4 ms·
The github page [0] states that "The In The Wild exploit relied on using ptrace." Now, I'm wondering what purpose ptrace serves, aside from debuggers? Why don't
by frederikvs 10y ago
The github page [0] states that "The In The Wild exploit relied on using ptrace."
Now, I'm wondering what purpose ptrace serves, aside from debuggers? Why don't we just disable this by default on production systems (where you shouldn't be debugging anyhow)?
[0] https://github.com/dirtycow/dirtycow.github.io/wiki/VulnerabilityDetails https://github.com/dirtycow/dirtycow.github.io/wiki/Vulnerab...
- CUViper 10y agoSee the SELinux boolean "deny_ptrace", and/or the sysctl "kernel.yama.ptrace_scope", and have at it. It's not just for debugging, but for any tool that needs some measure of process control. Probably the next most common ptrace-caller I know is "strace".
- aexaey 10y agoThere are a surprising number of users for ptrace. E.g. upstart uses it to count forks (presumably to mitigate fork bombs), as geofft has pointed out above.
- dllthomas 10y ago> production systems (where you shouldn't be debugging anyhow) I'm not sure about this. Ideally, yes, but if you don't know what's causing an issue it can be difficult to reproduce it, and strace can be phenomenally helpful in figuring out the cause. Of course, you could leave it off until you think you might be in such a situation.