this post was submitted on 01 Jul 2024
242 points (98.8% liked)

Linux

5409 readers
124 users here now

A community for everything relating to the linux operating system

Also check out [email protected]

Original icon base courtesy of [email protected] and The GIMP

founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] [email protected] 27 points 5 months ago (1 children)

the in depth technical details

TL;DR; sigalarm handler calls syslog which isn't safe to call from a signal handler context.

Their example exploit needed about 10k attempts to get a remote shell so it's not fast or quiet, but a neat find regardless

[โ€“] [email protected] 5 points 5 months ago

I can already imagine the log generated will be a hint. We usually automate those anyway as it is closer to (D)DoS too.