Slashdot Mirror


Cambridge Researcher Breaks OpenBSD Systrace

An anonymous reader writes "University of Cambridge researcher Robert Watson has published a paper at the First USENIX Workshop On Offensive Technology in which he describes serious vulnerabilities in OpenBSD's Systrace, Sudo, Sysjail, the TIS GSWTK framework, and CerbNG. The technique is also effective against many commercially available anti-virus systems. His slides include sample exploit code that bypasses access control, virtualization, and intrusion detection in under 20 lines of C code consisting solely of memcpy() and fork(). Sysjail has now withdrawn their software, recommending against any use, and NetBSD has disabled Systrace by default in their upcoming release."

2 of 194 comments (clear)

  1. Apposite by frisket · · Score: 0, Offtopic

    Offensive Technology

    Microsoft Windows?

  2. MOD PARENT DOWN!! by Anonymous Coward · · Score: 0, Offtopic

    This is frickin' stupid. Nice try at ripping off the CARRIER LOST template, but you should at least copy and paste it if you don't understand where it came from.