[fyre@box3n.gumbynet.org: Re: ld-2.1.3.so allows users to run programs from noexec partition]
Geoff Keating
geoffk@cygnus.com
Tue Sep 5 11:18:00 GMT 2000
> Date: Tue, 5 Sep 2000 10:01:22 -0400
> From: Daniel Jacobowitz <dmj+@andrew.cmu.edu>
> On Mon, Sep 04, 2000 at 08:27:15PM -0400, Ben Collins wrote:
> > Just a question, what's to stop anyone from copying their own ld.so to ~/
> > and using it? What I mean is, isn't the problem in the kernel and not
> > glibc (where fs options should be enforced just like read and write
> > perms)? Even going to the kernel, nothing stops someone from copying an
> > executable to their local ~/ and adding +x and then executing it. So
> > basically, the only thing noexec really cures is +s, and even then should
> > still be the fs (i.e. kernel) that enforces it.
>
> Well, that doesn't work if /home is mounted noexec. Isn't that the
> whole point?
There's also LD_LIBRARY_PATH and LD_PRELOAD; and plugins for
applications; and gdb; and bugs in programs that let you execute
arbitrary code.
--
- Geoffrey Keating <geoffk@cygnus.com>
More information about the Libc-alpha
mailing list