DrGFreeman · @jdlbt
101 followers · 286 posts · Server techhub.social

Error: org.freedesktop.NetworkManager.wifi.scan request failed: not authorized.

This one is quickly eating away my resolve to setup my own Raspberry Pi based astrophotography control computer from scratch...

#linux #polkit #networkmanager #ubuntu

Last updated 1 year ago

genstar.service · @Genstar
51 followers · 24785 posts · Server meow.social
· @jokeyrhyme
92 followers · 1310 posts · Server aus.social

I've raised a issue for to ask about granular `pkexec` allow-lists: gitlab.freedesktop.org/polkit/

polkit allows me to match based on the first argument, but not any further arguments, which means I can't allow-list certain safe `pkexec` invocations without also allow-listing dangerous ones (my example is `pkexec btrfs foo` where "foo" alone is not enough to isolate safe invocations)

Am I thinking about this the wrong way? I did try to achieve this with a configuration but it's matching system is filled with foot-guns

#linux #polkit #sudo

Last updated 1 year ago

e33io · @e33io
123 followers · 70 posts · Server gnulinux.social

is there a simple way to just have a terminal-based polkit authentication agent instead of using a GUI like `polkit-gnome-authentication-agent-1` ?

#linux #polkit

Last updated 2 years ago

Christian Brauner 🦊🐺 · @brauner
509 followers · 430 posts · Server mastodon.social
kosmosghost · @kosmosghost
27 followers · 106 posts · Server fosstodon.org

I am trying to daily drive my as much as possible with , which is running , as much as possible. I am an advid note taker, and I am missing a sync note app that has encryption by default. That will be my next project as soon as I can figure out .

#oneplus6t #postmarketos #phosh #polkit

Last updated 2 years ago

kosmosghost · @kosmosghost
26 followers · 105 posts · Server fosstodon.org

I am writing a simple wireguard ui for my mobile linux device using gtk4. Part of the app randomly picks a wireguard config from /etc/wireguard. That directory is protected from access and requires root privileges. I am trying to figure out how to use polkit in rust. I could use some help.

#gtk4 #polkit #rust

Last updated 2 years ago

@c0nsid3rate I've taken and failed OSCP 4 times (number 5 coming in January!). I think I used to privesc in number 2.

#polkit

Last updated 2 years ago

c0nsid3rate 🌱 · @c0nsid3rate
256 followers · 503 posts · Server infosec.exchange

Rooted another OSCP machine this morning. There is no other exploit that has been more widespread and easy to leverage than pwnkit (CVE-2021-4034). I've simply lost count of the the number of machines I've been able to use this on to get root access from a low-privilege account. For people who do this kind of stuff, this post is a cold take, but I just wanted to come here and state the obvious. -2021-4034

From the Ubuntu website: "A local privilege escalation vulnerability was found on polkit’s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn’t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it’ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine."

#oscp #pwnkit #polkit #cve #linux #pkexec #setuid

Last updated 2 years ago

One thing that I think we've lost over the last 20 years is "audio cues" -- the desktop used to give a lot more audio feedback as to the events & status of events.

Empty the recycle bin? It had s simple audio cue play

Copy a folder? You have a audio cue to communicate success.

New email? Cue AOL charming & cringy "You've got mail.wav"

OS Startup? You feel like you are getting excited to get something done withe Windows XP - 7 and early 2000s Ubuntu startup sounds.

I think this principle could be taken so much farther -- perform a Why not have a audio cue for both Success.ogg and Failure.ogg -- or what about password verification, you are multi tasking on the phone or doing something in your office -- having a cue to redirect your attention to that you need to enter a password would be helpful.

Same thing goes for and in

There are times you are compiling a program and it needs extra privileges to install but you don't notice it -- it would make a huge difference if we had a hook system and could Enable/Disable audio cues & notifications -- that would be a huge improvement.

I could really see this also bringing a lot of value in space, with and others.

Its really hard to know what your missing when its been so long since you had it.

Plug in a USB Flash Drive? Audio Cue

Connect / Disconnect your phone to your computer? Audio Cue

Remote SSH Connection logs into your machine? Notification & Audio Cue.

With the right sound packs there is so much room for improvement -- v3 does a good job with this too giving subtle cues as you navigate the UX, startup, shutdown, etc...

#linux #foss #kde #gnome #opensource #rsync #polkit #pacman #yay #paru #archlinux #linuxphone #ubuntutouch #postmarketos #sxmo #SteamDeck #steamos

Last updated 2 years ago

DeaDSouL :fedora: :fediverse: · @DeaDSouL
37 followers · 252 posts · Server fosstodon.org
Fabian :blobcatlul: · @fabiscafe
133 followers · 5815 posts · Server mstdn.social

Does anyone have a nice and simple example of a script that involves / to ultimately write a file to a root-owned directory?

#polkit #policykit #Python

Last updated 3 years ago

ar.al🌻 · @aral
25027 followers · 19527 posts · Server mastodon.ar.al

Linux folks – remember to update your systems (elementary OS: run Operating System Updates from AppCenter or sudo apt update from Terminal) to fix Polkit vulnerability.

#polkit #security #linux

Last updated 3 years ago

(RTP):tor:Privacy & Tech Tips · @RTP
2618 followers · 3880 posts · Server fosstodon.org

See above toot for the demo video using the local root for /#pkexec as an example in a intro talk on /#privileges.

Learn more on the vulnerability behind it here:


bleepingcomputer.com/news/secu

#exploit #polkit #linux #permissions #security #infosec #cybersecurity #foss #news

Last updated 3 years ago

· @ganselmartin
89 followers · 1793 posts · Server ruhr.social
(RTP):tor:Privacy & Tech Tips · @RTP
2618 followers · 3880 posts · Server fosstodon.org
ComputerBase · @ComputerBase
1525 followers · 17633 posts · Server mastodon.social
ComputerBase · @ComputerBase
2051 followers · 18379 posts · Server mastodon.social
· @notanamber
41 followers · 195 posts · Server mastodon.uno

Hanno trovato nel novembre 2021 una vulnerabilità su un componente usato anche da . Attraverso questa vulnerabilità un utente malintenzionato potrebbe eseguire con i privilegi di root del codice arbitrario. Sembra che ci sia una patch ad oggi

securityweek.com/polkit-vulner

#polkit #linux

Last updated 3 years ago