Uploaded videos
1-10 of 10-
Linux 2.6.18+ move_pages() Infoleak Exploit
spendergrsec
2,759 views
Quick video of an exploit I wrote for the move_pages() infoleak just submitted to oss-sec (though I had noticed the commit earlier today with SuSE security on CC ;)). The ...
-
Linux 2.X pipe() NULL ptr deref/race local root exploit (RHEL 5.4 x64)
spendergrsec
4,608 views
Watch in HD Fullscreen :)
Back again with yet another linux exploit. For time purposes I'm only demonstrating it on RHEL 5.4, but if you look on my twitter you can see ...
-
Linux 2.6.31 perf_counter x86/x64 Local Root Exploit with SELinux user_u defeat and disabling
spendergrsec
6,182 views
In this video I demonstrate a different method of exploiting the recent perf_counter vulnerability where it doesn't require a NULL mapping. The technique is from nemo, cre...
-
Linux 2.6.31 perf_counter x64 Local Root Exploit
spendergrsec
6,631 views
Same exploit as before, just ported to 64bit (the same .c works on x86/x64) all tidy within the enlightenment framework. Note: newer x64 exploits need to use 0x33 for USER...
-
Linux 2.6.31 perf_counter 0day Local Root Exploit
spendergrsec
7,559 views
Video dedicated to nemo, because I know he loves these!
Described in the changelog as causing a "kernel crash" -- this proves the claim to be a joke. I hacked it up into ...
-
Linux 2.6.0-2.6.19 udp_sendmsg() x86/x64 Local Root Exploit
spendergrsec
2,636 views
Exploits the recent udp_sendmsg() bug found by Julien Tinnes/Tavis Ormandy. Does not require an executable NULL mapping and is 100% stealthy. The vulnerability is interes...
-
Mr Magorium's Wunderbar Emporium
spendergrsec
13,092 views
*watch in HD fullscreen*
Exploits the vulnerability in all Linux kernels since 2001. Exploit works on all kernels since 2001. Disables SELinux, AppArmor, LSM -- you kn...
-
RHEL5 2.6.18-157 Local Kernel Exploit 0day, disables SELinux
spendergrsec
7,512 views
Same exploit as the previous two videos, this time on a new target: RHEL5 2.6.18-157
Same destruction commences ;)
Ah I forgot to show in the video after I got root tha...
-
Linux 2.6.30+ 64-bit Local Kernel Exploit 0day, disables SELinux/AppArmor/LSM ;)
spendergrsec
6,179 views
Here's an updated video of the exploit, this time against an ubuntu 64bit machine
Though the machine I tested on wasn't using SELinux (which as noted in the video actually...
-
Linux 2.6.30+ Local Kernel Exploit 0day, disabling SELinux/AppArmor/LSM ;)
spendergrsec
41,464 views
Hello to my new vendor-sec visitors! Haven't we learned yet that the kernel can do whatever it wants? Guess not ;)
Once I own the kernel (which SELinux does nothing to...
Advertisement










Play all(10)