AskUbuntu · @askubuntu
61 followers · 2227 posts · Server ubuntu.social

Gtk desktop app delayed on first launch (20.04) #2004

askubuntu.com/q/1459470/612

#permissions #gtk #policykit #pkexec

Last updated 2 years ago

c0nsid3rate 🌱 · @c0nsid3rate
256 followers · 503 posts · Server infosec.exchange

Rooted another OSCP machine this morning. There is no other exploit that has been more widespread and easy to leverage than pwnkit (CVE-2021-4034). I've simply lost count of the the number of machines I've been able to use this on to get root access from a low-privilege account. For people who do this kind of stuff, this post is a cold take, but I just wanted to come here and state the obvious. -2021-4034

From the Ubuntu website: "A local privilege escalation vulnerability was found on polkit’s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn’t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it’ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine."

#oscp #pwnkit #polkit #cve #linux #pkexec #setuid

Last updated 3 years ago

Shawn Webb · @lattera
1325 followers · 5171 posts · Server bsd.network

Should blame be placed solely on the C programming language for CVE-2021-4034?

#infosec #pkexec #PwnKit

Last updated 4 years ago

Dervishe the Grey · @dervishe
122 followers · 3084 posts · Server mastodon.sdf.org

#pkexec

Last updated 4 years ago

ITSEC News · @itsecbot
856 followers · 32557 posts · Server schleuss.online

“PwnKit” security bug gets you root on most Linux distros – what to do - An elevation of privilege bug that could let a "mostly harmless" user give themselves a i... nakedsecurity.sophos.com/2022/ -2021-4034

#eop #linux #pwnkit #pkexec #cve #vulnerability

Last updated 4 years ago

Senioradmin · @Haydar
568 followers · 6012 posts · Server social.tchncs.de
Shawn Webb · @lattera
1325 followers · 5171 posts · Server bsd.network

Taking inspiration from the camp, now rejects execve(argc==0) attempts: git.hardenedbsd.org/hardenedbs

This mitigates types of vulnerabilities like that of (CVE-2021-4034).

#openbsd #hardenedbsd #pkexec #infosec

Last updated 4 years ago

Diferencias entre y y porque se abandona gksudo

geekland.eu/diferencias-pkexec

#pkexec #gksudo

Last updated 7 years ago