PoC to demonstrate root permission hijacking by exploiting “systemd-run”

https://twitter.com/hackerfantastic/status/1785495587514638559
  • user avatar

    Lennart Poettering intends to replace "sudo" with systemd's run0. Here's a quick PoC to demonstrate root permission hijacking by exploiting the fact "systemd-run" (the basis of uid0/run0, the sudo replacer) creates a user owned pty for communication with the new "root" process.

  • user avatar

    This isn't the only bug of course, it's not possible on Linux to read the environment of a root owned process but as systemd creates a service in the system slice, you can query D-BUS and learn sensitive information passed to the process env, such as API keys or other secrets.

    user avatar

    I have only spent a little bit of time digging through the new implementation, I do not see how it is "safer" or more "secure" than existing SUID "sudo" or "su" implementations. It certainly seems to add additional attack surface to Linux as every sudo command is a service.

    user avatar

    The exploit above works by hijacking the master end of the pty from the process which is communicating with the root process, it uses "reptyr" - a tool for doing these attacks which were common on UNIX in the 90's. This is just quick demo to highlight replacing sudo ends poorly.

  • user avatar

    Can't we just to back to the days before Poettering and systemd?

{
"by": "mariuz",
"descendants": 19,
"id": 40247399,
"kids": [
40247802,
40247788,
40248293,
40248244,
40254216,
40258100,
40258711,
40247771
],
"score": 31,
"time": 1714742639,
"title": "PoC to demonstrate root permission hijacking by exploiting “systemd-run”",
"type": "story",
"url": "https://twitter.com/hackerfantastic/status/1785495587514638559"
}
{
"author": null,
"date": "2024-05-01T02:24:55.000Z",
"description": "Lennart Poettering intends to replace “sudo” with systemd’s run0. Here’s a quick PoC to demonstrate root permission hijacking by exploiting the fact “systemd-run” (the basis of uid0/run0, the sudo replacer) creates a user owned pty for communication with the new “root” process.",
"image": "https://pbs.twimg.com/media/GMdanXOWkAAwG4K.png:large",
"logo": null,
"publisher": "Twitter",
"title": "hacker.house (@hackerfantastic) on X",
"url": "https://x.com/hackerfantastic/status/1785495587514638559"
}
{
"url": "https://twitter.com/hackerfantastic/status/1785495587514638559",
"title": "hacker.house (@hackerfantastic) on X",
"description": "Lennart Poettering intends to replace \"sudo\" with systemd's run0. Here's a quick PoC to demonstrate root permission hijacking by exploiting the fact \"systemd-run\" (the basis of uid0/run0, the sudo replacer)...",
"links": [
"https://x.com/hackerfantastic/status/1785495587514638559",
"https://twitter.com/hackerfantastic/status/1785495587514638559"
],
"image": "https://pbs.twimg.com/media/GMdanXOWkAAwG4K.png:large",
"content": "<div><ul><li><div><article><div><div><a target=\"_blank\" href=\"https://twitter.com/hackerfantastic\"><p><img alt=\"user avatar\" src=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png\" srcset=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__mini.png 24w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png 48w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__bigger.png 73w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__x96.png 96w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__reasonably_small.png 128w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__200x200.png 200w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__400x400.png 400w\" /></p></a></div><p><span>Lennart Poettering intends to replace \"sudo\" with systemd's run0. Here's a quick PoC to demonstrate root permission hijacking by exploiting the fact \"systemd-run\" (the basis of uid0/run0, the sudo replacer) creates a user owned pty for communication with the new \"root\" process.</span></p><div><div><p><a target=\"_blank\" href=\"https://twitter.com/hackerfantastic/status/1785495587514638559/photo/1\"><img src=\"https://pbs.twimg.com/media/GMdanXOWkAAwG4K?format=webp&amp;name=medium\" srcset=\"https://pbs.twimg.com/media/GMdanXOWkAAwG4K?format=webp&amp;name=small 680w, https://pbs.twimg.com/media/GMdanXOWkAAwG4K?format=webp&amp;name=medium 1200w, https://pbs.twimg.com/media/GMdanXOWkAAwG4K?format=webp&amp;name=large 2048w\" /></a></p></div><div><p><a target=\"_blank\" href=\"https://twitter.com/hackerfantastic/status/1785495587514638559/photo/2\"><img src=\"https://pbs.twimg.com/media/GMdan9DWEAAmOyF?format=webp&amp;name=medium\" srcset=\"https://pbs.twimg.com/media/GMdan9DWEAAmOyF?format=webp&amp;name=small 680w, https://pbs.twimg.com/media/GMdan9DWEAAmOyF?format=webp&amp;name=medium 1200w, https://pbs.twimg.com/media/GMdan9DWEAAmOyF?format=webp&amp;name=large 2048w\" /></a></p></div></div></div></article></div></li><li><div><div><article><div><div><a target=\"_blank\" href=\"https://twitter.com/hackerfantastic\"><p><img alt=\"user avatar\" src=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png\" srcset=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__mini.png 24w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png 48w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__bigger.png 73w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__x96.png 96w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__reasonably_small.png 128w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__200x200.png 200w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__400x400.png 400w\" /></p></a></div><div><p><span>This isn't the only bug of course, it's not possible on Linux to read the environment of a root owned process but as systemd creates a service in the system slice, you can query D-BUS and learn sensitive information passed to the process env, such as API keys or other secrets.</span></p></div></div></article></div><div><article><div><div><a target=\"_blank\" href=\"https://twitter.com/hackerfantastic\"><p><img alt=\"user avatar\" src=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png\" srcset=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__mini.png 24w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png 48w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__bigger.png 73w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__x96.png 96w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__reasonably_small.png 128w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__200x200.png 200w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__400x400.png 400w\" /></p></a></div><div><p><span>I have only spent a little bit of time digging through the new implementation, I do not see how it is \"safer\" or more \"secure\" than existing SUID \"sudo\" or \"su\" implementations. It certainly seems to add additional attack surface to Linux as every sudo command is a service.</span></p></div></div></article></div><div><article><div><div><a target=\"_blank\" href=\"https://twitter.com/hackerfantastic\"><p><img alt=\"user avatar\" src=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png\" srcset=\"https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__mini.png 24w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__normal.png 48w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__bigger.png 73w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__x96.png 96w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__reasonably_small.png 128w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__200x200.png 200w, https://pbs.twimg.com/profile_images/1975213057216245760/3x5q1Pv__400x400.png 400w\" /></p></a></div><div><p><span>The exploit above works by hijacking the master end of the pty from the process which is communicating with the root process, it uses \"reptyr\" - a tool for doing these attacks which were common on UNIX in the 90's. This is just quick demo to highlight replacing sudo ends poorly.</span></p></div></div></article></div></div></li><li><div><article><div><div><a target=\"_blank\" href=\"https://twitter.com/GreggHoush\"><p><img alt=\"user avatar\" src=\"https://pbs.twimg.com/profile_images/1693092951029600256/9mZ-UZ99_normal.png\" srcset=\"https://pbs.twimg.com/profile_images/1693092951029600256/9mZ-UZ99_mini.png 24w, https://pbs.twimg.com/profile_images/1693092951029600256/9mZ-UZ99_normal.png 48w, https://pbs.twimg.com/profile_images/1693092951029600256/9mZ-UZ99_bigger.png 73w, https://pbs.twimg.com/profile_images/1693092951029600256/9mZ-UZ99_x96.png 96w, https://pbs.twimg.com/profile_images/1693092951029600256/9mZ-UZ99_reasonably_small.png 128w, https://pbs.twimg.com/profile_images/1693092951029600256/9mZ-UZ99_200x200.png 200w, https://pbs.twimg.com/profile_images/1693092951029600256/9mZ-UZ99_400x400.png 400w\" /></p></a></div><div><p><span>Can't we just to back to the days before Poettering and systemd?</span></p></div></div></article></div></li></ul></div>",
"author": "@hackerfantastic",
"favicon": "https://twitter.com/favicon.ico",
"source": "twitter.com",
"published": "2024-05-01T02:24:55.000Z",
"ttr": 41,
"type": "article"
}