No video

Linux SUID Vulnerability Demonstration

  Рет қаралды 6,998

Brian Green

Brian Green

Күн бұрын

Пікірлер: 14
@rafa_br34
@rafa_br34 2 ай бұрын
Helped me a bit to understand how the SUID bit works, but what would even be the reason to add the SUID bit to some executable?
@janb.9425
@janb.9425 2 ай бұрын
Breaking news: Allowing users to execute a shell as root allows them to get a root shell
@zuberkariye2299
@zuberkariye2299 10 ай бұрын
Amazing Demo!
@tbone907
@tbone907 3 жыл бұрын
Great video! Thanks for sharing.
@ahmedamr1124
@ahmedamr1124 3 ай бұрын
Nice observation
@AmazingJayB51
@AmazingJayB51 3 жыл бұрын
can you block someone from using zsh?
@adebolama2686
@adebolama2686 2 жыл бұрын
At 8:54 when you typed zsh you were login as root that's why you have the # in your prompt and I guess that was why it didn't ask for permission you are running in root context not as an ordinary user
@hetsonii
@hetsonii 2 жыл бұрын
He got the root zsh because SUID bit was set for zsh. If it wasn't the case, he would have got the non-root zsh. that's the whole point of SUID Vulnerabilities!
@creed404
@creed404 Жыл бұрын
That’s the point he was trying to explain!
@Michael_Jackson187
@Michael_Jackson187 7 ай бұрын
​@@hetsoniiWhat admin in there right fucking mind would set the SUID on a fucking shell, there are some things that need to be run as root and you can use something like gtfobin to escape then and get a sh. i remember using man to privesc during the eJPTv2 exam, this would be a more practical way of privesc like finding out what is already allowed on the system to run as root for the user by typing sudo -l and heading over to gtfobins for example "man" sudo man man !/bin/sh
@Autonomous4kpsf
@Autonomous4kpsf 7 ай бұрын
What if u are not in sudoers group
@firsfnamelastname8490
@firsfnamelastname8490 Жыл бұрын
It’s not a vulnerability but a functionality
@creed404
@creed404 Жыл бұрын
A functionality that leads to vulnerabilities like any functionality
@rafa_br34
@rafa_br34 2 ай бұрын
@@creed404 Just like TCP...
Encryption Demonstration using OpenSSL on CentOS 7
20:33
Brian Green
Рет қаралды 1,5 М.
The STICKY BITs of Linux
13:56
Shawn Powers
Рет қаралды 15 М.
Пройди игру и получи 5 чупа-чупсов (2024)
00:49
Екатерина Ковалева
Рет қаралды 4 МЛН
UNO!
00:18
БРУНО
Рет қаралды 5 МЛН
Dad Makes Daughter Clean Up Spilled Chips #shorts
00:16
Fabiosa Stories
Рет қаралды 1,7 МЛН
What Everyone Missed About The Linux Hack
20:24
Theo - t3․gg
Рет қаралды 285 М.
Hacking Linux // Linux Privilege escalation // Featuring HackerSploit
1:07:08
TryHackMe! Abusing SETUID Binaries - Vulnversity
29:35
John Hammond
Рет қаралды 143 М.
It's time for change, it's time for Linux.
10:53
DankPods
Рет қаралды 141 М.
new linux exploit is absolutely insane
8:29
Low Level Learning
Рет қаралды 427 М.
etc passwd Exploit for root Shell - What You Need to Know for OSCP
10:28
Brief Discussion of SUID & SGID
9:57
Jason Wertz
Рет қаралды 82 М.
Can ChatGPT Write an Exploit?
10:14
Low Level Learning
Рет қаралды 94 М.