3 ms·
It doesn't stop the exploit, as it is still possible to use ptrace to essentially dump the binary, even though it's not readable.
by rzhou 15y ago
It doesn't stop the exploit, as it is still possible to use ptrace to essentially dump the binary, even though it's not readable.
- ahv 15y agoOr if you know the distro, it is trivial to get the package containing the su executable and locate the address.
- kmm 15y agoI compiled it myself, so that is not an option.
- burgerbrain 15y agoPresumably they only need to guess the flags you used then. There is really not all that much entropy there. And I suspect doing so is fairly uncommon in production environments anyway.