3 ms·
That's because, to redirect that file to file descriptor 3 for reading, you need read permission on the file. In my system, for example, /bin/ping cannot be rea
by rg3 16y ago
That's because, to redirect that file to file descriptor 3 for reading, you need read permission on the file. In my system, for example, /bin/ping cannot be read as a normal user (permissions 4711) and I get that same error.
You'll have to find another binary that has the SUID bit set and is readable. For example, in my system /bin/mount does the job. Still, in the last step I get the same error as reported by several other users (Inconsistency detected...)
- pyre 16y agoThere is also a method at the end of the mail (in the Notes section) that details a method of using a SUID binary that you don't have read access to. TL;DR 1. cause STDERR to block 2. run the SUID binary in the background in a way that triggers ld to try to write to STDERR causing it to block. 3. Replace /tmp/exploit with your binary 4. eliminate the blocking condition on STDERR. 5. ld will continue on using the $ORIGIN value.