4 ms·
Interesting. If that’s possible (I haven’t tested it, but I’m sure it is) then you wouldn’t even need to log the password. You could just alias sudo to a bash s
by gamer191 6mo ago
Interesting. If that’s possible (I haven’t tested it, but I’m sure it is) then you wouldn’t even need to log the password. You could just alias sudo to a bash script that runs your malicious payload using the real sudo. Then the user would run the command, be prompted for their password by the real sudo, and be none the wiser that a malicious script has just been executed
For what it’s worth, Windows’ security model says it’s not an exploit that programs can grant themselves admin rights if the user is an admin (https://github.com/hfiref0x/UACME https://github.com/hfiref0x/UACME). But afaik Linux doesn’t have that model so it is a bit of an issue that this is possible
- hnlmorg 6mo ago> Interesting. If that’s possible It’s not possible. At least not unless those users have already borked their own system. The previous poster was clutching at straws.
- IshKebab 6mo agoOf course it's possible. I've tried it. It works. It's just standard Unix features. What makes you think it isn't possible?
- hnlmorg 6mo agoFor the reasons I’ve already stated: daemons don’t run with permissions to write into users directories. You’ve shifted goal posts to now talk about desktop applications when the topic was originally about daemons
- IshKebab 6mo ago> You’ve shifted goal posts to now talk about desktop applications when the topic was originally about daemons You imagined that. The topic was never originally about daemons.
- hnlmorg 6mo agoIt’s literally in the opening post you replied to: > A local privilege escalation to root via an exploitable service? > Doesn't Linux have one of these CVEs...each week? Why else would people be talking about docker, and user/group ownership of running services, and so on and so forth, in response to their comment and yours?
- IshKebab 6mo agoIf you actually read the article, the "exploitable service" is Windows Defender scanning a file that the user has downloaded.
- hnlmorg 6mo agoYes. - “Windows Defender” is the service - the discussion was about how Defender might have “root” access but Linux services have CVEs too. The reason Defender has elevated access is precisely because it needs to do stuff like hook into file system events and scan files irrespective of their underlying ACLs. So it’s not the same as desktop anpplication exploit that would be running as the same user/group as the person logged in. And it’s also not the same as any other type of service, be that a RDBMS, web server, IRC server, nor any other type of server you might think off. In fact this is true for both Windows AND Linux. Your average service will not have access to read user files and desktop applications are not services running as root. I get you’re trying to make a balanced argument. And I do agree that Linux has had a great many poorly thought out design decisions (and even more problems inherent from its POSIX lineage). But the specific arguments you’re making in this thread are just misinformed and misunderstand how these operating systems work.