2012.Január 24.(K) 08:26 idÅ‘pontban pageexec@freemail.hu ezt Ã*rta:
> On 24 Jan 2012 at 2:35, Francesco R.(vivo) wrote:
>
>> BTW this in "vanilla" gentoo does not work because of the permission of
>> the su
>> file:
>> ls -l /usr/bin/su
>> -rws--x--x 1 root root 36776 18 gen 21.31 /usr/bin/su
>>
>> readelf cannot read the address, but there can be other ways to access
>> the
>> binary for example for group "disk"
>
> http://seclists.org/fulldisclosure/2012/Jan/396
>
>> hardened gentoo is un-affected as expected (but you already know)
>
> this is not quite true, what could work against grsec is an exploit that
> implemented a ret2libc style exploit coupled with bruteforcing (if the
> target suid is a PIE). i hope you're all enabling the bruteforce
> protection
> feature in grsec

.
My only concern against bruteforce protection is the possiblity of a DoS.
But it's always better to get DoSed, than to get bruteforced...
--
dr Tóth Attila, Radiológus, 06-20-825-8057
Attila Toth MD, Radiologist, +36-20-825-8057