LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-18-2005, 01:59 PM   #1
gangxiao
LQ Newbie
 
Registered: Apr 2005
Posts: 1

Rep: Reputation: 0
Sysmask security challenge


I need advanced hackers to test my new Linux security package Sysmask, by trying to break the demo page:

wims.unice.fr/wims/wims.cgi?module=adm/unice/challenge

This page accepts and executes unmoderated arbitrary codes, in c, sh or perl, and defies any attempt to read a prohibited file. Script kiddies, don't think you can easily break it! The fact that it is set up as a demo of sysmask means that this is at least extremely hard. It has received 241 "assaults" since last Thursday, including some quite ingeneous tricks, but none of them has posed even a remote threat to the security cordon.

Try anything you like with the challenge, but you are warned: it is hopeless without a ring 0 privilege elevation. And you must find one behind a very commonly used syscall!

The system is at its very beginning, with some known weaknesses and even uncorrected bugs in the public server. Even under such conditions, I believe the challenge is very close to practically unbreakable. But it is the last chance, for within a few days the weaknesses and bugs will be fixed.

I have already all my systems (all of them are Linux) protected by sysmask. All my daemons and browsers are running under similar environments as the challenge. As long as the security challenge stands, I no longer fear infiltrations nor viruses. That allows me to forget about software updates.

Sysmask is released under GPL. But it is still alpha, and lacking user interface tools. So for the time being it is only recommended to experienced sysadmins.

wims.unice.fr/sysmask/doc/
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
A challenge - See how quick you can do this. Marshalle Linux - General 1 06-14-2005 08:18 AM
Want a challenge? TruckStuff Linux - Security 2 05-13-2005 01:39 AM
here lies a challenge!!!! jayboogie Linux - Newbie 7 12-20-2004 09:41 PM
a challenge for you derfaust Programming 3 03-12-2004 12:23 AM
Bash challenge!!! Nimoy Programming 16 11-16-2003 03:30 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:20 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration