Exploiting concurrency vulnerabilities in system call wrappers

  • Authors:
  • Robert N. M. Watson

  • Affiliations:
  • Computer Laboratory, University of Cambridge

  • Venue:
  • WOOT '07 Proceedings of the first USENIX workshop on Offensive Technologies
  • Year:
  • 2007

Quantified Score

Hi-index 0.02

Visualization

Abstract

System call interposition allows the kernel security model to be extended. However, when combined with current operating systems, it is open to concurrency vulnerabilities leading to privilege escalation and audit bypass. We discuss the theory and practice of system call wrapper concurrency vulnerabilities, and demonstrate exploit techniques against GSWTK, Systrace, and CerbNG.