Full Disclosure mailing list archives

By Date By Thread User man Local Root Exploit/Linux Kernel setgid Directory Privilege Escalation/PAM Owner Check Weakness From: halfdog <me () halfdog net>

Date: Mon, 14 Dec 2015 21:22:04 +0000

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hello List, This ([1]) is a short article how to use the setgid directory /var/cache/man to escalate privileges from man/man to man/root on Ubuntu Vivid and to root/root via the "catman" cron job [2]. In my opinion this is not a really big issue, but I had quite fun analyzing it and writing a tool to use SUID-binaries to create arbitrary SGID-binaries. So perhaps someone else might have fun reading the article and reproducing the results. hd [1] http://www.halfdog.net/Security/2015/SetgidDirectoryPrivilegeEscalation/ [2] http://www.halfdog.net/Security/2015/MandbSymlinkLocalRootPrivilegeEscalation/ - -- http://www.halfdog.net/ PGP: 156A AE98 B91F 0114 FE88 2BD8 C459 9386 feed a bee -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iEYEARECAAYFAlZvMu8ACgkQxFmThv7tq+663QCgh8NTR0FlY+she/dP029Sc8lg /WgAniPJE6/tlMhCMOmg7CVLrQkGRB5z =UbUn -----END PGP SIGNATURE----- _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/ By Date By Thread Current thread: User man Local Root Exploit/Linux Kernel setgid Directory Privilege Escalation/PAM Owner Check Weakness halfdog (Dec 16)