3 ms·
Yeah, sure. Here's a example from https://twitter.com/duo_labs/status/935607023026229249 https://twitter.com/duo_labs/status/935607023026229249 on how to escala
by Qerub 9y ago
Yeah, sure. Here's a example from https://twitter.com/duo_labs/status/935607023026229249 https://twitter.com/duo_labs/status/935607023026229249 on how to escalate to root:
/usr/bin/osascript -e 'do shell script "<command to be run as root>" user name "root" password "" with administrator privileges'
- 13of40 9y agoFrom the comments on that, it seems like you need to do the exploit in the UI first. According the the analysis of the bug, "Upon receiving a mach XPC message, opendirectoryd invokes..." but what happens on the client end of the XPC message isn't mentioned. I'm just wondering if a low privileged user can initiate that programmatically, and whether they could do it from code that doesn't need to be signed, like a shell script.