Re: Mac symlink attack techniques?



On Mon, Apr 14, 2008 at 10:59:05AM +0200, Marco Ivaldi wrote:
Just a few hints off the top of my head. Specific to Mac OS X:

http://www.milw0rm.com/exploits/2737
http://www.milw0rm.com/exploits/3386

Other platforms:

http://www.0xdeadbeef.info/exploits/raptor_libnspr2
http://www.0xdeadbeef.info/exploits/raptor_libnspr3
http://www.0xdeadbeef.info/exploits/raptor_prctl2.c
http://www.milw0rm.com/exploits/792

Thanks. The Mac OS X examples you gave were exactly what I needed. It
has been a while since I've had to exploit race conditions on a Mac so
my brain was a bit rusty in that respect. I guess the reality here is
that the particular conditions in play here are really no different than
they would be on a box other than a Mac.

cron is a great way of taking advantage of this particular situation.
Without being able to take advantage of this particular flaw, the
remainder of the flaws in this particular application only lead to
gaining the privileges of another user, not root. Those could be
further exploited but I'm a fan of instant gratification.

Cheers,

-jon


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: Updating an old application
    ... to support all these platforms, but like I said, my goal would be to have ... It could be used, as is, for the PC and Mac ... "David Wilkinson" wrote: ... I don't know if this would work for you (or your customers), ...
    (microsoft.public.vstudio.general)
  • Re: Good Looking UI for a stand alone application
    ... Now go try to run one of your Dabo apps on a Mac ... and then tests it on the other platforms. ... progress bars are native Aqua bars, ...
    (comp.lang.python)
  • Re: Parallels 3: Windows games in OSX
    ... And yet again we see Windows being used to advocate the Mac. ... legacy applications on legacy OSes. ... Creating OS agnostic platforms and applications is great. ...
    (comp.sys.mac.advocacy)
  • Re: Help with what equipment is needed
    ... through and across most enterprise platforms around - including SunOS ... editing video and images (to get the thread slighlty on topic - the ... Friends in the graphic agency business who've diversified into video ... promotion would disagree with you about the Mac for video. ...
    (uk.rec.video.digital)
  • Re: Parallels 3: Windows games in OSX
    ... And yet again we see Windows being used to advocate the Mac. ... legacy applications on legacy OSes. ... Creating OS agnostic platforms and applications is great. ...
    (comp.sys.mac.advocacy)

Loading