<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Linux vmsplice Local Root Exploit; Before &amp; After Kernel Update</title>
	<atom:link href="http://blog.irwan.name/?feed=rss2&#038;p=444" rel="self" type="application/rss+xml" />
	<link>http://blog.irwan.name/?p=444</link>
	<description>Through passion, I gain strength. Through strength, I gain power. Through power, I gain victory.</description>
	<lastBuildDate>Wed, 01 Sep 2010 02:56:41 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: piju</title>
		<link>http://blog.irwan.name/?p=444&#038;cpage=1#comment-24406</link>
		<dc:creator>piju</dc:creator>
		<pubDate>Sun, 17 Feb 2008 19:43:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.irwan.name/?p=444#comment-24406</guid>
		<description>*sekalian</description>
		<content:encoded><![CDATA[Using <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/iceweasel.png' alt='Debian IceWeasel' width='14' height='14' class='browsericon' /> Debian IceWeasel 2.0.0.11 on  <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/debian.png' alt='Debian GNU/Linux' width='14' height='14' class='browsericon' />  Debian GNU/Linux<p>
*sekalian</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: piju</title>
		<link>http://blog.irwan.name/?p=444&#038;cpage=1#comment-24404</link>
		<dc:creator>piju</dc:creator>
		<pubDate>Sun, 17 Feb 2008 19:43:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.irwan.name/?p=444#comment-24404</guid>
		<description>jgn lupa wahai ikan patin sekalin...</description>
		<content:encoded><![CDATA[Using <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/iceweasel.png' alt='Debian IceWeasel' width='14' height='14' class='browsericon' /> Debian IceWeasel 2.0.0.11 on  <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/debian.png' alt='Debian GNU/Linux' width='14' height='14' class='browsericon' />  Debian GNU/Linux<p>
jgn lupa wahai ikan patin sekalin&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dolphin</title>
		<link>http://blog.irwan.name/?p=444&#038;cpage=1#comment-24374</link>
		<dc:creator>dolphin</dc:creator>
		<pubDate>Sun, 17 Feb 2008 17:36:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.irwan.name/?p=444#comment-24374</guid>
		<description>ah,
kalo berkaitan dengan temerloh / patin.
korang berdua la sasaran aku</description>
		<content:encoded><![CDATA[Using <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/firefox.png' alt='Mozilla Firefox' width='14' height='14' class='browsericon' /> Mozilla Firefox 2.0.0.12 on  <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/linux.png' alt='Linux' width='14' height='14' class='browsericon' />  Linux<p>
ah,<br />
kalo berkaitan dengan temerloh / patin.<br />
korang berdua la sasaran aku</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xanda</title>
		<link>http://blog.irwan.name/?p=444&#038;cpage=1#comment-24302</link>
		<dc:creator>xanda</dc:creator>
		<pubDate>Sun, 17 Feb 2008 11:52:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.irwan.name/?p=444#comment-24302</guid>
		<description>Gentoo rocks.. (once upon a time)

owh ya... tokey ikan patin pakai gentoo</description>
		<content:encoded><![CDATA[Using <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/safari.png' alt='Safari' width='14' height='14' class='browsericon' /> Safari 521.24 on  <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/macos.png' alt='Mac OS' width='14' height='14' class='browsericon' />  Mac OS X<p>
Gentoo rocks.. (once upon a time)</p>
<p>owh ya&#8230; tokey ikan patin pakai gentoo</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: irwan</title>
		<link>http://blog.irwan.name/?p=444&#038;cpage=1#comment-24289</link>
		<dc:creator>irwan</dc:creator>
		<pubDate>Sun, 17 Feb 2008 10:36:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.irwan.name/?p=444#comment-24289</guid>
		<description>&lt;b&gt;Xanda &amp; Piju/Dolphin,&lt;/b&gt;
Sesungguhnya ikan patin tidak bersalah dalam hal ini. Ikan patin juga tiada kena mengena dengan Linux vmsplice Local Root Exploit &amp; yg paling penting, ikan patin tidak se&quot;g33k&quot; korang berdua :D

&lt;b&gt;Cae,&lt;/b&gt;
It&#039;s nice to see non-techie to use Debian. As far as I know, non-techie prefer to use Ubuntu instead of Debian. As a Singaporean, you might want to join &lt;a href=&quot;http://www.lugs.org.sg/&quot; rel=&quot;nofollow&quot;&gt;Linux User Group&lt;/a&gt; there :)</description>
		<content:encoded><![CDATA[Using <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/iceweasel.png' alt='Debian IceWeasel' width='14' height='14' class='browsericon' /> Debian IceWeasel 2.0.0.11 on  <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/debian.png' alt='Debian GNU/Linux' width='14' height='14' class='browsericon' />  Debian GNU/Linux<p>
<b>Xanda &#038; Piju/Dolphin,</b><br />
Sesungguhnya ikan patin tidak bersalah dalam hal ini. Ikan patin juga tiada kena mengena dengan Linux vmsplice Local Root Exploit &#038; yg paling penting, ikan patin tidak se&#8221;g33k&#8221; korang berdua :D</p>
<p><b>Cae,</b><br />
It&#8217;s nice to see non-techie to use Debian. As far as I know, non-techie prefer to use Ubuntu instead of Debian. As a Singaporean, you might want to join <a href="http://www.lugs.org.sg/" rel="nofollow">Linux User Group</a> there :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cae</title>
		<link>http://blog.irwan.name/?p=444&#038;cpage=1#comment-24268</link>
		<dc:creator>Cae</dc:creator>
		<pubDate>Sun, 17 Feb 2008 09:15:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.irwan.name/?p=444#comment-24268</guid>
		<description>Hi Xanda, 

now I understand why irwan is fumming :-)
he did already wrote a VERY SIMPLE howto, just that I really do not know it&#039;s there! LOL.

your 3 steps did the magic, TERIMA KASIH !

by the way, saya dak tahu malayu
hope I got the above sentence right :-)

Cheers</description>
		<content:encoded><![CDATA[Using <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/iceweasel.png' alt='Debian IceWeasel' width='14' height='14' class='browsericon' /> Debian IceWeasel 2.0.0.11 on  <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/debian.png' alt='Debian GNU/Linux' width='14' height='14' class='browsericon' />  Debian GNU/Linux<p>
Hi Xanda, </p>
<p>now I understand why irwan is fumming :-)<br />
he did already wrote a VERY SIMPLE howto, just that I really do not know it&#8217;s there! LOL.</p>
<p>your 3 steps did the magic, TERIMA KASIH !</p>
<p>by the way, saya dak tahu malayu<br />
hope I got the above sentence right :-)</p>
<p>Cheers</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dolphin</title>
		<link>http://blog.irwan.name/?p=444&#038;cpage=1#comment-24264</link>
		<dc:creator>dolphin</dc:creator>
		<pubDate>Sun, 17 Feb 2008 08:53:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.irwan.name/?p=444#comment-24264</guid>
		<description>ceh. dia nak marah buat ape</description>
		<content:encoded><![CDATA[Using <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/firefox.png' alt='Mozilla Firefox' width='14' height='14' class='browsericon' /> Mozilla Firefox 2.0.0.12 on  <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/linux.png' alt='Linux' width='14' height='14' class='browsericon' />  Linux<p>
ceh. dia nak marah buat ape</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xanda</title>
		<link>http://blog.irwan.name/?p=444&#038;cpage=1#comment-24255</link>
		<dc:creator>xanda</dc:creator>
		<pubDate>Sun, 17 Feb 2008 08:06:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.irwan.name/?p=444#comment-24255</guid>
		<description>jangan... nanti sysadmin marah</description>
		<content:encoded><![CDATA[Using <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/nokia.png' alt='Nokia' width='14' height='14' class='browsericon' /> Nokia 6630<p>
jangan&#8230; nanti sysadmin marah</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: piju</title>
		<link>http://blog.irwan.name/?p=444&#038;cpage=1#comment-24076</link>
		<dc:creator>piju</dc:creator>
		<pubDate>Sat, 16 Feb 2008 18:29:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.irwan.name/?p=444#comment-24076</guid>
		<description>woi patin2 sekalian,
aku nak siang korang</description>
		<content:encoded><![CDATA[Using <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/firefox.png' alt='Mozilla Firefox' width='14' height='14' class='browsericon' /> Mozilla Firefox 2.0.0.4 on  <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/linux.png' alt='Linux' width='14' height='14' class='browsericon' />  Linux<p>
woi patin2 sekalian,<br />
aku nak siang korang</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: piju</title>
		<link>http://blog.irwan.name/?p=444&#038;cpage=1#comment-24054</link>
		<dc:creator>piju</dc:creator>
		<pubDate>Sat, 16 Feb 2008 17:02:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.irwan.name/?p=444#comment-24054</guid>
		<description>ramai sungguh ikan patin di sini.
boleh buat kolam untuk ternak patin</description>
		<content:encoded><![CDATA[Using <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/iceweasel.png' alt='Debian IceWeasel' width='14' height='14' class='browsericon' /> Debian IceWeasel 2.0.0.11 on  <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/debian.png' alt='Debian GNU/Linux' width='14' height='14' class='browsericon' />  Debian GNU/Linux<p>
ramai sungguh ikan patin di sini.<br />
boleh buat kolam untuk ternak patin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xanda</title>
		<link>http://blog.irwan.name/?p=444&#038;cpage=1#comment-24041</link>
		<dc:creator>xanda</dc:creator>
		<pubDate>Sat, 16 Feb 2008 15:31:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.irwan.name/?p=444#comment-24041</guid>
		<description>Dear Cae,

Q: how to test if our system is affected by this security hole (which definitely is)

A: follow these steps

1) wget http://downloads.securityfocus.com/vulnerabilities/exploits/27704.c

2) gcc 27704.c -o exploit

3) ./exploit

Q: how to do the kernel update to cover this hole (a good learning experience)

A: I believe it has something to do with stack overflow where it allow normal user to perform system call to become a root. the patches might change the memory address or maybe randomize it so that the exploit wont work</description>
		<content:encoded><![CDATA[Using <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/firefox.png' alt='Mozilla Firefox' width='14' height='14' class='browsericon' /> Mozilla Firefox 2.0.0.12 on  <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/windows.png' alt='Windows' width='14' height='14' class='browsericon' />  Windows XP<p>
Dear Cae,</p>
<p>Q: how to test if our system is affected by this security hole (which definitely is)</p>
<p>A: follow these steps</p>
<p>1) wget <a href="http://downloads.securityfocus.com/vulnerabilities/exploits/27704.c" rel="nofollow">http://downloads.securityfocus.com/vulnerabilities/exploits/27704.c</a></p>
<p>2) gcc 27704.c -o exploit</p>
<p>3) ./exploit</p>
<p>Q: how to do the kernel update to cover this hole (a good learning experience)</p>
<p>A: I believe it has something to do with stack overflow where it allow normal user to perform system call to become a root. the patches might change the memory address or maybe randomize it so that the exploit wont work</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cae</title>
		<link>http://blog.irwan.name/?p=444&#038;cpage=1#comment-23727</link>
		<dc:creator>Cae</dc:creator>
		<pubDate>Fri, 15 Feb 2008 13:21:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.irwan.name/?p=444#comment-23727</guid>
		<description>Irwan, that&#039;s the funny part.

I am a totally none technical person and so your VERY SIMPLE , compile and run , is alien to me but something I am interested to learn.

Care to share :-)

Also, this shows how user friendly debian is, non-technie like me can get it installed and using as a full time desktop.</description>
		<content:encoded><![CDATA[Using <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/iceweasel.png' alt='Debian IceWeasel' width='14' height='14' class='browsericon' /> Debian IceWeasel 2.0.0.12 on  <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/debian.png' alt='Debian GNU/Linux' width='14' height='14' class='browsericon' />  Debian GNU/Linux<p>
Irwan, that&#8217;s the funny part.</p>
<p>I am a totally none technical person and so your VERY SIMPLE , compile and run , is alien to me but something I am interested to learn.</p>
<p>Care to share :-)</p>
<p>Also, this shows how user friendly debian is, non-technie like me can get it installed and using as a full time desktop.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: irwan</title>
		<link>http://blog.irwan.name/?p=444&#038;cpage=1#comment-23723</link>
		<dc:creator>irwan</dc:creator>
		<pubDate>Fri, 15 Feb 2008 12:58:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.irwan.name/?p=444#comment-23723</guid>
		<description>&lt;b&gt;Cae,&lt;/b&gt;
I&#039;ve made a VERY SIMPLE instruction in my post to see how the exploit works. You just have to download the code, compile, and run the binary as a normal user. After that, you should be able to get root.</description>
		<content:encoded><![CDATA[Using <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/iceweasel.png' alt='Debian IceWeasel' width='14' height='14' class='browsericon' /> Debian IceWeasel 2.0.0.11 on  <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/debian.png' alt='Debian GNU/Linux' width='14' height='14' class='browsericon' />  Debian GNU/Linux<p>
<b>Cae,</b><br />
I&#8217;ve made a VERY SIMPLE instruction in my post to see how the exploit works. You just have to download the code, compile, and run the binary as a normal user. After that, you should be able to get root.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cae</title>
		<link>http://blog.irwan.name/?p=444&#038;cpage=1#comment-23697</link>
		<dc:creator>Cae</dc:creator>
		<pubDate>Fri, 15 Feb 2008 10:48:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.irwan.name/?p=444#comment-23697</guid>
		<description>As I&#039;ve said earlier, my debian ( 2.6.22-3-686) installation is definitely affected :-)

Any chance of sharing a simple step by step howto to test for the security hole?</description>
		<content:encoded><![CDATA[Using <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/iceweasel.png' alt='Debian IceWeasel' width='14' height='14' class='browsericon' /> Debian IceWeasel 2.0.0.12 on  <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/debian.png' alt='Debian GNU/Linux' width='14' height='14' class='browsericon' />  Debian GNU/Linux<p>
As I&#8217;ve said earlier, my debian ( 2.6.22-3-686) installation is definitely affected :-)</p>
<p>Any chance of sharing a simple step by step howto to test for the security hole?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Irwan</title>
		<link>http://blog.irwan.name/?p=444&#038;cpage=1#comment-23649</link>
		<dc:creator>Irwan</dc:creator>
		<pubDate>Fri, 15 Feb 2008 07:33:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.irwan.name/?p=444#comment-23649</guid>
		<description>&lt;b&gt;Cae,&lt;/b&gt;

&lt;b&gt;Q: how to test if our system is affected by this security hole (which definitely is)&lt;/b&gt;
A: If you&#039;re using Kernel 2.6.17 - 2.6.24.1, then there&#039;s a high chance that you&#039;re affected.

&lt;b&gt;Q: how to do the kernel update to cover this hole (a good learning experience)&lt;/b&gt;
A: It depends on your Linux distro, consult the documentation. If RedHat-based, it&#039;s normally &quot;rpm -ivh new_kernel&quot;. If Debian-based, just &quot;apt-get update &amp;&amp; apt-get upgrade&quot;. Again, concult the docs/manual. The bottom line is; update/upgrade your kernel!</description>
		<content:encoded><![CDATA[Using <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/firefox.png' alt='Mozilla Firefox' width='14' height='14' class='browsericon' /> Mozilla Firefox 1.5.0.12 on  <img src='http://blog.irwan.name/wp-content/plugins/browser-sniff/icons/redhat.png' alt='RedHat Linux' width='14' height='14' class='browsericon' />  RedHat Linux<p>
<b>Cae,</b></p>
<p><b>Q: how to test if our system is affected by this security hole (which definitely is)</b><br />
A: If you&#8217;re using Kernel 2.6.17 &#8211; 2.6.24.1, then there&#8217;s a high chance that you&#8217;re affected.</p>
<p><b>Q: how to do the kernel update to cover this hole (a good learning experience)</b><br />
A: It depends on your Linux distro, consult the documentation. If RedHat-based, it&#8217;s normally &#8220;rpm -ivh new_kernel&#8221;. If Debian-based, just &#8220;apt-get update &amp;&amp; apt-get upgrade&#8221;. Again, concult the docs/manual. The bottom line is; update/upgrade your kernel!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
