Archive for May, 2018

Shatter Attack: what are its Linux equivalent

Looking at "Shatter Attack" in Windows:

https://pen-testing.sans.org/resources/papers/gcih/enemy-within-handling-insider-threat-posed-shatter-attacks-105884

http://index-of.es/Misc/pdf/shatter_attack_redux.pdf

https://www.blackhat.com/presentations/bh-usa-04/bh-us-04-moore/bh-us-04-moore-whitepaper.pdf

http://www.hpl.hp.com/techreports/2005/HPL-2005-87.pdf

Now you ask yourself, what are the Linux equivalent? How are messages passed from one applications to another? And if the messages and posted in arbitrary ways, is it possible to achieve privilege escalation in Linux scenario?

This is the processes relevant to graphical redering in Linux:

Looking at "Dbus" daemon above, what its function?

Since it is running at the high privilege level, privilege esclation is not impossible.

And history have shown its possibilities:

https://www.cyberciti.biz/tips/linux-dbus-packages-fix-privilege-escalation.html

https://www.rapid7.com/db/modules/exploit/linux/local/lastore_daemon_dbus_priv_esc

https://packetstormsecurity.com/files/147285/lastore-daemon-D-Bus-Privilege-Escalation.html

https://bugzilla.redhat.com/show_bug.cgi?id=847402

https://exchange.xforce.ibmcloud.com/vulnerabilities/82135

https://www.exploit-db.com/exploits/33614/

Vickblöm

Research scattered with thoughts, ideas, and dreams

Penetration Testing Lab

Offensive Techniques & Methodologies

Astr0baby's not so random thoughts _____ rand() % 100;

@astr0baby on Twitter for fresh randomness

The Data Explorer

playing around with open data to learn some cool stuff about data analysis and the world

Conorsblog

Data | ML | NLP | Python | R

quyv

Just a thought

IFT6266 - H2017 Deep Learning

A Graduate Course Offered at Université de Montréal

Deep Learning IFT6266-H2017 UdeM

Philippe Paradis - My solutions to the image inpainting problem

IFT6266 – H2017 DEEP LEARNING

Pulkit's thoughts on the course project

Thomas Dinsmore's Blog

No man but a blockhead ever wrote except for money -- Samuel Johnson

the morning paper

a random walk through Computer Science research, by Adrian Colyer

The Spectator

Shakir's Machine Learning Blog