<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SecDocs Feed for author Julien Tinnes</title>
    <link>http://secdocs.lonerunners.net</link>
    <atom:link type="application/rss+xml" href="http://secdocs.lonerunners.net/rss/author/872-julien-tinnes" rel="self"/>
    <description>Latest security documents RSS feed for author Julien Tinnes</description>
    <language>en-us</language>
    <item>
      <title>[Slides] There's a party at Ring0 (and you're invited)</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/872-julien-tinnes"&gt;Julien Tinnes&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/65-tavis-ormandy"&gt;Tavis Ormandy&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/52-kernel"&gt;kernel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/71-black-hat-usa-2010"&gt;Black Hat USA 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: Getting to ring0 is the final step towards complete system compromise and can also be the most fun. In the course of one year, we have found around twenty kernel vulnerabilities, mostly in Windows and Linux, some of them being uncovered after ten or fifteen years of existence. We share some of this work and demonstrate some exploits, bugs and techniques.</description>
      <pubDate>Sat, 24 Sep 2011 16:18:42 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4061-theres-a-party-at-ring0-and-youre-invited</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4061-theres-a-party-at-ring0-and-youre-invited</guid>
    </item>
    <item>
      <title>[Slides] Security In-Depth for Linux Software</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/872-julien-tinnes"&gt;Julien Tinnes&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/873-chris-evans"&gt;Chris Evans&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/5-security"&gt;security&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/210-secure-development"&gt;secure development&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/44-hack-in-the-box-2009-malaysia"&gt;Hack In The Box 2009 Malaysia&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 14 Sep 2010 10:40:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2880-security-in-depth-for-linux-software</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2880-security-in-depth-for-linux-software</guid>
    </item>
    <item>
      <title>[Paper] Security in depth for Linux software</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/872-julien-tinnes"&gt;Julien Tinnes&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/873-chris-evans"&gt;Chris Evans&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/5-security"&gt;security&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/41-black-hat-eu-2010"&gt;Black Hat EU 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: In many designs, the slightest error in the source code may become an exploitable vulnerability granting an attacker barely or not at all restricted access to a system. In this talk, using vsftpd and Google Chrome Linux as examples, we will firstly show how to design your code to be more robust to well-known classes of vulnerabilities and secondly, how to generically mitigate the consequences of such a vulnerability by dropping privileges and reducing attack surfaces.  There are a surprising number of options in Linux to manage privileges, but using them tends to be nuanced. This talk will discuss the technical aspects of various options and explain how to mix them to raise the bar to a system compromise from a sophisticated attacker.  While Mandatory Access Control systems are readily available, three of them being merged in the current Linux kernel tree, the ability to drop privileges in a "discretionary" way has to often rely on ancient mechanisms (which may not have been designed for security). We will show the state of the art on Linux and how well-known mechanisms, such as switching to an unprivileged uid, using chroot() and capabilities may or may not be suitable to achieve decent privilege dropping. We will discuss their drawbacks, availabilities to non-root processes and how an incorrect usage could be exploited by an attacker to circumvent security measures.  We will then explain and demonstrate designs, some of them using novel ideas or obscure features that can allow developers to put error-prone parts of their code inside a sandbox, using vsftpd and the Google Chrome Linux sandbox as examples.  We will discuss their limitations and how further kernel support could improve them.</description>
      <pubDate>Tue, 22 Jun 2010 06:03:56 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2574-security-in-depth-for-linux-software</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2574-security-in-depth-for-linux-software</guid>
    </item>
  </channel>
</rss>

