4 ms·
Additionally, if can find a way to trick a user into installing a malicious kext, why even bother with PACMAN? You already have arbitrary kernel code execution!
by jprx 4y ago
Additionally, if can find a way to trick a user into installing a malicious kext, why even bother with PACMAN? You already have arbitrary kernel code execution!
- throwaway290 4y agoPerhaps the kext with the overflow may not necessarily look malicious? It can serve as an actually useful kext and pass review.
- shp0ngle 4y agoyeah but if you can trick the user to do that, you can already trick him to do more
- aenis 4y agoThese days all kexts look malicious.
- ntauthority 4y agoYeah. The bundled ones in the main OS image are the worst. Who the hell knows what nefarious acts lie behind IOPCIFamily.kext?! /s, though not entirely, moving more stuff to unprivileged contexts would be nice
- sgjohnson 4y agoFirst you need to trick Apple into signing that kext (which is getting more difficult by the day even for legitimate uses), or get the user to disable SIP first.
- throwaway290 4y agoDidn't many tools require disabling SIP, like Homebrew? Is this no longer true?
- sgjohnson 4y agoThis hasn't been true for at least 2 major macOS releases. But yes, there was a time when editing even /etc/sudoers required disabling SIP. That time is long gone.