4 ms·
POC (tweet + direct link) https://twitter.com/bl4sty/status/1486092552755466242 https://twitter.com/bl4sty/status/1486092552755466242 https://haxx.in/files/bl
by staticassertion 5y ago
POC (tweet + direct link)
https://twitter.com/bl4sty/status/1486092552755466242 https://twitter.com/bl4sty/status/1486092552755466242
https://haxx.in/files/blasty-vs-pkexec.c https://haxx.in/files/blasty-vs-pkexec.c
- aftbit 5y agoI get: [~] compile helper.. [~] maybe get shell now? The value for environment variable XAUTHORITY contains suscipious content This incident has been reported. And no root shell
- Pieman103021 5y agoAdding `GIO_USE_VFS=` to the end of `a_envp` (starting on line 56), fixes that for me on Fedora 34 with polkit-0.117-3. If anybody knows why that makes a difference, I would love to hear.
- deleted 5y ago[deleted]
- vrzh 5y agoRan into this while writing my exploit. I explain it here https://github.com/v-rzh/CVE-2021-4034/blob/master/README.md#whats-the-deal-with-gio_use_vfs https://github.com/v-rzh/CVE-2021-4034/blob/master/README.md... :)
- hakube 5y agoI've just updated my Arch system and tried this. No longer works
- makeworld 5y agoSame. Seems like the exploit wouldn't work for me. When I modify the XAUTHORITY line in the code, either to remove it or point it to my current XAUTHORITY value, I rightfully get a GUI password prompt before the root shell will open. On Arch Linux.
- deleted 5y ago[deleted]
- nvarsj 5y agohttps://github.com/berdav/CVE-2021-4034 https://github.com/berdav/CVE-2021-4034 works more reliably and is simpler.