Hackers can exploit the Linux kernel high-risk vulnerability to attack all Linux systems.

Source: Internet
Author: User

On the same day of Microsoft's menstruation day, 8.11), foreign hackers taviso and julien disclosed a vulnerability that can attack all new and old Linux systems, including but not limited to RedHat, CentOS, Suse, Debian, ubuntu, Slackware, Mandriva, Gentoo and its derivative systems. Hackers only need to execute one command to obtain the root permission through this vulnerability. Even if SELinux is enabled, this vulnerability does not help. How simple is the Attack Vulnerability? Let's look at the figure below and see the truth.

As shown in, using this vulnerability is extremely simple and affects all Linux kernels. baoz strongly recommends that system administrators or security personnel refer to the following temporary repair solutions to prevent Linux system attacks.

1. Use Grsecurity or Pax kernel security patches and enable KERNEXEC protection.

2. Upgrade to 2.6.31-rc6 or 2.4.37.5 or later.

3. If you are using a RedHat Enterprise Linux 4/5 system or Centos4/5 system, you can use the following simple operations to prevent attacks.

Add the following content to the/etc/modprobe. conf file:

Install pppox/bin/true

Install bluetooth/bin/true

Install appletalk/bin/true

Install ipx/bin/true

Install sctp/bin/true

Obviously, the third solution is relatively simple and effective, with minimal impact on your business. If you are not familiar with compiling and installing the Linux kernel, do not use the first two solutions, otherwise, your system may never start.

Linux has such a serious vulnerability in Microsoft's menstruation, which is worth remembering. If you want to learn more about the vulnerabilities, gossip and details, visit the http://baoz.net/linux-sockops-wrap-proto-ops-local-root-exploit/.

  1. How to Use gdb to check the kernel rootkit in Linux
  2. Complete Linux Kernel Analysis-mathematical coprocessor
  3. Complete Linux Kernel Analysis --- math_emulate.c Program

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.