Re: predictable IP ID

Alan Cox (alan@lxorguk.ukuu.org.uk)
Mon, 4 Oct 1999 16:29:35 +0100 (BST)


> What if attacked server is running a web server and is known to be
> mmap'ing static content... think about this very carefully, it is
> identical to your initial interpretation of my argument with the added
> element of being a remote attack. Many people do this and don't
> consider is remotely exploitable in any way, right?

They rely on the web server being secure. Its totally different to the
arbitary code case.

Alan

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/