<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8992811497323121233.post5382334599747832580..comments</id><updated>2010-08-12T17:14:42.996-07:00</updated><category term='ASLR'/><category term='sandbox'/><category term='Virtualisation'/><category term='the sky is falling'/><category term='VMware'/><category term='Linux'/><category term='vulnerability'/><category term='Presentation'/><category term='seccomp'/><category term='TSC'/><category term='Windows'/><category term='Security'/><category term='NetBSD'/><category term='Java'/><category term='Apple'/><category term='side-channel'/><title type='text'>Comments on cr0 blog: Bypassing Linux' NULL pointer dereference exploit ...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.cr0.org/feeds/5382334599747832580/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/5382334599747832580/comments/default'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html'/><author><name>Julien Tinnes</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>7</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-296394368738341785</id><published>2009-12-03T15:48:02.559-08:00</published><updated>2009-12-03T15:48:02.559-08:00</updated><title type='text'>No, we fixed it on Android</title><content type='html'>No, we fixed it on Android</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/5382334599747832580/comments/default/296394368738341785'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/5382334599747832580/comments/default/296394368738341785'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html?showComment=1259884082559#c296394368738341785' title=''/><author><name>Julien Tinnes</name><uri>http://www.blogger.com/profile/05636781178145883012</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-5382334599747832580' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/5382334599747832580' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-155021837'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-183426246780533772</id><published>2009-11-30T05:25:05.352-08:00</published><updated>2009-11-30T05:25:05.352-08:00</updated><title type='text'>&amp;quot;So what we need is a setuid binary that will...</title><content type='html'>&amp;quot;So what we need is a setuid binary that will give us control back without going through exec.&amp;quot;&lt;br /&gt;&lt;br /&gt;We&amp;#39;d need to find such a binary on Android to use this method as far as I understand.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/5382334599747832580/comments/default/183426246780533772'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/5382334599747832580/comments/default/183426246780533772'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html?showComment=1259587505352#c183426246780533772' title=''/><author><name>Milo</name><uri>http://www.blogger.com/profile/04032856273646677104</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-5382334599747832580' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/5382334599747832580' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-194139560'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-6750248747298942922</id><published>2009-11-23T06:27:54.459-08:00</published><updated>2009-11-23T06:27:54.459-08:00</updated><title type='text'>Could this be used to gain root in Android? The cu...</title><content type='html'>Could this be used to gain root in Android? The current method does not work anymore, they patched mmap_min_addr.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/5382334599747832580/comments/default/6750248747298942922'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/5382334599747832580/comments/default/6750248747298942922'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html?showComment=1258986474459#c6750248747298942922' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-5382334599747832580' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/5382334599747832580' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1896140286'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-6590406992887335759</id><published>2009-08-16T14:16:54.643-07:00</published><updated>2009-08-16T14:16:54.643-07:00</updated><title type='text'>No, it&amp;#39;s not a bug in pulseaudio. It was a bug...</title><content type='html'>No, it&amp;#39;s not a bug in pulseaudio. It was a bug in the Linux kernel and we already corrected it there.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/5382334599747832580/comments/default/6590406992887335759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/5382334599747832580/comments/default/6590406992887335759'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html?showComment=1250457414643#c6590406992887335759' title=''/><author><name>Julien Tinnes</name><uri>http://www.blogger.com/profile/05636781178145883012</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-5382334599747832580' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/5382334599747832580' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-155021837'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-8017612123216659731</id><published>2009-08-16T14:10:05.467-07:00</published><updated>2009-08-16T14:10:05.467-07:00</updated><title type='text'>I would assume that this should be considered a se...</title><content type='html'>I would assume that this should be considered a security bug in pulseaudio, right? Could you please report it there?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/5382334599747832580/comments/default/8017612123216659731'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/5382334599747832580/comments/default/8017612123216659731'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html?showComment=1250457005467#c8017612123216659731' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-5382334599747832580' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/5382334599747832580' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1510040267'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-8910146202438659118</id><published>2009-07-20T14:25:26.041-07:00</published><updated>2009-07-20T14:25:26.041-07:00</updated><title type='text'>BTW the first 2 things listed in your list of thin...</title><content type='html'>BTW the first 2 things listed in your list of things you tried to do to bypass mmap_min_addr worked just fine for the first 6 months it was in the kernel ;)&lt;br /&gt;&lt;br /&gt;-Brad</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/5382334599747832580/comments/default/8910146202438659118'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/5382334599747832580/comments/default/8910146202438659118'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html?showComment=1248125126041#c8910146202438659118' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-5382334599747832580' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/5382334599747832580' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1468863757'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-3576085421076234864</id><published>2009-07-16T09:07:23.418-07:00</published><updated>2009-07-16T09:07:23.418-07:00</updated><title type='text'>Interestingly, with SELinux, it&amp;#39;s likely that ...</title><content type='html'>Interestingly, with SELinux, it&amp;#39;s likely that your SELinux policy will allow pulseaudio to mmap() at address zero anyway (seems to work on Fedora).&lt;br /&gt;&lt;br /&gt;With SELinux, you don&amp;#39;t need the personality trick, and having CVE-2009-1895 fixed is not going to help you, you need to update your policy instead.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/5382334599747832580/comments/default/3576085421076234864'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/5382334599747832580/comments/default/3576085421076234864'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html?showComment=1247760443418#c3576085421076234864' title=''/><author><name>Julien Tinnes</name><uri>http://www.blogger.com/profile/05636781178145883012</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-5382334599747832580' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/5382334599747832580' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-155021837'/></entry></feed>
