Loading...
Please wait, while we are loading the content...
Similar Documents
Fixing races for fun and profit: how to abuse atime (2005)
| Content Provider | CiteSeerX |
|---|---|
| Author | Borisov, Nikita Johnson, Rob Sastry, Naveen Wagner, David |
| Abstract | Dean and Hu proposed a probabilistic countermeasure to the classic access(2)/open(2) TOCTTOU race condition in privileged Unix programs [4]. In this paper, we describe an attack that succeeds with very high probability against their countermeasure. We then consider a stronger randomized variant of their defense and show that it, too, is broken. We conclude that access(2) must never be used in privileged Unix programs. The tools we develop can be used to attack other filesystem races, underscoring the importance of avoiding such races in secure software. 1 |
| File Format | |
| Publisher Date | 2005-01-01 |
| Publisher Institution | In 14th USENIX Security Symp |
| Access Restriction | Open |
| Subject Keyword | Tocttou Race Condition Randomized Variant Privileged Unix Program Classic Access High Probability Probabilistic Countermeasure Secure Software Filesystem Race |
| Content Type | Text |