3 ms·
Woah - can you expand on this a bit? I don't have a system to test atm, but I'm curious how that works. Are you sure privileges/security boundaries are circumve
by thricegr8 5y ago
Woah - can you expand on this a bit? I don't have a system to test atm, but I'm curious how that works. Are you sure privileges/security boundaries are circumvented?
- Retr0id 5y agoIf YAMA is disabled, you can use it to migrate laterally into processes owned by the same user. See [1]. It only really crosses a security boundary if, for some reason, dd is configured to run as root (e.g. via setuid bit, or sudo config). At that point, you could use it to patch the filesystem directly anyway, but keeping things in-memory is much stealthier (and less risk of bricking hardware, if your working with an embedded device or similar). For a description of using dd to gain file-less native code execution, see [2]. As a concise (golfed) example (x86-64 /bin/sh shellcode): cd /*/$$;read a<*l;exec 3>mem;base64 -d<<<McBIu9GdlpHQjJf/SPfbU1RfmVJXVF6wOw8F|dd bs=1 seek=$[`cut -d\ -f9<<<$a`]>&3 Source: [3] [1] https://www.kernel.org/doc/Documentation/security/Yama.txt https://www.kernel.org/doc/Documentation/security/Yama.txt [2] https://blog.sektor7.net/#!res/2018/pure-in-memory-linux.md https://blog.sektor7.net/#!res/2018/pure-in-memory-linux.md [3] https://twitter.com/David3141593/status/1386678449604108289 https://twitter.com/David3141593/status/1386678449604108289
- anthk 5y agoNo one would be that insane to set dd as setuid.