.2' (signal 11), Intel 80386, version 1

pbunyk:~> gdb /lib/ld-linux.so.2
GNU gdb 4.17.0.4 with Linux/x86 hardware watchpoint and FPU support
Copyright 1998 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB. Type "show warranty" for details.
This GDB was configured as "i386-redhat-linux"...
(gdb) r --verify ./CSE/Claudio/STree/core
Starting program: /lib/ld-linux.so.2 --verify ./CSE/Claudio/STree/core
Cannot insert breakpoint -4:
Temporarily disabling shared library breakpoints:
-4

Program received signal SIGSEGV, Segmentation fault.
0x2aaad7dd in ?? ()

Maybe we should see what's going on in /lib/ld-linux.so.2? Might it be
related?

Paul

-- 
  ("`-''-/").___..--''"`-._   UNIX *is* user-friendly, he is just very 
   `6_ 6  )   `-.  (     ).`-.__.`) picky about who his friends are...
   (_Y_.)'  ._   )  `._ `. ``-..-'      Paul Bunyk, Research Scientist
 _..`--'_..-_/  /--'_.' ,'art by           (and part-time UN*X sysadm)
(il),-''  (li),'  ((!.-' F. Lee http://pbunyk.physics.sunysb.edu/~paul

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/