<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Linux kernel 2.6.31 perf_counter_open exploit</title>
	<atom:link href="http://redstack.net/blog/2009/09/24/linux-kernel-2631-perf_counter_open-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://redstack.net/blog/2009/09/24/linux-kernel-2631-perf_counter_open-exploit/</link>
	<description>Pirates are way cooler than Ninjas, but not as much as Samuraïs</description>
	<lastBuildDate>Sat, 26 Jun 2010 12:44:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: ties</title>
		<link>http://redstack.net/blog/2009/09/24/linux-kernel-2631-perf_counter_open-exploit/comment-page-1/#comment-8186</link>
		<dc:creator>ties</dc:creator>
		<pubDate>Sat, 31 Oct 2009 00:18:46 +0000</pubDate>
		<guid isPermaLink="false">http://redstack.net/blog/?p=70#comment-8186</guid>
		<description>Write more ! :(</description>
		<content:encoded><![CDATA[<p>Write more ! <img src='http://redstack.net/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: argp</title>
		<link>http://redstack.net/blog/2009/09/24/linux-kernel-2631-perf_counter_open-exploit/comment-page-1/#comment-7846</link>
		<dc:creator>argp</dc:creator>
		<pubDate>Sun, 18 Oct 2009 14:04:47 +0000</pubDate>
		<guid isPermaLink="false">http://redstack.net/blog/?p=70#comment-7846</guid>
		<description>Nice post.</description>
		<content:encoded><![CDATA[<p>Nice post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: core</title>
		<link>http://redstack.net/blog/2009/09/24/linux-kernel-2631-perf_counter_open-exploit/comment-page-1/#comment-7747</link>
		<dc:creator>core</dc:creator>
		<pubDate>Tue, 13 Oct 2009 21:41:32 +0000</pubDate>
		<guid isPermaLink="false">http://redstack.net/blog/?p=70#comment-7747</guid>
		<description>excellent writeup!</description>
		<content:encoded><![CDATA[<p>excellent writeup!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xipe</title>
		<link>http://redstack.net/blog/2009/09/24/linux-kernel-2631-perf_counter_open-exploit/comment-page-1/#comment-7708</link>
		<dc:creator>xipe</dc:creator>
		<pubDate>Sat, 10 Oct 2009 15:16:09 +0000</pubDate>
		<guid isPermaLink="false">http://redstack.net/blog/?p=70#comment-7708</guid>
		<description>Thank you Keen :)
- Xipe</description>
		<content:encoded><![CDATA[<p>Thank you Keen <img src='http://redstack.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
- Xipe</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Keen Observer</title>
		<link>http://redstack.net/blog/2009/09/24/linux-kernel-2631-perf_counter_open-exploit/comment-page-1/#comment-7707</link>
		<dc:creator>Keen Observer</dc:creator>
		<pubDate>Sat, 10 Oct 2009 06:16:50 +0000</pubDate>
		<guid isPermaLink="false">http://redstack.net/blog/?p=70#comment-7707</guid>
		<description>Also, credits should go to Silvio Cesare for being the first to use iret in 03, so there!</description>
		<content:encoded><![CDATA[<p>Also, credits should go to Silvio Cesare for being the first to use iret in 03, so there!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Keen Observer</title>
		<link>http://redstack.net/blog/2009/09/24/linux-kernel-2631-perf_counter_open-exploit/comment-page-1/#comment-7705</link>
		<dc:creator>Keen Observer</dc:creator>
		<pubDate>Sat, 10 Oct 2009 06:06:33 +0000</pubDate>
		<guid isPermaLink="false">http://redstack.net/blog/?p=70#comment-7705</guid>
		<description>Spender has always been out for glory, it&#039;s common news that he stole the whole grsecurity ideology, I mean -- a bug was discovered, and exploited over a week ago, and he scouts the internet for blogs that talk about it without giving credit to him and qaaz, funny how it&#039;s not qaaz that complains ;) --  Good work xipe, continue posting more, I&#039;m sure a lot of people congratulate your efforts.</description>
		<content:encoded><![CDATA[<p>Spender has always been out for glory, it&#8217;s common news that he stole the whole grsecurity ideology, I mean &#8212; a bug was discovered, and exploited over a week ago, and he scouts the internet for blogs that talk about it without giving credit to him and qaaz, funny how it&#8217;s not qaaz that complains <img src='http://redstack.net/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  &#8212;  Good work xipe, continue posting more, I&#8217;m sure a lot of people congratulate your efforts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: c</title>
		<link>http://redstack.net/blog/2009/09/24/linux-kernel-2631-perf_counter_open-exploit/comment-page-1/#comment-7574</link>
		<dc:creator>c</dc:creator>
		<pubDate>Fri, 25 Sep 2009 03:15:13 +0000</pubDate>
		<guid isPermaLink="false">http://redstack.net/blog/?p=70#comment-7574</guid>
		<description>Xipe, thanks for the walk-through. For those not familiar with kernel exploitation, it\&#039;s a good read and educational. Spender, if you read this, your code and research are top-notch, and grsecurity is a valuable addition to our world. But your apparent arrogance and harsh criticism of others, including the elitist arrogance of calling others idiots sends a big fat pointer towards your own ego-trip. I\&#039;m sure you popped out of the womb knowing everything. Cool the ego and life will be better.</description>
		<content:encoded><![CDATA[<p>Xipe, thanks for the walk-through. For those not familiar with kernel exploitation, it\&#8217;s a good read and educational. Spender, if you read this, your code and research are top-notch, and grsecurity is a valuable addition to our world. But your apparent arrogance and harsh criticism of others, including the elitist arrogance of calling others idiots sends a big fat pointer towards your own ego-trip. I\&#8217;m sure you popped out of the womb knowing everything. Cool the ego and life will be better.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xipe</title>
		<link>http://redstack.net/blog/2009/09/24/linux-kernel-2631-perf_counter_open-exploit/comment-page-1/#comment-7570</link>
		<dc:creator>xipe</dc:creator>
		<pubDate>Thu, 24 Sep 2009 18:33:44 +0000</pubDate>
		<guid isPermaLink="false">http://redstack.net/blog/?p=70#comment-7570</guid>
		<description>spender, concerning the code that doesn&#039;t work on 4k stacks ... I wrote it as documented in Understanding Linux Kernel 3th edition ... please just stop ;)
For people reading this and wanting to run the exploit on a 4k stack, you should change the &quot;movl $0xffffe000,%%eax ;&quot; with &quot;movl $0xfffff000,%%eax ;&quot;
Best regards,
- Xipe</description>
		<content:encoded><![CDATA[<p>spender, concerning the code that doesn&#8217;t work on 4k stacks &#8230; I wrote it as documented in Understanding Linux Kernel 3th edition &#8230; please just stop <img src='http://redstack.net/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br />
For people reading this and wanting to run the exploit on a 4k stack, you should change the &#8220;movl $0xffffe000,%%eax ;&#8221; with &#8220;movl $0xfffff000,%%eax ;&#8221;<br />
Best regards,<br />
- Xipe</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: spender</title>
		<link>http://redstack.net/blog/2009/09/24/linux-kernel-2631-perf_counter_open-exploit/comment-page-1/#comment-7569</link>
		<dc:creator>spender</dc:creator>
		<pubDate>Thu, 24 Sep 2009 18:17:54 +0000</pubDate>
		<guid isPermaLink="false">http://redstack.net/blog/?p=70#comment-7569</guid>
		<description>I wasn&#039;t asking credit for myself (since he obviously hadn&#039;t seen the work I had done), just for the person whose code they ripped (including the get_stack_top code which doesn&#039;t work on 4k stacks).  It&#039;s common courtesy.</description>
		<content:encoded><![CDATA[<p>I wasn&#8217;t asking credit for myself (since he obviously hadn&#8217;t seen the work I had done), just for the person whose code they ripped (including the get_stack_top code which doesn&#8217;t work on 4k stacks).  It&#8217;s common courtesy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dcl</title>
		<link>http://redstack.net/blog/2009/09/24/linux-kernel-2631-perf_counter_open-exploit/comment-page-1/#comment-7568</link>
		<dc:creator>dcl</dc:creator>
		<pubDate>Thu, 24 Sep 2009 17:55:05 +0000</pubDate>
		<guid isPermaLink="false">http://redstack.net/blog/?p=70#comment-7568</guid>
		<description>Yeah... heaven forbid someone use the documented way to return across ring boundaries. Brad, you do good research. I&#039;ll give you that. But you sure do fucking whine and cry a lot about shit. Does your ego really not get fed enough? Jesus man..</description>
		<content:encoded><![CDATA[<p>Yeah&#8230; heaven forbid someone use the documented way to return across ring boundaries. Brad, you do good research. I&#8217;ll give you that. But you sure do fucking whine and cry a lot about shit. Does your ego really not get fed enough? Jesus man..</p>
]]></content:encoded>
	</item>
</channel>
</rss>
