{"id":132,"date":"2019-10-20T17:30:41","date_gmt":"2019-10-20T15:30:41","guid":{"rendered":"http:\/\/linuxboxen2.dk\/?page_id=132"},"modified":"2024-07-24T15:58:25","modified_gmt":"2024-07-24T15:58:25","slug":"sikkerhed","status":"publish","type":"page","link":"https:\/\/www.linuxboxen.dk\/?page_id=132","title":{"rendered":"Sikkerhed."},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"http:\/\/linuxboxen.dk\/wp-content\/uploads\/2019\/10\/sad.png\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p>Der er fundet et problem med sudo. L\u00e6s mere <a href=\"https:\/\/thehackernews.com\/2019\/10\/linux-sudo-run-as-root-flaw.html?fbclid=IwAR3zmZ8kRhfzp7HRw9F7xAK9RmRKwEi9GhARObvMaukITOFPA0JgRhsqN5A\">her<\/a><\/p>\n<p>Hvordan udnytter jeg denne fejl? Bare Sudo bruger-id -1 eller 4294967295<br \/>S\u00e5rbarheden, der spores som CVE-2019-14287 og opdaget af Joe Vennix fra Apple Information Security, handler mere om, fordi sudo-v\u00e6rkt\u00f8jet er designet til at lade brugerne bruge deres egne login-adgangskoder til at udf\u00f8re kommandoer som en anden bruger uden at kr\u00e6ve deres adgangskode.<br \/><br \/>Hvad der er mere interessant er, at denne fejl kan udnyttes af en angriber til at k\u00f8re kommandoer som root blot ved at specificere bruger-ID &#8220;-1&#8221; eller &#8220;4294967295.&#8221;\u00a0Det skyldes, at funktionen, der konverterer bruger-id til dens brugernavn forkert, behandler -1 eller dens usignerede \u00e6kvivalent 4294967295, som 0, hvilket altid er bruger-id for rodbruger.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Det er muligt at udf\u00f8re sudo komandoer. Du\u00a0kan pr\u00f8ve dette eks.<\/p>\n<p>Det vil give UID 0 som er root.<\/p>\n<p><code>sudo -u#-1 id -u\u00a0 <\/code><\/p>\n<p><code>0<\/code><\/p>\n<p>Efter patch<\/p>\n<p>unable to initialize policy plugin<\/p>\n\n\n\n<hr class=\"wp-block-separator has-css-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Linux brugere pas p\u00e5! CVE-2019-12735.<\/h2>\n\n\n\n<pre id=\"tw-target-text\" dir=\"ltr\" data-placeholder=\"Translation\">Product: Vim &lt; 8.1.1365, Neovim &lt; 0.3.6\nType:    Arbitrary Code Execution\nCVE:     CVE-2019-12735\nDate:    2019-06-04\nAuthor:  Arminius (@rawsec)<\/pre>\n<p dir=\"ltr\">Patch vi\/vim S\u00e5 hurtigt som muligt.<\/p>\n<p dir=\"ltr\">Beskrivelse af hack.<\/p>\n<p dir=\"ltr\"><a href=\"https:\/\/github.com\/numirias\/security\/blob\/master\/doc\/2019-06-04_ace-vim-neovim.md\">https:\/\/github.com\/numirias\/security\/blob\/master\/doc\/2019-06-04_ace-vim-neovim.md<\/a><\/p>\n<p dir=\"ltr\">\u00a0<\/p>\n\n\n\n<hr class=\"wp-block-separator has-css-opacity is-style-wide\"\/>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" src=\"http:\/\/linuxboxen.dk\/wp-content\/uploads\/2019\/10\/sad.png\" alt=\"\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Alle versioner af container-softwaren Docker har fejl.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Update din docker installation hurtigst muligt.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kernen i hullet er FollowSymlinkInScope-funktionen, som er s\u00e5rbar overfor basale TOCTOU-angeb. Funktionen har til form\u00e5l at udregne en given filsti p\u00e5 en sikker m\u00e5de, ved at behandle processerne som om de befandt sig inde i en Docker-container.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Den udregnede filsti bliver ikke brugt med det samme, men rundsendes en smule og anvendes lidt senere. En angriber kan udnytte dette tidsgab og tilf\u00f8je en filsti, som er et symbolsk link (filhenvisning), der efter udregning kan ende med at pege p\u00e5 v\u00e6rtens filer med rod-privilegier.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<div class=\"pvc_clear\"><\/div><p id=\"pvc_stats_132\" class=\"pvc_stats all  \" data-element-id=\"132\" style=\"\"><i class=\"pvc-stats-icon medium\" aria-hidden=\"true\"><svg aria-hidden=\"true\" focusable=\"false\" data-prefix=\"far\" data-icon=\"chart-bar\" role=\"img\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewBox=\"0 0 512 512\" class=\"svg-inline--fa fa-chart-bar fa-w-16 fa-2x\"><path fill=\"currentColor\" d=\"M396.8 352h22.4c6.4 0 12.8-6.4 12.8-12.8V108.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v230.4c0 6.4 6.4 12.8 12.8 12.8zm-192 0h22.4c6.4 0 12.8-6.4 12.8-12.8V140.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v198.4c0 6.4 6.4 12.8 12.8 12.8zm96 0h22.4c6.4 0 12.8-6.4 12.8-12.8V204.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v134.4c0 6.4 6.4 12.8 12.8 12.8zM496 400H48V80c0-8.84-7.16-16-16-16H16C7.16 64 0 71.16 0 80v336c0 17.67 14.33 32 32 32h464c8.84 0 16-7.16 16-16v-16c0-8.84-7.16-16-16-16zm-387.2-48h22.4c6.4 0 12.8-6.4 12.8-12.8v-70.4c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v70.4c0 6.4 6.4 12.8 12.8 12.8z\" class=\"\"><\/path><\/svg><\/i> <img loading=\"lazy\" decoding=\"async\" width=\"16\" height=\"16\" alt=\"Loading\" src=\"https:\/\/www.linuxboxen.dk\/wp-content\/plugins\/page-views-count\/ajax-loader-2x.gif\" border=0 \/><\/p><div class=\"pvc_clear\"><\/div>","protected":false},"excerpt":{"rendered":"<p>Der er fundet et problem med sudo. L\u00e6s mere her Hvordan udnytter jeg denne fejl? Bare Sudo bruger-id -1 eller 4294967295S\u00e5rbarheden, der spores som CVE-2019-14287 og opdaget af Joe Vennix fra Apple Information Security, handler mere om, fordi sudo-v\u00e6rkt\u00f8jet er designet til at lade brugerne bruge deres egne login-adgangskoder til at udf\u00f8re kommandoer som en [&hellip;]<\/p>\n<div class=\"pvc_clear\"><\/div>\n<p id=\"pvc_stats_132\" class=\"pvc_stats all  \" data-element-id=\"132\" style=\"\"><i class=\"pvc-stats-icon medium\" aria-hidden=\"true\"><svg aria-hidden=\"true\" focusable=\"false\" data-prefix=\"far\" data-icon=\"chart-bar\" role=\"img\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewBox=\"0 0 512 512\" class=\"svg-inline--fa fa-chart-bar fa-w-16 fa-2x\"><path fill=\"currentColor\" d=\"M396.8 352h22.4c6.4 0 12.8-6.4 12.8-12.8V108.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v230.4c0 6.4 6.4 12.8 12.8 12.8zm-192 0h22.4c6.4 0 12.8-6.4 12.8-12.8V140.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v198.4c0 6.4 6.4 12.8 12.8 12.8zm96 0h22.4c6.4 0 12.8-6.4 12.8-12.8V204.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v134.4c0 6.4 6.4 12.8 12.8 12.8zM496 400H48V80c0-8.84-7.16-16-16-16H16C7.16 64 0 71.16 0 80v336c0 17.67 14.33 32 32 32h464c8.84 0 16-7.16 16-16v-16c0-8.84-7.16-16-16-16zm-387.2-48h22.4c6.4 0 12.8-6.4 12.8-12.8v-70.4c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v70.4c0 6.4 6.4 12.8 12.8 12.8z\" class=\"\"><\/path><\/svg><\/i> <img loading=\"lazy\" decoding=\"async\" width=\"16\" height=\"16\" alt=\"Loading\" src=\"https:\/\/www.linuxboxen.dk\/wp-content\/plugins\/page-views-count\/ajax-loader-2x.gif\" border=0 \/><\/p>\n<div class=\"pvc_clear\"><\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"class_list":["post-132","page","type-page","status-publish","hentry"],"a3_pvc":{"activated":true,"total_views":73,"today_views":0},"_links":{"self":[{"href":"https:\/\/www.linuxboxen.dk\/index.php?rest_route=\/wp\/v2\/pages\/132","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.linuxboxen.dk\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.linuxboxen.dk\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.linuxboxen.dk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.linuxboxen.dk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=132"}],"version-history":[{"count":2,"href":"https:\/\/www.linuxboxen.dk\/index.php?rest_route=\/wp\/v2\/pages\/132\/revisions"}],"predecessor-version":[{"id":33104,"href":"https:\/\/www.linuxboxen.dk\/index.php?rest_route=\/wp\/v2\/pages\/132\/revisions\/33104"}],"wp:attachment":[{"href":"https:\/\/www.linuxboxen.dk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}