Forgot your password?
typodupeerror

Submission Summary: 0 pending, 1 declined, 2 accepted (3 total, 66.67% accepted)

Security

Submission + - Arbitrary Code Execution with `ldd` (catonmat.net)

pkrumins writes: The `ldd` utility is more vulnerable than you think. It’s frequently used by programmers and system administrators to determine the dynamic library dependencies of executables. Sounds pretty innocent, right? Wrong! It turns out that running `ldd` on an executable can result in executing arbitrary code. This article details how such executable can be constructed and comes up with a social engineering scenario that may lead to system compromise. I researched this subject thoroughly and found that it’s almost completely undocumented.

Slashdot Top Deals

Center meeting at 4pm in 2C-543.

Working...