MENU

Fun & Interesting

Elliot Ward - Leveraging features for privilege escalation in Ubuntu 24.04 - Hackfest 2024

Hackfest Communication 90 lượt xem 3 months ago
Video Not Working? Fix It Now

In this session, we explore a unique approach to privilege escalation in Ubuntu 24.04 by leveraging system features rather than relying solely on traditional vulnerabilities. Our research began with an investigation into Ubuntu's privilege boundaries, focusing on DBus and its interaction with the cups printing system. Through a series of methodical steps, we uncovered a way to escalate privileges from a standard user to root by chaining together minor bugs and existing features.

Our journey highlights the importance of understanding system components and their interactions. By exploiting the configurations within the cups service and bypassing AppArmor restrictions, we achieved arbitrary command execution, ultimately gaining root access through the wpa_supplicant service.

This talk emphasizes the significance of a holistic approach to security research, demonstrating how combining knowledge of system features can lead to successful exploitation. Attendees will gain insights into advanced privilege escalation techniques and the critical role of comprehensive system analysis in identifying security risks.

https://hackfest.ca

Comment