[apparmor] openSUSE Summit

Christian Boltz apparmor at cboltz.de
Fri Apr 6 14:23:34 UTC 2012


Hallo Leute,

Am Freitag, 6. April 2012 schrieb Frankie Onuonga:
> I know you normally get busy so just thought I would remind you on the
> slides you guys said you will send .

I hoped that someone explains why my "hello world" script (see below) is 
insecure before sending them ;-) - but you can/should still answer that, 
the answer isn't in the slides *eg*

You can download my slides at
http://blog.cboltz.de/uploads/linuxtag2009/apparmor-in-der-praxis.pdf
(german - I didn't have time to translate them yet)

If you want the slides in OpenOffice/LibreOffice format, just ask.
I can also provide translations for specific slides if needed - but 
please give me some days to do it ;-)

Oh, BTW: You might wonder why I'm using dog pictures on the slides about 
ix/Cx/Px/Ux. It's a little pun - the german word "ausführen" translates 
to "execute" - and also to "take the dog for a walk" ;-)  (besides that, 
the world has seen enough cat content already ;-)

> >>>> On 03/31/2012 02:00 AM, Christian Boltz wrote:
> >>> #!/bin/bash
> >>> echo "Hello World!" > /tmp/hello.txt
> >>> cat /tmp/hello.txt
> >>> rm /tmp/hello.txt
> >>> 
> >>> Then try to exploit the script (anyone knows how to do that? ;-)

Any idea?


Regards,

Christian Boltz
-- 
>> Ich an seiner Stelle hätte den Fotografen reallife geplonkt.
> Wie entsteht denn in "reallife" dein *PLONK*? Beim Einschlag der
> Faust auf dem Auge?
man "Ernst August"    [Torsten Wiens und Cornell Binder in datr-s]




More information about the AppArmor mailing list