240
submitted 2 years ago by Blaze@lemmy.zip to c/linux@programming.dev
you are viewing a single comment's thread
view the rest of the comments
[-] lurklurk@lemmy.world 27 points 2 years ago

the in depth technical details

TL;DR; sigalarm handler calls syslog which isn't safe to call from a signal handler context.

Their example exploit needed about 10k attempts to get a remote shell so it's not fast or quiet, but a neat find regardless

[-] bitfucker@programming.dev 5 points 2 years ago

I can already imagine the log generated will be a hint. We usually automate those anyway as it is closer to (D)DoS too.

this post was submitted on 01 Jul 2024
240 points (98.8% liked)

Linux

14858 readers
688 users here now

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

founded 3 years ago
MODERATORS