PoC to demonstrate root permission hijacking by exploiting “systemd-run”
twitter.com
twitter.com
The other demonstration shows the latter part, but requires you to have a reverse shell in the parent and can't be abused across users.
https://twitter.com/hackerfantastic/status/17860809689581612...
Generally, this issue is overblown. Both of these "exploits" works on `su`, `sudo` and probably `doas` because of session caching or because you have access to `ptrace`.
I'm not sure what security boundary you are breaking and this seems more like a cheap dig at `systemd` to feed into the decade-old hate train at this point.
I reproduced this targeting sudo (just `cat` the parent tty), in fact able to capture my password as I type it in, and capture commands as they are being typed in. Surprised it was not mentioned that it breaks the terminal while you run it, no characters get sent to the program.
Edit: Here is a POC https://gist.github.com/bahorn/198987f55611f2011a91a5af09e7c... so you can see that this applies to sudo as well.
The problem is you can not hijack (meaning command exec right?) a root shell running under your account with this unless there is an approach that hasn't been mentioned yet. You can read character input, stopping the program from receiving input while you are doing so, of a process your user account directly started. I investigated the other ways and he hasn't given a viable one beyond running stuff directly in shell of the target session (TIOCSTI doesn't work if you target a different pty) or using ptrace.
All of these apply to other programs as even though they set root permissions on their pty as you can influence their parent. You need to chown both if you want to stop issues, but that'll probably break stuff. To be clear his whole point is that systemd is less secure compared to sudo etc but is using something that applies to everything to try and show that, involving using pocs that didn't even show the issues he was claiming, which is disingenuous.
That some other process of the same user can influence that session with elevated privileges isn't really an issue. In fact, the terminal in which systemd-run was invoked is also owned by the user and can be "taken over" in the same way.
If this is real then great, it can be patched no need for attacks. If it's fake then shame on <whoever>, no need for attacks.
Personal theory, it's just really easy to feel better about yourself by being the true zealot who knows better, who sees ruin elsewhere. It's much harder to find empathy & appreciation, to see both good and bad mixing.
gives a 3rd example to explain the problem and suggests a fix. The pty should be chown() to root after a root program is attached.
The reality is that this is just self-promotion from a grifter, and that's why it's happening on Twitter. If it was a real issue from a competent researcher it would have been reported via the appropriate channels, not on social media to feed haters and trigger the usual abuse and death threats while chasing impressions.
And again, there is no "vulnerability", there is simply a person that doesn't know how Linux works and has learned something new. Which again it's fine, nobody knows everything and we all learn new things everyday, it's just that normal and sensible people don't use that to make grand claims on social media and start harassment campaigns culminating in death threats.
Professional security researchers responsibly report real issues using the appropriate channels, such as defined at: https://github.com/systemd/systemd/security/policy this is not the work of a researcher, this is a grifter looking for self-promotion on social media.
He did call me a "facist weenie" with no clear reason why beyond me pushing back on their grand claims.