<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Disqus - Latest Comments for Spender2001</title><link>http://disqus.com/by/Spender2001/</link><description></description><atom:link href="http://disqus.com/Spender2001/comments.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Fri, 14 Aug 2009 12:27:57 -0000</lastBuildDate><item><title>Re: Another Linux Kernel Flaw Emerges</title><link>http://threatpost.com/blogs/another-linux-kernel-flaw-emerges-114#comment-14838748</link><description>&lt;p&gt;My exploit still defeats SELinux on the latest updated kernels:&lt;br&gt;It works on all 2.4/2.6, x86, x64, 4k stacks, 8k stacks, creds support or not, bypasses mmap_min_addr if they're still unpatched to that, disables SELinux, AppArmor, LSM, auditing, etc.&lt;/p&gt;&lt;p&gt;&lt;a href="http://grsecurity.net/~spender/wunderbar_emporium.tgz" rel="nofollow noopener" target="_blank" title="http://grsecurity.net/~spender/wunderbar_emporium.tgz"&gt;http://grsecurity.net/~spen...&lt;/a&gt;&lt;/p&gt;&lt;p&gt;-Brad&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Spender2001</dc:creator><pubDate>Fri, 14 Aug 2009 12:27:57 -0000</pubDate></item><item><title>Re: Researcher Uses New Linux Kernel Flaw to Bypass SELinux, Other Protections</title><link>http://threatpost.com/blogs/researcher-uses-new-linux-kernel-flaw-bypass-selinux-other-protections#comment-12879498</link><description>&lt;p&gt;francky: It does use that (as they're credited in the exploit for it) but also a high severity vulnerability in SELinux that I discovered.  That SELinux vulnerability likely exists on all systems using SELinux right now and is more relevant I think to users right now than this actual particular exploit.&lt;/p&gt;&lt;p&gt;-Brad&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Spender2001</dc:creator><pubDate>Sat, 18 Jul 2009 11:10:11 -0000</pubDate></item><item><title>Re: Researcher Uses New Linux Kernel Flaw to Bypass SELinux, Other Protections</title><link>http://threatpost.com/blogs/researcher-uses-new-linux-kernel-flaw-bypass-selinux-other-protections#comment-12831610</link><description>&lt;p&gt;Actually, I posted the first null ptr dereference exploit for Linux in 2007, similarly disabling SELinux and LSM, as noted in the exploit.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Spender2001</dc:creator><pubDate>Fri, 17 Jul 2009 16:15:32 -0000</pubDate></item></channel></rss>