4 ms·
A malicious user could inject memstop.so into a critical system service and delay execution--Writing a wrapper script would work, along with keeping unprivilege
by d00mB0t 1y ago
A malicious user could inject memstop.so into a critical system service and delay execution--Writing a wrapper script would work, along with keeping unprivileged users from using LD_PRELOAD.
- josephcsible 1y agoIf a malicious user can control the environment of critical system services, you're already pwned. There's no actual security issue there and no value in such a wrapper script.
- d00mB0t 1y agoYou sure about that? :)
- josephcsible 1y agoCan you give a counterexample?
- coherentpony 1y agoYou are the person that made the initial claim. The burden of proof is on you, not someone else.
- josephcsible 1y agoHuh? You claimed there was a security vulnerability and I disagreed and asked for an example of it.
- giingyui 1y ago[dead]
- pjc50 1y agoIf it's a critical service running as root, there's no way you're allowed to inject stuff into it. That's already a far bigger security vulnerability. (I don't get the wrapper script suggestion, wrap what?)
- mpyne 1y agoIn addition, the link-loader already should ignore LD_PRELOAD for setuid binaries so even if you're not root but running a setuid binary, LD_PRELOAD can't help you (and if it can it's a security flaw with the link-loader).
- deleted 1y ago[deleted]