Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.devel > #100992
| From | Andrey Rahmatullin <wrar@debian.org> |
|---|---|
| Newsgroups | linux.debian.devel |
| Subject | Re: Debian package manager privilege escalation attack |
| Date | 2021-08-12 14:50 +0200 |
| Message-ID | <CLijM-fl-3@gated-at.bofh.it> (permalink) |
| References | <CL9Jv-2Nw-1@gated-at.bofh.it> <CLbBD-4vB-1@gated-at.bofh.it> <CLcxH-57t-1@gated-at.bofh.it> <CLia5-bZ-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
On Thu, Aug 12, 2021 at 08:35:42AM -0400, Kyle Edwards wrote: > > > > I just ran across this article > > > > https://blog.ikuamike.io/posts/2021/package_managers_privesc/ I tested > > > > the attacks on Debian 11 and they work successfully giving me a root > > > > shell prompt. > > > I don't think calling this "privilege escalation" or "attack" is correct. > > > The premise of the post is "the user should not be a root/admin user but > > > has been assigned sudo permissions to run the package manager" and one > > > doesn't really need a long article to prove that it's not secure. > > I think the article is interesting nonetheless. Some people may think > > that granting sudo on apt is OK. In the past, I think "apt install > > ./something.deb" was not possible. > Random thought: could it be possible to restrict non-sudo users to > installing packages from repos that are signed by a GPG key that is already > trusted by the system (the Debian archive key)? Via some wrapper maybe? But at that point just use PackageKit? > That way this attack could not be carried out. Only the one that relies on package content, while there are more ways to ask apt to run a process, as listed in the article and in this thread. > Then add a Unix group that allows apt installation from > trusted repos, make apt setuid Please don't. -- WBR, wRAR
Back to linux.debian.devel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Debian package manager privilege escalation attack Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2021-08-12 05:40 +0200
Re: Debian package manager privilege escalation attack Brian Thompson <brian@hashvault.io> - 2021-08-12 06:00 +0200
Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 07:50 +0200
Re: Debian package manager privilege escalation attack Brian Thompson <brian@hashvault.io> - 2021-08-12 08:20 +0200
Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 08:30 +0200
Re: Debian package manager privilege escalation attack Paul Tagliamonte <paultag@debian.org> - 2021-08-12 15:00 +0200
Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 07:40 +0200
Re: Debian package manager privilege escalation attack Vincent Bernat <bernat@debian.org> - 2021-08-12 08:40 +0200
Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 08:40 +0200
Re: Debian package manager privilege escalation attack Vincent Bernat <bernat@debian.org> - 2021-08-12 09:00 +0200
Re: Debian package manager privilege escalation attack Ansgar <ansgar@43-1.org> - 2021-08-12 10:40 +0200
Re: Debian package manager privilege escalation attack Vincent Bernat <bernat@debian.org> - 2021-08-12 11:20 +0200
Re: Debian package manager privilege escalation attack Philipp Kern <pkern@debian.org> - 2021-08-12 11:20 +0200
Re: Debian package manager privilege escalation attack David Kalnischkies <david@kalnischkies.de> - 2021-08-12 13:50 +0200
Re: Debian package manager privilege escalation attack Kyle Edwards <kyle.edwards@kitware.com> - 2021-08-12 14:40 +0200
Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 14:50 +0200
Re: Debian package manager privilege escalation attack Niels Thykier <niels@thykier.net> - 2021-08-12 07:40 +0200
Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 08:20 +0200
Re: Debian package manager privilege escalation attack Brian Thompson <brian@hashvault.io> - 2021-08-12 08:30 +0200
Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 08:40 +0200
Re: Debian package manager privilege escalation attack Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-08-12 12:30 +0200
Re: Debian package manager privilege escalation attack Philipp Kern <pkern@debian.org> - 2021-08-12 13:50 +0200
Re: Debian package manager privilege escalation attack Marc Haber <mh+debian-devel@zugschlus.de> - 2021-08-12 18:00 +0200
Re: Debian package manager privilege escalation attack Philipp Kern <pkern@debian.org> - 2021-08-12 20:10 +0200
Re: Debian package manager privilege escalation attack Russ Allbery <rra@debian.org> - 2021-08-12 21:10 +0200
Re: Debian package manager privilege escalation attack Brian Thompson <brian@hashvault.io> - 2021-08-12 08:20 +0200
Re: Debian package manager privilege escalation attack Holger Levsen <holger@layer-acht.org> - 2021-08-12 15:20 +0200
Re: Debian package manager privilege escalation attack Holger Levsen <holger@layer-acht.org> - 2021-08-12 18:10 +0200
Re: Debian package manager privilege escalation attack Wouter Verhelst <wouter@debian.org> - 2021-08-16 16:50 +0200
csiph-web