[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ale] Linux Distributions
On Tue, 17 May 2005, Jim Popovitch wrote:
> If you run your browser as user bob, how do you really know that
> java/javascript/flash/realplayer/etc. didn't just do a malicious thing
> that did in fact gain root privileges via any local root exploit (like
> the ones just announced in kernel 2.6.11)?
You don't. What you know is that it's much harder for potential attacker
to (a) exploit app then (b) carry out other root exploit than it is for
potential attacker to (a) exploit app but not have to (b) carry out other
root exploit because app was already run as root.
later,
chris