Hacker News new | past | comments | ask | show | jobs | submit login

Did you try if you can do something else beside the echo on Ubuntu? dhclient runs under an AppArmor profile which tries to keep it in a pretty short leash.



Nope dhclient running under apparmor profile is still vulnerable. I was able to execute linux commands like rm, wget, chmod...


Interesting! Hopefully someone will post an investigation on what goes wrong in AppArmor here.


No, I didn't try that, but we happen to be running a custom kernel that doesn't include AppArmor support, as we needed to pull in a newer upstream kernel version. Given this issue, we should probably revisit that decision.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: