Vulnerability Development mailing list archives
Re: Core Dump as an Intrusion Event
From: Pascal Bouchareine <pb () GROLIER FR>
Date: Thu, 5 Oct 2000 17:31:34 +0200
So true.
Many crontabs used to do a find / -name core -exec rm -f {} \;
Services core dumps would ideally be analyzed by a system administrator.
If not to notice (a bit late ?) an intrusion attempt, to fix bugs in his
applications.
Core dump notification sounds generally good to me. Even a false-true
is interesting to look at :)
An annoying point is, *many* usual daemons have complex memory leaks,
and often core dump after a long period of running time. This is often
very hard to analyze and fix.
On Thu, Oct 05, 2000 at 07:00:15AM -0700, Crispin Cowan wrote:
Anyone have practical comments on this hypothesis? In practice, how often do services dump core for non-security reasons? If services dump core for non-security reasons even just a little, then the false-positive rate of intrusion detection from this clue gets out of control. Caveat: I know that this is a bad heuristic for Windows machines :-)
--
Kalou.
ldiq t0, 0xbeeffedadeadbabe
Current thread:
- Core Dump as an Intrusion Event Crispin Cowan (Oct 05)
- Re: Core Dump as an Intrusion Event Alexander Kiwerski (Oct 05)
- Re: Core Dump as an Intrusion Event antirez (Oct 05)
- Re: Core Dump as an Intrusion Event Slawek (Oct 05)
- Re: Core Dump as an Intrusion Event Pascal Bouchareine (Oct 05)
- Re: Core Dump as an Intrusion Event Crist Clark (Oct 05)
- Re: Core Dump as an Intrusion Event W. Reilly Cooley (Oct 05)
- Re: Core Dump as an Intrusion Event Eclipse, Solar (Oct 05)
- Re: Core Dump as an Intrusion Event Erik Tayler (Oct 06)
- Re: Core Dump as an Intrusion Event Jarno Huuskonen (Oct 06)
- Re: Core Dump as an Intrusion Event Crist Clark (Oct 07)
- Re: Core Dump as an Intrusion Event Kev (Oct 07)
- Re: Core Dump as an Intrusion Event antirez (Oct 08)
- Re: Core Dump as an Intrusion Event Jarno Huuskonen (Oct 08)
- Re: Core Dump as an Intrusion Event Gigi Sullivan (Oct 09)
