Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfaceforon access scanning

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <tvrtko.ursulin@...>
Cc: Arjan van de Ven <arjan@...>, Adrian Bunk <bunk@...>, <davecb@...>, Greg KH <greg@...>, Press, Jonathan <Jonathan.Press@...>, <linux-kernel@...>, <linux-security-module@...>, <malware-list@...>, Mihai Don??u <mdontu@...>
Date: Thursday, August 14, 2008 - 8:56 am

On Wed 2008-08-13 15:16:12, tvrtko.ursulin@sophos.com wrote:

Yes, there are about 5 suid binaries on typical linux system. Link
them to libmalware by hand.


That is does not work?

(Neither does LD_PRELOAD; it still has the old mmap problem. Too bad,
but at least you get 99.9% coverage of all the apps). 
									Pavel
-- 
(english) http://www.livejournal.com/~pavelmachek
(cesky, pictures) http://atrey.karlin.mff.cuni.cz/~pavel/picture/horses/blog.html
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Sidebar to [malware-list] [RFC 0/5] [TALPA] Intro to a linux..., David Collier-Brown, (Wed Aug 6, 7:40 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfa..., David Collier-Brown, (Mon Aug 11, 12:11 pm)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfa..., Pavel Machek, (Thu Aug 14, 8:56 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfa..., Arjan van de Ven, (Wed Aug 13, 10:28 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interf..., David Collier-Brown, (Wed Aug 6, 7:31 am)