|
Caution advised when using the ldd system tool |
|
|
|
Source: H Security - Posted by Anthony Pell
|
Bugs in system utilities are not usually particularly interesting from a security point of view, but if the utility is regularly used to obtain information on suspect programs, it's a rather different story.
That's exactly what ldd, a system tool that resolves the dependencies of dynamic libraries and offers an insight into the workings of unknown programs, does. It's a standard tool for system administrators and forensic analysts. In his blog, Peteris Krumin discusses how ldd works under Linux – and how it can be exploited by the program under examination to execute arbitrary code.
Read this full article at H Security
Only registered users can write comments. Please login or register. Powered by AkoComment! |