Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Linux 2.6.31 perf_counter x86/x64 Local Root Exploit with SELinux user_u defeat and disabling

Loading...

Sign in or sign up now!
6,072
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Sep 18, 2009

In this video I demonstrate a different method of exploiting the recent perf_counter vulnerability where it doesn't require a NULL mapping. The technique is from nemo, credits to him: it seems quite stable on both single and multi-processor machines (it's been 100% reliable so far). To further demonstrate how easy the vulnerability can be exploited in the face of access control mechanisms, I exploit the vulnerability in the restricted user_u role of SELinux on a fully patched FC11 (which prevents execution of any suid app, among many other things), bypassing execmem restrictions, and finally disable SELinux completely.

Category:

Comedy

Tags:

License:

Standard YouTube License

Link to this comment:

Share to:

Uploader Comments (spendergrsec)

  • what is the name of this wonderfull music ?

  • It was whatever was playing on the PsyChill channel of di . fm at the time. Or maybe Chillout Dreams? --Night time music. I don't pay attention to song names :p

see all

All Comments (7)

Sign In or Sign Up now to post a comment!
  • no taste for music...

  • Hmm i'm not sure if is your exploit because i use it :) this exploits.. maybe i'm wrong but not sure :) RULLz the Emporium exploit.

  • lool i want any local root 2011

    can you send me?

  • Spengler, you are exploit God. It is sort of disappointing that all the MAC systems on Linux/BSD are worthless. These exploits prove it. Good work.

  • answering to myself: i have an idea, just need to code it ... :-)

  • nice!

    I wrote an exploit (my first one) by myself, and it worked

    very well. I couldn't figure out, how to do it without the zero

    mapping, which is obsolete in my opinion. I'am not so familiar

    with race conditions. Could you give me some hints, how it is done?

Loading...
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more