University of Cambridge > Talks.cam > Computer Laboratory Security Group meeting presentations > Exploiting concurrency vulnerabilities in system call wrappers

Exploiting concurrency vulnerabilities in system call wrappers

Add to your list(s) Download to your calendar using vCal

If you have a question about this talk, please contact Steven J. Murdoch.

Practice talk for USENIX Security WOOT

System call interposition allows the kernel security model to be extended. However, when combined with current operating systems, it is open to concurrency vulnerabilities leading to privilege escalation and audit bypass. We discuss the theory and practice of system call wrapper concurrency vulnerabilities, and demonstrate exploit techniques against GSWTK , Systrace, and CerbNG.

This talk is part of the Computer Laboratory Security Group meeting presentations series.

Tell a friend about this talk:

This talk is included in these lists:

Note that ex-directory lists are not shown.

 

© 2006-2024 Talks.cam, University of Cambridge. Contact Us | Help and Documentation | Privacy and Publicity