Linux local privilege escalation using authentication bypass vulnerability in polkit CVE-2021-3560

แชร์
ฝัง
  • เผยแพร่เมื่อ 5 ม.ค. 2025

ความคิดเห็น •

  • @AnkitGaur9
    @AnkitGaur9 3 ปีที่แล้ว +15

    good find, well demonstrated !!

  • @removeheaven1550
    @removeheaven1550 3 ปีที่แล้ว +11

    l am invincible! Boris™

  • @Basieeee
    @Basieeee 3 ปีที่แล้ว +7

    Very well explained thanks man

  • @ko-Daegu
    @ko-Daegu 2 ปีที่แล้ว +1

    in a clean debain installation why do I get:
    The name org.freedesktop.Accounts was not provided by any .service files

  • @conceptrat
    @conceptrat 3 ปีที่แล้ว +3

    Nice work 007 errrr Kevin 😛

  • @rovrest1838
    @rovrest1838 3 ปีที่แล้ว

    It comes at the right time

  • @uksuperrascal
    @uksuperrascal 3 ปีที่แล้ว

    Hi just got my first polkit when trying to use balena etcher writing an OS to and SD - I am using Ubuntu Studio 18.04.6 LTS - any help would be great.

  • @thomasstaats3146
    @thomasstaats3146 2 ปีที่แล้ว

    does anyone know if this patched? Im using a vps with ubuntu 20.04 kernel 5.4 and wrote a script to run it over and over with varying wait times before killing

  • @maxberlyan6782
    @maxberlyan6782 3 ปีที่แล้ว +1

    very nice!!!

  • @hex2344
    @hex2344 2 ปีที่แล้ว

    Hi. What is that string "GoldenEye" there?

  • @s1lv3rh4wk
    @s1lv3rh4wk 3 ปีที่แล้ว +1

    Nice work.

  • @ayylmao1558
    @ayylmao1558 3 ปีที่แล้ว +2

    Thank you Mr Github, ery noice

  • @randomguy3784
    @randomguy3784 2 ปีที่แล้ว

    This also works with Centos 8 with polkit version 0.115

  • @JohnHollowell
    @JohnHollowell 3 ปีที่แล้ว +12

    So GitHub can post videos of fully functioning exploitable code, but anyone else can't put similar code on GitHub's platform? I think you need to follow your own rules

    • @CristianTraina
      @CristianTraina 3 ปีที่แล้ว +3

      I think that's because you can ask a victim to download the code from github and run it. While having the code in a video is way safer

  • @ZainAli-uq3fj
    @ZainAli-uq3fj 3 ปีที่แล้ว

    is it patcher as of Nov 2021

  • @Canadian789119
    @Canadian789119 3 ปีที่แล้ว +2

    Hey question. I can't get it to work.
    If I don't have sudo. Or any gui password auth. can I expect it to work? I also don't have any .service files so the github exploit doesn't work either.
    BAH! I'M INVINCIBLE!
    The amount of times people downvote me on something like reddit for calling sudo bloat ware.. :)

  • @priyanshukumarpu
    @priyanshukumarpu 3 ปีที่แล้ว +2

    Neat

  • @bossscast
    @bossscast 3 ปีที่แล้ว +5

    great demonstration. How do I fix it?

  • @DanSalazarish
    @DanSalazarish 3 ปีที่แล้ว +1

    Magic

  • @Tudumanu
    @Tudumanu 3 ปีที่แล้ว +1

    wow

  • @huebs
    @huebs 3 ปีที่แล้ว +4

    Oops

  • @chiragartani
    @chiragartani 3 ปีที่แล้ว

    Hi, Thank you very much!
    It is possible to auth bypass in any linux machine, because I know a web server which is not allowing me to run any remote code example: git clone, sudo apt install xyz ?
    Now when I trying to change password it throwing me at denied line, I can't even change user or create user in that machine.
    Let me try your POC in that machine. Will update here.
    Update: Not working tried 17 times, Machine version is vulnerable for exploit, When ever I try to run it says enter password.

    • @ColinRubbert
      @ColinRubbert 3 ปีที่แล้ว +3

      In the supporting documentation it indicates that it require gnome-control-center and accountservice which implies if it's a GUI w/gnome it's very likely exploitable, anything w/o a GUI or non-gnome environment is very unlikely to be exploitable. Most web servers and servers in general online don't have GUI's natively installed. That being said if you could potentially install these two dependencies w/o root privs you could maybe exploit it.

    • @chiragartani
      @chiragartani 3 ปีที่แล้ว

      @@ColinRubbert Thank you 🙏 , I got it.

  • @igorgiuseppe1862
    @igorgiuseppe1862 3 ปีที่แล้ว +1

    qute ironic video to post coming from github who was recently purchased by microsoft

  • @sothoncyber8377
    @sothoncyber8377 3 ปีที่แล้ว

    seriously

  • @_NguyenVanDien
    @_NguyenVanDien ปีที่แล้ว

    WTF

  • @nacnud_
    @nacnud_ 3 ปีที่แล้ว +1

    Yikes