3 ms·
> Okay, so the systemsetup binary simply checks if we are running as the root user? >Philip tried patching that function (replacing sete with setne), with succ
by towelguy 11y ago
> Okay, so the systemsetup binary simply checks if we are running as the root user?
>Philip tried patching that function (replacing sete with setne), with success:
How do you patch the binary without root or the admin user password anyway?
- nmc 11y agoI think this is not part of the exploit, it was simply a step to ensure that their intuition about the assembly code was correct. Hint: the first sentence you quoted ends with a question mark.
- apendleton 11y agoPretty sure they did that as root, so they could get past that and explore how the program worked when being run as a non-root user. The final exploit doesn't depend on this program, though; it uses the same RPC interfaces this program does, from a separate program, so the patching was just part of their exploration, not part of the exploit.
- AgentME 11y agoJust make a copy of the binary that's editable by the user. Or copy its code into a new program. There's nothing special about the specific root-owned systemsetup binary. (It's not setuid.)