Login Register






The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Thread Rating:
  • 0 Vote(s) - 0 Average


Privilege Escalation - Stuck as balls filter_list
Author
Message
RE: Privilege Escalation - Stuck as balls #11
(03-22-2015, 06:40 PM)whatever Wrote:
Code:
/etc/cron.daily:
total 108
-rwxr-xr-x   1 root root  2032 Jun  4  2014 chkrootkit

You could be very lucky here. Check what version of chkrootkit this is... if it's < 0.50 then popping root is pretty trivial: http://www.exploit-db.com/exploits/33899/

I'm a little discouraged that the timestamp is 6/4/14, as that is also the day that 0.50 was released. Nevertheless, it's worth checking out.

(03-22-2015, 02:20 PM)Lynux Wrote: This may work for you http://www.exploit-db.com/exploits/18411/

(03-22-2015, 04:41 PM)Lynux Wrote: Ahh no problem I just skimed over it and saw the kernel version, shame that it doesn't work, have you thought about shellcode?

Lol mayne I'm sorry but this is all just so not right.

Reply

RE: Privilege Escalation - Stuck as balls #12
(03-25-2015, 12:42 PM)Dyme Wrote: You could be very lucky here. Check what version of chkrootkit this is... if it's < 0.50 then popping root is pretty trivial: http://www.exploit-db.com/exploits/33899/

I had to use that one yesterday morning. Works great assuming chkrootkit is the vuln version.
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: Privilege Escalation - Stuck as balls #13
(03-25-2015, 01:21 PM)Reiko Wrote: I had to use that one yesterday morning. Works great assuming chkrootkit is the vuln version.

I have yet to run into it, but the situation is perfectly plausible and the vuln is so easily exploited. I love privilege escalation vulns like this as you probably already know lmao.

Reply

RE: Privilege Escalation - Stuck as balls #14
(03-25-2015, 01:42 PM)Dyme Wrote: I have yet to run into it, but the situation is perfectly plausible and the vuln is so easily exploited. I love privilege escalation vulns like this as you probably already know lmao.

Dude, the trend now is to patch the vulns on the news and nothing else. SSL bugs, kernel bugs, GHOST are ALWAYS patched/mitigated. Anything else? Wide open.
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: Privilege Escalation - Stuck as balls #15
(03-25-2015, 12:42 PM)Dyme Wrote: You could be very lucky here. Check what version of chkrootkit this is... if it's < 0.50 then popping root is pretty trivial: http://www.exploit-db.com/exploits/33899/

I'm a little discouraged that the timestamp is 6/4/14, as that is also the day that 0.50 was released. Nevertheless, it's worth checking out.



Lol mayne I'm sorry but this is all just so not right.

I fucking love you man, the version is 0.49. Thanks for the help.

Reply

RE: Privilege Escalation - Stuck as balls #16
(03-25-2015, 07:18 PM)whatever Wrote: I fucking love you man, the version is 0.49. Thanks for the help.

ayyyy must be the moneyyy


Reply

RE: Privilege Escalation - Stuck as balls #17
haha.. pretty funny an anti rootkit sw has a root hole in it

Reply







Users browsing this thread: 2 Guest(s)